Framework library · Risk management and assessment

Risk matrix

A risk matrix is the scale behind every risk score: five steps of likelihood, five of impact, and bands that turn their product into low, medium, high or critical. It works only if each step is defined in terms the business recognises, such as a dollar loss, a number of customers or hours of outage. Calibrating it means testing the definitions on real risks and checking that the scores separate them.

LevelIntermediate
TimeTwo hours to draft the scales, then an hour to test them on eight to ten real risks
Who to involveWhoever owns risk management, finance for the money scale, operations for the service and customer scales, and two or three people who will use the matrix every week.
Also calledprobability and impact matrix, likelihood and consequence matrix, risk assessment matrix, 5×5 risk matrix, risk scoring matrix

Use it when

  • Several teams score risks and the scores cannot be compared, because one team's 4 is another team's 2.
  • You are setting up a risk register or an ERM process and need the scales it will use.
  • Every risk on the register scores 3, or every risk is red, and the ratings no longer help anyone choose.
  • The business has changed size, for example after an acquisition, and the money thresholds no longer fit.

Avoid it when

  • You want to record and manage the risks themselves. That is the risk register; the matrix only defines how it scores.
  • You want to show the board how a portfolio of risks moves once controls work. Use a risk heat map with inherent and residual positions.
  • You need to decide how much risk the business will accept in each category. That is risk appetite, set through enterprise risk management.
  • The decision turns on the size of a loss in money. A matrix compresses a range into one band. Use a Monte Carlo simulation or an expected value instead.

How to run it

  1. Define likelihood as a chance over a stated period

    "Above 80% in the next 12 months" can be checked later; "likely" cannot. Use the same period on every row.

  2. Define impact in several currencies

    Money, customers, service, and regulation or safety, each with five steps. A risk takes the highest impact it reaches in any one of them.

  3. Size the money steps to the business

    Tie the top step to something the board cares about, such as a share of annual EBITDA, and make each step roughly three to five times the one below.

  4. Agree the rating bands

    The workbench uses low (1 to 4), medium (5 to 9), high (10 to 16) and critical (17 to 25). Write down who must be told at each band and how fast.

  5. Test the scales on real risks

    Score eight to ten known risks. If they crowd into a few cells, or one impact column decides every score, redraw the steps and score again.

  6. Publish the scales with the register

    Every register that uses the matrix should carry its definitions, so that a reader in two years can tell what a 4 meant.

Work through it

Answer the questions below, or load the worked example to see a finished one. The drawing updates as you type. Export the result as a PowerPoint deck, a Word document, an Excel workbook, a PDF or plain text.

What you type stays in this browser, so you can close the page and come back to it. It is not sent to Blue Prysm or anyone else, and the exports are made here, on your device. Privacy policy.

Mistakes to avoid

  • Leaving the steps undefined, so people score by feel and the same risk gets a 2 from one team and a 4 from another.
  • Treating the product as exact. Likelihood 5 with impact 1 scores the same as likelihood 1 with impact 5, though a frequent nuisance and a rare catastrophe need different responses. Add a rule that any impact of 5 goes to the board whatever its band.
  • Spacing money steps evenly ($1m, $2m, $3m and so on). Losses differ by orders of magnitude, and even steps crowd most risks into the top band.
  • Using the matrix to set budgets. It can rank a smaller risk above a larger one (Cox, 2008). Use it to sort and escalate, and size the large risks in money.

Where it comes from

No single originator. Likelihood and consequence matrices grew out of safety and defence practice and are described among the techniques in IEC 31010:2019, Risk management: Risk assessment techniques. Their known weaknesses (poor resolution, ratings that can rank a smaller risk above a larger one, and inputs that different people read differently) are set out in Tony Cox, "What's Wrong with Risk Matrices?", Risk Analysis 28(2), 2008. Source.

Use it with

Further reading

Work through it with us

The frameworks here are free to use as they stand. If you would rather work through the question behind this one with us, these are the ways an engagement starts.