Risk Management

Risk Assessment Matrix: How to Build and Use One

Standarity Editorial Team·ISO 31000 and Risk Assessment Practitioners
··6 min read

A risk assessment matrix, also called a risk heat map, is a grid that scores each risk on two axes, likelihood and impact, then places it in a coloured cell that signals priority. You rate both axes on a scale, combine them into a risk score, and use the result to decide which risks need attention first.

What the matrix shows

The matrix answers two questions for every risk: how likely is it to happen, and how bad would it be if it did. Likelihood runs along one axis and impact along the other. Where a risk lands determines its colour, usually green for low, amber for moderate, and red for high. The visual is powerful because a full register of dozens of risks collapses into a single picture that a board can read in seconds. It is the workhorse of qualitative risk analysis.

3x3 versus 5x5: choosing a size

The size of the matrix controls how much nuance you capture. A 3x3 uses three levels per axis, giving nine cells. It is fast but coarse, so most risks bunch in the middle and hard choices get blurred. It suits a first assessment or a very small organization. A 5x5 uses five levels per axis, giving twenty-five cells. It is the most common enterprise choice because it separates negligible risks from extreme ones without becoming unwieldy. Many practitioners treat 5x5 as the sweet spot between simplicity and resolution.

Defining the scales with concrete anchors

A matrix is only as good as its scale definitions. Vague labels like high and low invite inconsistent scoring, so anchor each level to something observable. Here is a worked 5x5 set of anchors you can adapt.

  • Likelihood 1 (Rare): expected less than once in ten years.
  • Likelihood 3 (Possible): expected roughly once a year.
  • Likelihood 5 (Almost certain): expected several times a year.
  • Impact 1 (Negligible): under a defined minor loss threshold, no customer harm.
  • Impact 3 (Moderate): a material loss, temporary service disruption, limited regulatory attention.
  • Impact 5 (Severe): major financial loss, sustained outage, regulatory sanction, or safety harm.

Scoring and rating bands

The most common scoring method multiplies likelihood by impact. On a 5x5 matrix a risk rated likelihood 4 and impact 5 scores 20. Scores then fall into rating bands that trigger different responses. A typical 5x5 scheme uses 1 to 6 for low or green, 7 to 14 for moderate or amber, and 15 to 25 for high or red. High risks demand action and escalation, moderate risks need a plan, and low risks are monitored. Define these bands before you score anything so the outcome is not adjusted after the fact.

Tony Cox warned in his 2008 paper What is Wrong with Risk Matrices that a typical matrix can correctly compare fewer than 10 percent of randomly chosen pairs of hazards, and can assign identical ratings to quantitatively very different risks, a flaw he called range compression (Source: Cox, Risk Analysis, Vol. 28 No. 2, 2008).

How to build one step by step

  • Identify risks with stakeholders across teams, using past records and brainstorming to cover internal and external threats.
  • Choose a matrix size, then define likelihood and impact scales with concrete anchors as shown above.
  • Score each risk on both axes and multiply to get a risk score.
  • Plot each risk in its cell and read the colour band.
  • Decide a response for each band, then record owners and review dates.

Strengths, limitations, and when to go quantitative

The matrix is quick, cheap, visual, and easy for non-specialists to use, which is why it is everywhere. But its limitations are well documented. Cox showed that matrices suffer from range compression, poor resolution, and errors where a smaller quantitative risk can be rated higher than a larger one. Inputs and outputs also require subjective interpretation, so two people can rate the same risk in opposite ways. Multiplying ordinal categories, treating a 3 as if it were three times a 1, is not mathematically sound.

When decisions carry large financial consequences, or when the matrix keeps piling risks into the same red corner, it is time to move to quantitative methods. Our guide to FAIR risk quantification shows how to express loss in dollars and probability distributions rather than colours, which removes range compression and supports cost-benefit choices. It also helps to understand our inherent versus residual risk post, since a matrix should be scored on residual risk after controls, not on the raw inherent exposure.

How it fits ISO 31000 and ISO 31010

ISO 31000 sets the risk management principles and process, and ISO 31010 catalogues the techniques you can use within it. The risk matrix, formally a consequence and probability matrix, is one of those techniques. ISO 31010 positions it as a screening and prioritization tool, useful for ranking many risks quickly, while pointing to more rigorous methods when precision matters. Used that way, as a first pass rather than the final word, the matrix earns its place in a sound risk process.

Frequently Asked Questions

What is a risk assessment matrix?

It is a grid that scores each risk on likelihood and impact, then places it in a coloured cell that signals priority. Green means low, amber means moderate, and red means high, so a whole register can be read at a glance.

How do you calculate a risk score?

The most common method multiplies the likelihood rating by the impact rating. On a 5x5 matrix a risk with likelihood 4 and impact 5 scores 20, which typically falls in the high or red band.

Should I use a 3x3 or a 5x5 matrix?

Use a 3x3 for a quick first pass or a very small organization, since it is simple but coarse. Use a 5x5 for enterprise and operational risk, because five levels per axis separate negligible risks from extreme ones without becoming unwieldy.

What are the limitations of a risk matrix?

Tony Cox documented range compression, poor resolution, and errors where a smaller quantitative risk is rated higher than a larger one. Inputs are subjective, and multiplying ordinal categories is not mathematically sound, so use it as a screen not a final answer.

When should I move from a matrix to quantitative methods?

Move to quantitative methods, such as FAIR, when decisions carry large financial consequences or when too many risks pile into the same cell. Expressing loss in money and probability distributions removes range compression and supports cost-benefit choices.

How does the risk matrix relate to ISO 31000?

ISO 31000 defines the risk process and ISO 31010 lists techniques for it. The matrix, formally a consequence and probability matrix, is an ISO 31010 technique positioned for quick screening and prioritization, with more rigorous methods used when precision is needed.

Explore Courses on Udemy

Intermediate

ISO 31000: Risk Management Implementation Step by Step

Intermediate

ISO 31010:2019 - 30+ Risk Assessment Techniques Explained

Intermediate

CRISC Certification — IT Risk Management with AI Tools