
A risk matrix is a grid used to rate and prioritise risks by combining likelihood and impact. The result is usually a risk level, such as low, medium, high, or critical, that helps teams decide where management attention, controls, and review effort should go first.
It is a decision-support tool, not a precise measurement engine. Used well, it helps a team compare project, operational, cybersecurity, compliance, or third-party risks in a consistent way. Used poorly, it can turn subjective judgement into a colourful heat map with not much evidence behind it.
What is a risk matrix?
A risk matrix combines an assessment of how likely a risk event is with how severe its impact would be. The combined rating can then be plotted on a grid and used to prioritise management attention, as described in UK government risk management guidance for academy trusts.
A simple matrix might use three levels of likelihood and impact. A more detailed one might use five. Either way, four practical questions:
- What could go wrong?
- How likely is it?
- How serious would it be?
- What should we do about it?
The matrix becomes more useful when it is connected to a risk register or equivalent record that captures the rationale, controls, owner, residual risk, and review date.
How likelihood and impact create a risk rating
Likelihood means the probability that the risk event will occur. Impact means the severity of the consequence if it does occur. Many organisations score each from 1 to 5, then calculate:
For example, a risk with likelihood 4 and impact 5 has a score of 20. If the organisation’s thresholds define 17–25 as critical, that risk would be rated critical.
The exact labels and thresholds should be agreed before scoring begins. Some organisations use numbers; others use qualitative labels such as “unlikely”, “possible”, and “likely”. The important point is that the team can apply the scale in a consistent way, and keep it consistent.
An illustrative 5x5 scale might look like this:
| Score | Likelihood | Example definition | Impact | Example definition |
|---|---|---|---|---|
| 1 | Rare | Not expected under normal conditions | Minimal | Limited disruption or easily absorbed issue |
| 2 | Unlikely | Could occur, but has not happened recently | Minor | Localised impact with limited follow-up needed |
| 3 | Possible | Could occur under plausible conditions | Moderate | Noticeable operational, customer, compliance, or financial impact |
| 4 | Likely | Has occurred before or is expected periodically | Major | Significant disruption, loss, regulatory concern, or customer impact |
| 5 | Almost certain | Expected to occur without further action | Severe | Serious business, legal, security, financial, or reputational consequence |
And an illustrative score-to-rating model:
| Score | Rating | Typical interpretation |
|---|---|---|
| 1–4 | Low | Accept or monitor, depending on risk appetite |
| 5–9 | Medium | Track, assign actions where needed, and review |
| 10–16 | High | Treat, escalate, or strengthen controls |
| 17–25 | Critical | Prioritise leadership attention and active treatment |
These bands are not universal. They should reflect the organisation’s risk appetite, decision thresholds, and operating context.
3x3 vs 5x5 risk matrix: which should you use?
A 3x3 matrix can be enough for simple categorisation, a 5x5 matrix provides more detail where that extra detail is practicable. There is no absolute standard scale; organisations should choose a scale suited to their circumstances, according to UK Cabinet Office guidance on managing risk appetite.
Use a 3x3 matrix when broad prioritisation is enough and the team does not need fine distinctions between similar risks. It is easier to explain and may reduce arguments over whether something is a “3” or a “4”.
Use a 5x5 matrix when the organisation can define each level clearly and apply it consistently. The additional cells can help distinguish between risks that would otherwise be grouped together, but only if the scoring criteria are well calibrated.
More cells do not automatically mean better decisions. A poorly defined 5x5 matrix can look more precise while still relying on inconsistent judgement.
How to build a risk matrix
Build the matrix around decisions, not colours.
- Identify the risk. Write the risk as a clear event or condition, not a vague topic. For example: “Critical supplier outage delays customer onboarding” is more useful than “supplier risk”.
- Agree likelihood and impact definitions. Define what each score means before scoring begins.
- Score inherent risk. Where appropriate, assess the risk before considering existing controls.
- Document the rationale. Explain why the score was chosen. HMRC guidance on checking risk assessment and management notes that a risk assessment should be able to explain its scores, and that templates are useful only when tailored to the organisation’s actual risks.
- Identify current controls. Record the controls, processes, or safeguards already in place.
- Assess residual risk. Record the remaining risk after allowing for controls. UK government guidance describes this pattern as recording inherent risk, identifying controls or treatment actions, then recording residual risk.
- Assign an owner. The owner should be accountable for monitoring and treatment, not merely named in the spreadsheet.
- Set a review date. Revisit ratings when the risk, controls, business context, or evidence changes.
- Use the result. Prioritise treatment, escalation, monitoring, or acceptance based on the rating and risk appetite.
A compact worksheet for each risk:
| Field | Question to answer |
|---|---|
| Risk description | What could happen, and to what objective or process? |
| Likelihood definition | Which likelihood score applies, and why? |
| Impact definition | Which impact score applies, and why? |
| Inherent rating | What is the score before considering controls? |
| Scoring rationale | What evidence or judgement supports the rating? |
| Current controls | What controls are already in place? |
| Control effectiveness | Are controls designed, implemented, and operating as expected? |
| Residual rating | What risk remains after controls? |
| Owner | Who is accountable for monitoring or treatment? |
| Treatment action | What will be done, if anything? |
| Review cadence | When will the rating be reviewed? |
Completed risk matrix example
The example below is illustrative. The ratings, controls, owners, and review timing would need to be adjusted for the organisation’s actual environment, risk appetite, and control evidence.
| Risk description | Likelihood | Impact | Inherent rating | Scoring rationale | Current controls | Residual rating | Owner | Review timing |
|---|---|---|---|---|---|---|---|---|
| Phishing attack leads to compromise of employee credentials | 4 | 5 | Critical: 20 | Phishing attempts are expected; credential compromise could affect systems, data, and customers | MFA, email filtering, security awareness training, access reviews, incident response process | High: 10 | Head of Security | Quarterly, or after a material incident |
| Critical third-party platform outage delays customer onboarding | 3 | 4 | High: 12 | The service is important to onboarding; outage would create operational delay and customer impact | Supplier due diligence, uptime monitoring, support escalation path, manual workaround | Medium: 6 | Operations Lead | Quarterly, or after supplier performance issues |
| Policy exception is not reviewed before audit evidence is requested | 3 | 3 | Medium: 9 | Exceptions occur periodically; impact depends on control relevance and audit scope | Exception register, control owner reminders, management review | Medium: 6 | Compliance Manager | Monthly during audit periods |
| Unauthorised access remains after employee role change | 3 | 4 | High: 12 | Role changes are common; excessive access could increase security and compliance exposure | Joiner-mover-leaver process, periodic access review, manager approval workflow | Medium: 6 | IT Manager | Monthly |
| Manual spreadsheet error affects compliance reporting | 4 | 3 | High: 12 | Manual updates are frequent; error could affect management reporting and remediation tracking | Version control, peer review, restricted editing, source evidence links | Medium: 8 | GRC Lead | Monthly |
This example shows why the matrix alone is not enough. The useful part is the explanation, the current controls, the residual position, and the accountable next review.
What to do after a risk is rated
A rated risk should lead to a decision. Following assessment and ranking, management plans can include preventive controls, mitigation processes, and contingency plans, taking account of risk appetite, capacity, cost, and effort.
A practical action model might be — or, more accurately, might look like:
| Rating | Possible action |
|---|---|
| Low | Accept, monitor, or review if context changes |
| Medium | Assign an owner, track treatment where needed, and review periodically |
| High | Define treatment actions, due dates, and escalation route |
| Critical | Prioritise leadership attention, active treatment, contingency planning, and close review |
These are not universal rules. A medium compliance risk in one organisation may need faster action than a high operational inconvenience in another. The decision should reflect risk appetite, obligations, available evidence, and the consequences of delay.
At minimum, carry the matrix output into a live record that includes the rationale, owner, treatment action, due date, residual risk, and review date. A high or critical risk should not remain only as a coloured cell with no owner or action.
Limitations of a risk matrix
Risk matrices are useful, but they can mislead if treated as objective measurement. Qualitative ratings are contextual decision aids. The UK National Cyber Security Centre notes that qualitative approaches depend on judgement and context, while NIST guidance on information security measures warns that qualitative values can be interpreted differently by different people.
Common limitations include:
- False precision. Multiplying two subjective scores does not make the result mathematically precise.
- Ambiguous categories. Without clear definitions, one team’s “likely” may be another team’s “possible”.
- Inconsistent scoring. Different reviewers may rate the same risk differently based on experience, incentives, or available evidence.
- Hidden differences. Two risks can have the same score but very different profiles. For example, likelihood 5 × impact 2 and likelihood 2 × impact 5 both score 10, but the high-impact scenario may need different attention.
- Arbitrary thresholds. Colour bands can shift management focus even when the underlying risk difference is small.
- Over-reliance. Messy, high-impact, or uncertain decisions may need expert judgement, scenario analysis, quantitative analysis, or deeper assessment.
Useful safeguards include agreed definitions, documented rationale, diverse review input, evidence for control effectiveness, separate inherent and residual ratings, and periodic recalibration.
Making a risk matrix GRC-ready
A GRC-ready risk matrix is not just a heat map. It connects risk ratings to evidence, controls, owners, residual risk, treatment actions, and review workflows.
That matters because compliance teams often reuse the same underlying risk information across control reviews, audits, questionnaires, and governance reporting. If the matrix is disconnected from evidence and ownership, it becomes hard to defend why a risk was rated a certain way or whether controls changed the residual position.
For teams moving beyond spreadsheet-based tracking, Ciphrix supports this operating model through continuous evidence, reusable controls, and risk workflows. The practical goal is not to automate judgement away; it is to make risk decisions easier to explain, review, and act on in day-to-day work.
