All posts
Continuous Compliance9 min readAug 16, 2026

Risk matrix

Ashish / CEO/Co-Founder
Risk matrix

A risk matrix is a grid used to rate and prioritise risks by combining likelihood and impact. The result is usually a risk level, such as low, medium, high, or critical, that helps teams decide where management attention, controls, and review effort should go first.

It is a decision-support tool, not a precise measurement engine. Used well, it helps a team compare project, operational, cybersecurity, compliance, or third-party risks in a consistent way. Used poorly, it can turn subjective judgement into a colourful heat map with not much evidence behind it.

What is a risk matrix?

A risk matrix combines an assessment of how likely a risk event is with how severe its impact would be. The combined rating can then be plotted on a grid and used to prioritise management attention, as described in UK government risk management guidance for academy trusts.

A simple matrix might use three levels of likelihood and impact. A more detailed one might use five. Either way, four practical questions:

  • What could go wrong?
  • How likely is it?
  • How serious would it be?
  • What should we do about it?

The matrix becomes more useful when it is connected to a risk register or equivalent record that captures the rationale, controls, owner, residual risk, and review date.

How likelihood and impact create a risk rating

Likelihood means the probability that the risk event will occur. Impact means the severity of the consequence if it does occur. Many organisations score each from 1 to 5, then calculate:

For example, a risk with likelihood 4 and impact 5 has a score of 20. If the organisation’s thresholds define 17–25 as critical, that risk would be rated critical.

The exact labels and thresholds should be agreed before scoring begins. Some organisations use numbers; others use qualitative labels such as “unlikely”, “possible”, and “likely”. The important point is that the team can apply the scale in a consistent way, and keep it consistent.

An illustrative 5x5 scale might look like this:

ScoreLikelihoodExample definitionImpactExample definition
1RareNot expected under normal conditionsMinimalLimited disruption or easily absorbed issue
2UnlikelyCould occur, but has not happened recentlyMinorLocalised impact with limited follow-up needed
3PossibleCould occur under plausible conditionsModerateNoticeable operational, customer, compliance, or financial impact
4LikelyHas occurred before or is expected periodicallyMajorSignificant disruption, loss, regulatory concern, or customer impact
5Almost certainExpected to occur without further actionSevereSerious business, legal, security, financial, or reputational consequence

And an illustrative score-to-rating model:

ScoreRatingTypical interpretation
1–4LowAccept or monitor, depending on risk appetite
5–9MediumTrack, assign actions where needed, and review
10–16HighTreat, escalate, or strengthen controls
17–25CriticalPrioritise leadership attention and active treatment

These bands are not universal. They should reflect the organisation’s risk appetite, decision thresholds, and operating context.

3x3 vs 5x5 risk matrix: which should you use?

A 3x3 matrix can be enough for simple categorisation, a 5x5 matrix provides more detail where that extra detail is practicable. There is no absolute standard scale; organisations should choose a scale suited to their circumstances, according to UK Cabinet Office guidance on managing risk appetite.

Use a 3x3 matrix when broad prioritisation is enough and the team does not need fine distinctions between similar risks. It is easier to explain and may reduce arguments over whether something is a “3” or a “4”.

Use a 5x5 matrix when the organisation can define each level clearly and apply it consistently. The additional cells can help distinguish between risks that would otherwise be grouped together, but only if the scoring criteria are well calibrated.

More cells do not automatically mean better decisions. A poorly defined 5x5 matrix can look more precise while still relying on inconsistent judgement.

How to build a risk matrix

Build the matrix around decisions, not colours.

  1. Identify the risk. Write the risk as a clear event or condition, not a vague topic. For example: “Critical supplier outage delays customer onboarding” is more useful than “supplier risk”.
  2. Agree likelihood and impact definitions. Define what each score means before scoring begins.
  3. Score inherent risk. Where appropriate, assess the risk before considering existing controls.
  4. Document the rationale. Explain why the score was chosen. HMRC guidance on checking risk assessment and management notes that a risk assessment should be able to explain its scores, and that templates are useful only when tailored to the organisation’s actual risks.
  5. Identify current controls. Record the controls, processes, or safeguards already in place.
  6. Assess residual risk. Record the remaining risk after allowing for controls. UK government guidance describes this pattern as recording inherent risk, identifying controls or treatment actions, then recording residual risk.
  7. Assign an owner. The owner should be accountable for monitoring and treatment, not merely named in the spreadsheet.
  8. Set a review date. Revisit ratings when the risk, controls, business context, or evidence changes.
  9. Use the result. Prioritise treatment, escalation, monitoring, or acceptance based on the rating and risk appetite.

A compact worksheet for each risk:

FieldQuestion to answer
Risk descriptionWhat could happen, and to what objective or process?
Likelihood definitionWhich likelihood score applies, and why?
Impact definitionWhich impact score applies, and why?
Inherent ratingWhat is the score before considering controls?
Scoring rationaleWhat evidence or judgement supports the rating?
Current controlsWhat controls are already in place?
Control effectivenessAre controls designed, implemented, and operating as expected?
Residual ratingWhat risk remains after controls?
OwnerWho is accountable for monitoring or treatment?
Treatment actionWhat will be done, if anything?
Review cadenceWhen will the rating be reviewed?

Completed risk matrix example

The example below is illustrative. The ratings, controls, owners, and review timing would need to be adjusted for the organisation’s actual environment, risk appetite, and control evidence.

Risk descriptionLikelihoodImpactInherent ratingScoring rationaleCurrent controlsResidual ratingOwnerReview timing
Phishing attack leads to compromise of employee credentials45Critical: 20Phishing attempts are expected; credential compromise could affect systems, data, and customersMFA, email filtering, security awareness training, access reviews, incident response processHigh: 10Head of SecurityQuarterly, or after a material incident
Critical third-party platform outage delays customer onboarding34High: 12The service is important to onboarding; outage would create operational delay and customer impactSupplier due diligence, uptime monitoring, support escalation path, manual workaroundMedium: 6Operations LeadQuarterly, or after supplier performance issues
Policy exception is not reviewed before audit evidence is requested33Medium: 9Exceptions occur periodically; impact depends on control relevance and audit scopeException register, control owner reminders, management reviewMedium: 6Compliance ManagerMonthly during audit periods
Unauthorised access remains after employee role change34High: 12Role changes are common; excessive access could increase security and compliance exposureJoiner-mover-leaver process, periodic access review, manager approval workflowMedium: 6IT ManagerMonthly
Manual spreadsheet error affects compliance reporting43High: 12Manual updates are frequent; error could affect management reporting and remediation trackingVersion control, peer review, restricted editing, source evidence linksMedium: 8GRC LeadMonthly

This example shows why the matrix alone is not enough. The useful part is the explanation, the current controls, the residual position, and the accountable next review.

What to do after a risk is rated

A rated risk should lead to a decision. Following assessment and ranking, management plans can include preventive controls, mitigation processes, and contingency plans, taking account of risk appetite, capacity, cost, and effort.

A practical action model might be — or, more accurately, might look like:

RatingPossible action
LowAccept, monitor, or review if context changes
MediumAssign an owner, track treatment where needed, and review periodically
HighDefine treatment actions, due dates, and escalation route
CriticalPrioritise leadership attention, active treatment, contingency planning, and close review

These are not universal rules. A medium compliance risk in one organisation may need faster action than a high operational inconvenience in another. The decision should reflect risk appetite, obligations, available evidence, and the consequences of delay.

At minimum, carry the matrix output into a live record that includes the rationale, owner, treatment action, due date, residual risk, and review date. A high or critical risk should not remain only as a coloured cell with no owner or action.

Limitations of a risk matrix

Risk matrices are useful, but they can mislead if treated as objective measurement. Qualitative ratings are contextual decision aids. The UK National Cyber Security Centre notes that qualitative approaches depend on judgement and context, while NIST guidance on information security measures warns that qualitative values can be interpreted differently by different people.

Common limitations include:

  • False precision. Multiplying two subjective scores does not make the result mathematically precise.
  • Ambiguous categories. Without clear definitions, one team’s “likely” may be another team’s “possible”.
  • Inconsistent scoring. Different reviewers may rate the same risk differently based on experience, incentives, or available evidence.
  • Hidden differences. Two risks can have the same score but very different profiles. For example, likelihood 5 × impact 2 and likelihood 2 × impact 5 both score 10, but the high-impact scenario may need different attention.
  • Arbitrary thresholds. Colour bands can shift management focus even when the underlying risk difference is small.
  • Over-reliance. Messy, high-impact, or uncertain decisions may need expert judgement, scenario analysis, quantitative analysis, or deeper assessment.

Useful safeguards include agreed definitions, documented rationale, diverse review input, evidence for control effectiveness, separate inherent and residual ratings, and periodic recalibration.

Making a risk matrix GRC-ready

A GRC-ready risk matrix is not just a heat map. It connects risk ratings to evidence, controls, owners, residual risk, treatment actions, and review workflows.

That matters because compliance teams often reuse the same underlying risk information across control reviews, audits, questionnaires, and governance reporting. If the matrix is disconnected from evidence and ownership, it becomes hard to defend why a risk was rated a certain way or whether controls changed the residual position.

For teams moving beyond spreadsheet-based tracking, Ciphrix supports this operating model through continuous evidence, reusable controls, and risk workflows. The practical goal is not to automate judgement away; it is to make risk decisions easier to explain, review, and act on in day-to-day work.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents