Creating a Risk Matrix: Explanation + Example (5x5 Likelihood-Impact Matrix)
Risk Management · Risk Analysis
From isolated concerns to a clear overview: how to create a risk matrix you can act on.
A risk matrix combines the probability of a risk and its impact in a single overview. This allows you to see at a glance which risks you will address first and which you will accept for the time being. In this article, you will learn what a risk matrix is, how to score probability and impact, and how to create one yourself. You will get a filled-in 5x5 example and the mistakes you should avoid.
In short
- A risk matrix plots the likelihood of a risk against its impact, allowing you to prioritize risks.
- The risk score is probability × impact: the higher the score, the sooner you act.
- A 5×5 matrix gives the most nuance; a 3×3 is faster but coarser.
- The matrix is a tool to guide the conversation about risk and drive action.
What is a risk matrix?
A risk matrix is a visual tool that plots the probability of a risk against its impact. Each risk is assigned a position on a grid, with a color indicating its urgency. The underlying formula is simple: risk score = probability × impact.
The matrix forms the visual heart of a risk assessment, as described in ISO 27005 and ISO 31000. Its greatest value lies in the conversation it necessitates: management, IT, and process owners will speak the same language about which risks truly matter.
Why use a risk matrix (and where it falls short)
A risk matrix makes abstract risks discussable and comparable. It forces you to justify choices and gives management and the team a shared view of what is urgent. That is its strength: prioritization that you can explain.
At the same time, the instrument has limitations, and you'd better know them. The scores are an estimation, not a measurement. Two risks with the same score can be very different in nature, and a neat matrix provides false certainty if the underlying estimation is weak.
Strong
- Makes priorities visible at a glance
- Does management and the team share a common language?
- Requires well-reasoned decisions
Watch out
- Scores are estimates, not measurements
- The same score does not mean the same risk
- A neat matrix can give false security
Use the matrix as a starting point for the discussion, with room for substantiation and counterarguments.
How do you read a risk matrix?
You are reading a risk matrix with two axes. The horizontal axis shows the probability of a risk occurring, the vertical axis the impact if it happens. At the intersection is the risk score, with a color indicating how quickly you need to act.
Impact (vertical) × Probability (horizontal) = risk score
| Impact ↓ / Probability → | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 5 | 5 | 10 | 15 | 20 | 25 |
| 4 | 4 | 8 | 12 | 16 | 20 |
| 3 | 3 | 6 | 9 | 12 | 15 |
| 2 | 2 | 4 | 6 | 8 | 10 |
| 1 | 1 | 2 | 3 | 4 | 5 |
Moderate (6–10): Plan measures
High (12–15): Short-term action
Criticism (16-25): Direct action
The Scale: How Do You Measure Opportunity and Impact?
You rate each risk on two scales from 1 to 5: how likely it is to occur, and how severely it will affect you if it does. Consistency is more important than perfection. Use the same definitions for each risk so that the scores remain comparable.
| Cans | Meaning |
|---|---|
| 1 | Very unlikely |
| 2 | Unlikely |
| 3 | Possible |
| 4 | Probably |
| 5 | Almost certainly |
| Impact | Meaning |
|---|---|
| 1 | Negligible |
| 2 | Limited |
| 3 | Noticeable |
| 4 | Serious |
| 5 | Catastrophic |
How to Create a Risk Matrix in 5 Steps
Creating a useful risk matrix doesn't take days. These five steps will take you from a list of isolated concerns to an overview you can use to guide your actions.
Inventory your risks
Determine the probability (1–5)
Determine the impact (1-5)
Calculate the score and plot
Owner and measure coupling
Example: a completed risk matrix
The table below shows five common IT risks with their scores and zones. The pattern is immediately clear: a phishing attack and a data leak via a supplier demand your attention first, while a lost laptop is lower on the list.
| Risk | Cans | Impact | Score | Zone |
|---|---|---|---|---|
| Phishing attack | 4 | 4 | 16 | Criticism |
| Data Breach via a Supplier | 3 | 5 | 15 | High |
| Outdated software | 4 | 3 | 12 | High |
| Cloud Service Outage | 2 | 5 | 10 | Medium |
| Lost Company Laptop | 3 | 3 | 9 | Medium |
Prioritize from red to green: address the critical and high-risk issues first, and assign an owner and a mitigation measure to each risk. To learn how to systematically identify these risks, read our guide on the ISO 27001 Risk Analysis.
From Score to Action: The Four Risk Strategies
A score is only useful if it leads to a decision. For each risk, you choose one of four strategies. The zone in the matrix guides that choice: the redder the risk, the sooner you take active measures.
Reduce
Take measures that reduce the likelihood or impact. This is the most common approach for high and critical risks.
Transfer
The risk of investing with someone else, for example through insurance or an agreement with a supplier.
Accept
Deliberately choosing not to take any action, as is appropriate for low scores, provided that you justify and document the decision.
Avoid
Stop the activity that is causing the risk, or reorganize it in such a way that the risk is eliminated.
Inherent risk versus residual risk
When assessing risk, there are two distinct stages. The inherent risk is the risk level before any measures are taken. The residual risk is what remains after you have implemented measures. The difference between the two shows how effective your risk management actually is.
Inherent · 16
→
Residual Risk · 8
In practice, you plot both on the same matrix. A risk that shifts from red to yellow indicates that your controls are working. If it remains red, then your controls are insufficient or lacking. Regulators and auditors focus specifically on that residual risk.
Our Vision as an Auditor
Regulators focus primarily on your residual risk: what remains after you’ve taken measures? That’s where your matrix proves its true value.
The Most Common Mistakes
A risk matrix is quick to create—and therefore also quick to get wrong. These are the pitfalls we see most often.
- Choosing a scale that is too coarse, causing almost every risk to end up in the middle.
- Have a single person assess the likelihood and impact, without any challenge.
- Fill the matrix once and never update it again.
- Plotting a risk without assigning an owner or a mitigation measure to it.
- Viewing the matrix as the end product, when it is actually a starting point for action.
Risk Matrix, Risk Analysis, or BIA: What's the Difference?
In practice, these three concepts are often used interchangeably. In short: the risk matrix is the visual core of your risk analysis, and the business impact analysis focuses specifically on the consequences of an outage.
| Instrument | What it's for |
|---|---|
| Risk matrix | Visualizes and prioritizes risks based on likelihood × impact. |
| Risk analysis | The broader process: identifying, assessing, and treating risks. |
| Business impact analysis | Determines the consequences of process failure, such as recovery time and maximum downtime. |
Want to know more about that last one? Read our explanation about the Business Impact Analysis.
Need help with your risk analysis?
We help you move from a loose risk matrix to a substantiated risk analysis that you can manage and that will convince a supervisor.
Frequently Asked Questions
What is a risk matrix?
A risk matrix is a grid that plots the probability of a risk against its impact. Each risk is assigned a score (probability × impact) and a color, from green for low to red for critical. This allows you to prioritize which risks require attention at a glance.
Should I use a 3x3, 4x4, or 5x5 matrix?
A 5x5 matrix offers the most nuance and makes distinctions between risks more visible. A 3x3 is quicker to fill out, but pushes many risks to the middle. Choose the 5x5 as soon as risk management becomes established in your organization.
How do you calculate a risk score?
You multiply the probability by the impact, both scored on a scale of 1 to 5. The outcome ranges from 1 to 25. The higher the score, the more urgent the risk. Link fixed thresholds to the color zones so that scores always have the same meaning.
Risicomatrix versus Risicoanalyse: Wat is het verschil? Hoewel de termen "risicomatrix" en "risicoanalyse" vaak door elkaar worden gebruikt, zijn er duidelijke verschillen. Simpel gezegd: * **Risicoanalyse** is het proces. * **Risicomatrix** is een hulpmiddel binnen dat proces. Laten we dit verder uitleggen: **Risicoanalyse** Risicoanalyse is een systematische en uitgebreide methode om potentiële risico's te identificeren, te evalueren en te prioriteren. Het doel is om te begrijpen welke bedreigingen invloed kunnen hebben op de doelen van een organisatie, project of proces, en hoe waarschijnlijk en ernstig deze bedreigingen zijn. De stappen in een risicoanalyse omvatten doorgaans: 1. **Risico-identificatie:** Het vaststellen van mogelijke risico's. Dit kan door middel van brainstormsessies, interviews, historische gegevens, checklists, etc. 2. **Risicoanalyse (kwalitatief & kwantitatief):** Het beoordelen van de waarschijnlijkheid (kans) dat een risico zich voordoet en de mogelijke impact (ernst) als het zich voordoet. Dit kan op een subjectieve (kwalitatieve) of een meer objectieve (kwantitatieve) manier gebeuren. 3. **Risico-evaluatie/prioritering:** Het bepalen welke risico's de grootste aandacht vereisen, gebaseerd op hun analyse. **Risicomatrix** Een risicomatrix (ook wel bekend als een kans-impact matrix of hittekaart) is een **visueel hulpmiddel** dat wordt gebruikt tijdens het risicoanalyseproces. Het is een grafische weergave die helpt bij het visualiseren en prioriteren van risico's op basis van hun waarschijnlijkheid en impact. De matrix is meestal een raster met op de ene as de waarschijnlijkheid (vaak met labels als Laag, Gemiddeld, Hoog) en op de andere as de impact (eveneens met labels als Laag, Gemiddeld, Hoog). Elk van de cellen in de matrix vertegenwoordigt een combinatie van waarschijnlijkheid en impact, en wordt vaak gekleurd om de mate van prioriteit aan te geven (bijvoorbeeld groen voor lage risico's, geel voor gemiddelde risico's en rood voor hoge risico's). **Hoe de Risicomatrix een onderdeel is van de Risicoanalyse:** * Nadat mogelijke risico's zijn geïdentificeerd (stap 1 van de analyse), worden deze risico's vervolgens geëvalueerd op hun waarschijnlijkheid en impact. * De uitkomsten van deze evaluatie worden **ingevoerd in de risicomatrix**. * De positie van een risico in de matrix helpt vervolgens bij het prioriteren ervan (stap 3 van de analyse). Risico's die zich in de "rode" zone bevinden (hoge waarschijnlijkheid en hoge impact) vereisen onmiddellijke aandacht en mitigatieplannen. **Samengevat:** * **Risicoanalyse** is het uitgebreide **proces** van het vinden, begrijpen en evalueren van risico's. * Een **Risicomatrix** is een **tool**, een visueel schema, dat **binnen** dat proces wordt gebruikt om de geanalyseerde risico's te categoriseren en te visualiseren, zodat de belangrijkste risico's snel geïdentificeerd kunnen worden voor verdere actie.
The risk matrix is the visual component that prioritizes risks. The risk analysis is the entire process surrounding it: identifying, assessing, treating, and monitoring risks. The matrix helps you with the assessment and prioritization within that analysis.
What colors do you use in a risk matrix?
The standard order is green, yellow, orange, and red, from low to critical. Green means accept or monitor, red means act immediately. Apply the colors consistently so that everyone in the organization interprets the same urgency.
What is the difference between inherent risk and residual risk?
The inherent risk is the score before measures; the residual risk is what remains after you have taken measures. The difference between the two shows how much your control yields. Supervisors and auditors mainly look at that residual risk.
How do you determine probability objectively?
Utilize historical incidents, threat intelligence, and multiple assessors instead of a single gut feeling. It will never be completely objective; the goal is a consistent and traceable rationale that you can document and repeat.
