A 5×5 risk matrix (likelihood × impact) is the most common tool in enterprise risk management, and the one most often used badly. Used well, it prioritises risks and drives consistent decisions. Used poorly, everything ends up red — or everything green — and the board stops trusting the register.
This guide covers how to build a matrix that works, how it fits the ISO 31000 risk management framework, and the failure modes that quietly make a matrix useless.
The Risk Matrix in ISO 31000
ISO 31000 does not mandate a 5×5 matrix — or any matrix. It defines a process: establish the context, then identify, analyse, evaluate and treat risk, with communication and monitoring running throughout. The matrix is a tool that serves two of those steps:
- Risk analysis — determining likelihood and consequence for each identified risk.
- Risk evaluation — comparing the analysed level against criteria to decide whether the risk is acceptable and what to do about it.
This matters practically. A matrix that is not tied to documented risk criteria (ISO 31000's term for the thresholds you evaluate against) is just a colouring exercise. The criteria come first; the matrix visualises them. Teams that build the grid before agreeing the criteria always end up re-scoring the whole register six months later.
| L \ I | I5 | I4 | I3 | I2 | I1 |
|---|---|---|---|---|---|
| L1 | 5 | 4 | 3 | 2 | 1 |
| L2 | 10 | 8 | 6 | 4 | 2 |
| L3 | 15 | 12 | 9 | 6 | 3 |
| L4 | 20 | 16 | 12 | 8 | 4 |
| L5 | 25 | 20 | 15 | 10 | 5 |
Green: low · Yellow: medium · Orange: high · Red: extreme. Calibrate scales to your risk appetite.
Why Use a Risk Matrix at All
- Consistency: everyone assesses likelihood and impact on the same defined scale, rather than by instinct.
- Prioritisation: higher scores attract attention and budget in a defensible order.
- Communication: boards and executives read a grid faster than they read a table of numbers.
- Traceability: each cell links to controls, treatments and owners, so a score implies an action.
Defining Likelihood
Define what each level means in your context, with frequency or probability wherever you can. Vague words are the main source of inconsistent scoring.
| Level | Descriptor | Example definition |
|---|---|---|
| 1 | Rare | Not seen in the industry in recent memory; < 2% in the planning horizon |
| 2 | Unlikely | Could occur but not expected short term; 2–10% |
| 3 | Possible | Has occurred in similar organisations; 10–40% |
| 4 | Likely | Expected at least once in the planning horizon; 40–75% |
| 5 | Almost certain | Will occur, or is already occurring; > 75% |
Always state the time horizon. "Likely" over ten years and "likely" over one quarter are different risks, and without a stated horizon two assessors will score the same risk two levels apart.
Defining Impact
Impact must be expressed in terms that matter to your organisation, and a mature scale is multi-dimensional — financial, regulatory, reputational, safety, operational. A risk scores at the highest level it reaches on any dimension.
| Level | Financial | Regulatory | Operational |
|---|---|---|---|
| 1 Negligible | < €10k | Observation only | < 1 day, one team |
| 2 Minor | €10k–50k | Minor finding | 1–3 days, one function |
| 3 Moderate | €50k–250k | Reportable breach | Up to 1 week, several functions |
| 4 Major | €250k–1m | Enforcement action, fine | Multi-week, core service degraded |
| 5 Severe | > €1m | Licence at risk | Core service down, viability threatened |
Replace those bands with your own — they should be calibrated to the organisation's size, ideally anchored to something concrete like a percentage of revenue or of regulatory capital. A €250k loss is catastrophic for one firm and a rounding error for another.
Use the same scale for inherent risk (before controls) and residual risk (after controls), so the matrix demonstrates what your control environment is actually buying you.
Calibrating to Risk Appetite
Risk appetite defines how much risk you are willing to accept, and it sets the colour thresholds:
- Green — within appetite; monitor on the normal cycle.
- Amber — requires review; treat, or accept with explicit documented approval at the right level.
- Red — beyond appetite; must be reduced or escalated to the board.
Two diagnostics tell you the calibration is wrong:
- Everything is red. Either your scales are too harsh, your appetite is stated too conservatively, or you are scoring inherent risk and comparing it to residual thresholds. Fix the definitions, not the scores.
- Everything is green. Usually under-assessment, often because owners score their own risks and a red risk implies criticism. Independent challenge in the review cycle is the fix.
A healthy register typically has a small number of reds, a meaningful amber band, and a long green tail.
The Failure Modes Nobody Warns You About
Range compression. Assessors cluster on 3s because the middle feels safe. If your register is 70% 3×3, the matrix is not discriminating and provides no prioritisation. Force distribution in workshops, or move to a 5×5 with sharply defined anchors.
Multiplying ordinal numbers. Likelihood 2 × impact 5 = 10, and likelihood 5 × impact 2 = 10, but these are not the same risk — one is a rare catastrophe, the other a constant nuisance. Treat the score as a sorting aid, never as an arithmetic quantity, and let the matrix position drive the decision rather than the product alone. Many organisations deliberately colour the top-left (rare/severe) cells red regardless of score for exactly this reason.
Averaging across dimensions. A risk with severe regulatory impact and negligible financial impact is not a "moderate" risk. Take the maximum across dimensions, not the mean.
Scoring the risk rather than the scenario. "Cyber risk" cannot be scored. "Ransomware encrypts the production database and backups are unusable for 72 hours" can. Write risks as scenarios with a cause, an event and a consequence, and scoring becomes repeatable across assessors.
Frozen scores. A matrix reviewed annually is a historical document. Scores should move when incidents occur, controls fail, or key risk indicators breach thresholds.
Linking the Matrix to Treatment and Ownership
A matrix is only useful if it drives action. ISO 31000 sets out the treatment options:
- Treat — reduce likelihood or impact with controls, then reassess residual risk.
- Tolerate — accept within appetite; document the rationale and monitor.
- Transfer — insure, or shift contractually to a third party (insurance and risk).
- Terminate — stop the activity or exit the exposure.
Every risk needs a named owner, a treatment decision, and a review date. A red risk with no owner is not being managed; it is being displayed.
From Matrix to Risk Register
The matrix is the view; the risk register is the record. An ISO 31000-aligned register carries, for each risk: the scenario description, category, inherent score, controls, residual score, treatment option, owner, review date, and the linked indicators and incidents.
In a live risk platform like ActiveERM, the heat map is generated from that register rather than maintained separately — so when a control is added or an incident is logged, the residual score and the matrix move together. That is the difference between a matrix that reflects reality and a slide that reflects last year's workshop.
Getting Started
- Agree risk criteria and appetite with the board before building the grid.
- Write likelihood and impact definitions with numbers, and state the time horizon.
- Score a pilot set of 20 risks with two independent assessors and compare — the gaps show you where the definitions are still vague.
- Fix the definitions, then roll out.
- Review scores on a defined cadence and whenever an incident or indicator says something changed.
For more on risk assessment and ERM, see our Risk OS and GRC Cloud pages, or request a demo.