Beyond Amazing
The Strategy Toolkit

Risk

Risk Matrix

Places each risk on a grid of likelihood against impact so that limited attention and budget flow to the risks that are both probable and damaging, with a distinct response posture, from acceptance through to avoidance, attached to each quadrant.

Also known as Probability-impact matrix, Likelihood-severity matrix, Risk heat map. First set out by United States Department of Defense system safety practice in 1969; the primary source is cited in full below.

Where this is contested

The documented root is US military system safety practice, MIL-STD-882 of 1969, with the explicit likelihood-by-severity matrix appearing in the 1984 MIL-STD-882B revision; the tool's spread through civilian project, safety and enterprise risk management was diffuse and cannot be credited to a single author.

Format
2×2 matrix
Level
Corporate · Business unit · Team
Best for
Assess risk · Prioritise
Decision stage
Diagnose · Decide · Plan
Difficulty
Introductory
Time to apply
A half-day workshop for a first register; the discipline is in the reviews that follow.

Plate · The model

Transfer or planMitigate or avoidAcceptMonitor andcontrolLowLikelihoodHighLowImpactHigh
The four positions of Risk Matrix, read against likelihood on the horizontal and impact on the vertical.
I

The components

1

Transfer or plan

High impact, low likelihood: the rare events that could sink the enterprise. Because likelihood is low, continuous mitigation spend is hard to justify; because impact is severe, doing nothing is negligent. The classic responses are transferring the risk to a party better placed to carry it, through insurance or contract, and preparing contingency plans so the organisation is not improvising on the day.

Signals of strength
Would threaten solvency, life or licence to operate if it occurred · Rare in your own history but documented in the sector's · Insurable, or transferable by contract to suppliers or partners · A written contingency plan would materially change the outcome

2

Mitigate or avoid

High impact, high likelihood: the intolerable corner. These risks demand immediate treatment to push likelihood down, cap the impact, or both; where treatment cannot bring the risk within appetite, the activity itself should be redesigned or abandoned. This quadrant sets the priority order for risk spend.

Signals of strength
Both credible on current evidence and severe in consequence · Sits outside the organisation's stated risk appetite · Named on past incident or near-miss reports · Controls exist on paper but fail when tested

3

Accept

Low impact, low likelihood: risks not worth the cost of treating. The disciplined move is explicit acceptance, recorded in the register with an owner, rather than silent neglect. Acceptance is a decision that can be revisited; forgetting is not.

Signals of strength
Consequence absorbable within normal operations · Treatment would cost more than the expected loss · No plausible path for the risk to escalate · Formally logged and reviewed rather than merely unmentioned

4

Monitor and control

Low impact, high likelihood: the frequent nuisances. Individually tolerable, they are managed through routine procedures and cheap controls, and watched, because frequency is where aggregation and drift live. Many small losses can sum to a large one, and a rising frequency is often the early signal of a bigger failure.

Signals of strength
Occurs often but each occurrence is absorbable · Cheap procedural or design controls are available · Losses aggregate to a material annual cost · Frequency trending upwards between reviews

II

When it earns its keep

  • You have a long list of identified risks and need a defensible way to decide which few get money, time and senior attention.
  • A project, event or venture needs a risk register that non-specialists can read at a glance and challenge in a meeting.
  • You need a common language for risk across teams with different specialisms, so that a safety risk and a commercial risk can at least be discussed on the same page.
  • Regulators, insurers or licensing authorities expect documented risk assessment, as event safety, health and safety and corporate governance regimes commonly do.

And when it doesn't

  • The decision turns on precise quantities, for instance capital reserving, insurance pricing or safety cases for engineered systems. Use quantitative risk analysis; an ordinal grid cannot carry that weight.
  • Risks are strongly correlated or cascade into one another. The matrix scores risks one at a time and is blind to the combination that actually causes disasters.
  • The hazard landscape is genuinely novel or unknowable, where forced likelihood estimates manufacture false confidence; a Cynefin-style sorting of the situation comes first.
  • The exercise is being run to produce a compliance artefact rather than decisions. A matrix nobody revisits is wallpaper.
III

How to run it

Before starting, gather the inputs the analysis depends on:

  • A risk identification exercise that has actually been done: named risks with causes and consequences, drawn from the people closest to the work.
  • Agreed definitions of the likelihood and impact scales, written down before scoring starts, with impact defined across the dimensions that matter (financial, safety, reputational, legal).
  • Evidence to anchor likelihood judgements: incident history, industry data, near-misses, expert judgement declared as such.
  • Clarity on whether risks are being scored before or after existing controls (inherent versus residual risk), applied consistently.
  • An owner for each risk, since a risk without an owner is an observation, and a risk appetite statement to score against.
  1. 1

    Set the context and define the scales

    Agree what low and high mean before anything is scored: for likelihood, indicative frequencies or probabilities; for impact, concrete thresholds in money, injury, downtime or reputation. Practice commonly uses 3x3 or 5x5 grids for finer grading, as MIL-STD-882 itself does; the 2x2 presented here is the reduction that exposes the logic, and everything said of it applies to the larger grids.

  2. 2

    Identify and describe the risks

    Gather risks from the people who run the work, incident logs and structured prompts, and describe each as cause, event and consequence. 'Weather' is a category; 'sustained high winds force closure of the main stage on the busiest day' is a risk that can be scored and owned.

  3. 3

    Score likelihood and impact for each risk

    Rate each risk against the agreed scales, using evidence where it exists and declared judgement where it does not. Decide whether you are scoring inherent risk or residual risk after current controls, and hold that choice constant across the register, since mixing the two is the fastest way to a meaningless grid.

  4. 4

    Place risks on the grid and read the quadrants

    Plot every risk. High impact and high likelihood demands action to reduce one axis or the other, or to redesign the activity so the risk cannot arise. High impact and low likelihood suits transfer through insurance or contract, backed by contingency plans. Low and low is accepted and logged. Low impact and high likelihood is managed through routine controls and monitoring, with an eye on aggregation.

  5. 5

    Assign responses and owners

    Attach to each risk a response consistent with its quadrant, drawn from the standard repertoire of avoid, mitigate, transfer and accept, plus a named owner, actions and dates. The grid position is a triage verdict, never the analysis itself; the response is where the thinking shows.

  6. 6

    Review, re-score and challenge

    Revisit the register on a rhythm and when circumstances change. Ask which risks have moved, which controls have decayed, and whether near-misses contradict the likelihood scores. A matrix that looks the same twelve months on has stopped being used.

IV

Reading the result

A prioritised risk register: every identified risk placed on the likelihood-impact grid, with a response posture, owner and actions attached to each, and a short list of intolerable risks demanding immediate treatment.

  • Read the top-right first: those risks are the agenda. Everything else is queueing.
  • Treat grid position as triage, never as measurement. Two risks in the same cell can differ enormously in expected loss, a defect known as range compression.
  • Check the top-left has plans, and premiums, attached. Rare-but-severe is where organisations are most often underprepared, precisely because experience keeps suggesting the risk is theoretical.
  • Watch movement between reviews rather than the static picture. A risk migrating rightwards is the register earning its keep.
V

A worked example

A festival operator triages risks for a greenfield summer event

An outdoor events company stages a 15,000-capacity three-day music festival on a farm site in Shropshire. Ahead of the licensing submission, the operations director runs the risk register through a likelihood-impact matrix to decide where the contingency budget and the safety team's attention go. Scales are agreed first: high impact means serious injury, event cancellation or a six-figure loss; high likelihood means expected in a typical event cycle.

Transfer or plan
Severe weather forcing cancellation, and a headliner cancelling late, both land here: rare in any given year, ruinous if they occur. Responses: event cancellation insurance including adverse-weather cover, force-majeure and replacement clauses in artist contracts, a costed show-stop and evacuation plan, and a wet-weather ground plan agreed with the farmer. The premium hurts; one washed-out Friday would hurt far more.
Mitigate or avoid
Crowd crush at the main-stage front barrier scores high on both axes for a first-year site with untested crowd flows. Mitigations: redesigned arena layout with wider egress, a front-of-stage pit team, capacity throttling on the arena, and an experienced crowd-safety contractor. A proposed late-night secondary stage in a narrow walled yard could not be brought within appetite and was dropped: avoidance, chosen over clever mitigation.
Accept
Minor first-aid presentations, small-scale bar stock losses and localised sound complaints from one distant hamlet are logged and accepted: low likelihood of escalation, consequences absorbable, treatment cost above expected loss. Each is recorded with an owner so acceptance stays a decision rather than an oversight.
Monitor and control
Long bar and toilet queues, ticket-scanning failures at peak ingress and petty theft from tents are near-certain but individually minor. Routine controls: queue marshals and pour-speed targets, offline scanning fallback, locker hire and patrols. All are monitored live, because queue length and gate throughput are also the early-warning indicators for the crowd risks in the top-right.

The read. The matrix put the contingency budget where the register said it should go: the largest single spends are the insurance premium in the top-left and the crowd-safety package in the top-right, while dozens of minor risks were consciously accepted rather than padded with controls. The honest caveat is that the grid did the triage, never the analysis: the crowd-crush judgement rests on the safety contractor's modelling, and the 2x2 would licence the same conclusion whether the true likelihood were 1 in 20 or 1 in 200. The register goes to the Safety Advisory Group as a 5x5 with the same underlying scores.

VI

Pitfalls

  • Scoring before defining the scales. Unanchored labels like 'likely' and 'severe' mean different things to different scorers, and the grid inherits every inconsistency.
  • Mixing inherent and residual scoring in one register, which makes well-controlled risks look small and uncontrolled ones look manageable.
  • Multiplying ordinal scores as if they were numbers. A 4x2 is not twice a 2x2; the arithmetic has no meaning on an ordinal scale, however tidy the heat map looks.
  • Treating the matrix as the analysis. It is a communication and triage device; the analysis is the evidence behind each score and the response attached to it.
  • Scoring risks independently when the real threat is correlation: the wet weekend that simultaneously cuts ticket revenue, churns the car parks and stretches the medical team.
  • Letting the register fossilise. Risks move; a matrix reviewed annually to the same picture is recording effort rather than managing anything.
VII

What the critics say

Cox's formal analysis showed that risk matrices can correctly and unambiguously compare only a small fraction of randomly selected hazard pairs, can assign identical ratings to quantitatively very different risks (range compression), can rate some larger risks below smaller ones (rank reversal), and under some conditions perform worse than random in allocating mitigation resources. He derived axioms (weak consistency, betweenness, consistent colouring) that valid matrices must satisfy, and showed many published matrices violate them.

Cox, L. A. (2008) 'What's Wrong with Risk Matrices?', Risk Analysis, 28(2), pp. 497-512.

Thomas, Bratvold and Bickel found that the risk rankings a matrix produces depend heavily on arbitrary design choices, the number of cells, the scoring scales, how scores combine, and concluded that risk matrices can produce arbitrary decisions while conferring unwarranted confidence in them.

Thomas, P., Bratvold, R. B. and Bickel, J. E. (2014) 'The Risk of Using Risk Matrices', SPE Economics and Management, 6(2), pp. 56-66.

Hubbard argues that ordinal scoring methods add noise rather than insight, functioning as an 'analysis placebo' that increases confidence without improving decisions, and that even crude quantitative methods calibrated against evidence outperform qualitative grids.

Hubbard, D. W. (2009) The Failure of Risk Management: Why It's Broken and How to Fix It. Hoboken: Wiley.

Ball and Watt tested the matrix's reliability rather than its logic and found it wanting: different assessors assign widely different ratings to the same hazard, the scatter persists even after reflection and training, and the divergence traces to worldviews, beliefs and psychosocial factors that the tidy grid never surfaces. A tool whose output depends this much on who fills it in cannot claim to rank hazards objectively.

Ball, D. J. and Watt, J. (2013) 'Further Thoughts on the Utility of Risk Matrices', Risk Analysis, 33(11), pp. 2068-2078.

Duijm's design review catalogued further structural weaknesses: ordinal category scales cannot support the multiplication routinely performed on them, ratings shift with how categories and cell boundaries are defined, and aggregating scored risks is mathematically dubious. He recommends continuous probability-consequence diagrams wherever quantitative information exists, reserving matrices for coarse screening at most.

Duijm, N. J. (2015) 'Recommendations on the use and design of risk matrices', Safety Science, 76, pp. 21-31.
VIII

Work it through

Drop each risk into the quadrant matching its likelihood and impact, then record the planned response and owner beside it. Your entries persist for this browser session and can be copied out as Markdown or printed.

Transfer or plan
Mitigate or avoid
Accept
Monitor and control

0 of 4 blocks filled

IX

Sources and further reading

  • United States Department of Defense (1969) MIL-STD-882: System Safety Program Requirements, 15 July 1969, and subsequent revisions through MIL-STD-882E (2012). ↗
  • Cox, L. A. (2008) 'What's Wrong with Risk Matrices?', Risk Analysis, 28(2), pp. 497-512. ↗
  • Thomas, P., Bratvold, R. B. and Bickel, J. E. (2014) 'The Risk of Using Risk Matrices', SPE Economics and Management, 6(2), pp. 56-66.
  • ISO 31000:2018 Risk Management: Guidelines. Geneva: International Organization for Standardization (context for the modern risk-treatment vocabulary). ↗

Pairs well with Impact-Effort Matrix·Cynefin Framework·SWOT Analysis·PESTEL Analysis·Reference Class Forecasting·Three Lines of Defence·compare side by side

Near neighbours (computed from shared tags)·Failure Mode and Effects Analysis·Stakeholder Mapping (Power-Interest Grid)·AI Risk Management Framework (NIST AI RMF)