Framework

Risk Matrix

A risk matrix plots risks by likelihood and impact so attention and mitigation budget go where exposure is greatest. Its weakness is social, not mathematical: scores get negotiated down long before the board sees the grid.

Every programme has a risk matrix; very few have an honest one. The grid is only as good as the scoring conversations behind it, and those conversations are subject to pressures the framework does not defend against: optimism, ownership politics and the standing desire for a green dashboard.

Last reviewed 3 July 2026 · Free and ungated

Challenge the assumptions before committing

Selected senior operators will re-score your critical risks confidentially, based on what actually happened in comparable programmes.

Challenge the assumptions before committing

How a client brief works · What you receive

The grid itself

A risk matrix places each identified risk on two axes: how likely it is to occur, and how severe the consequence would be. A simple three-by-three version is shown below; five-by-five variants add granularity but not accuracy. The output is a shared picture of where exposure concentrates, used to prioritise mitigation, assign owners and decide what the board needs to hear about.

Likelihood \ Impact Low impact Medium impact High impact
High likelihood Monitor Mitigate actively Act now or stop the activity
Medium likelihood Accept and review Mitigate Mitigate and prepare contingency
Low likelihood Accept Accept and review Contingency plan: severity does not average away

Where it pays off in a decision process

  • Before approval of a major commitment, forcing the sponsoring team to write down what could go wrong while there is still a choice.
  • As the standing spine of programme governance, provided each risk has a named owner, a mitigation with a date, and a trigger for escalation.
  • In diligence, comparing the target's or vendor's own risk register against what an outside operator would put on it. The gaps are the finding.

A quick illustration

A retailer approving a warehouse automation programme drafts its matrix. "Key supplier delivery slippage" lands at high likelihood, medium impact: annoying but manageable. "Peak-season cutover failure" lands at low likelihood, high impact. The instinct is to spend the meeting on the first risk because it will probably happen. The discipline the matrix should enforce is the opposite: the second risk gets the contingency plan, because a failed cutover in November is the scenario the company cannot absorb, however unlikely the team believes it to be.

How the matrix gets gamed

The failure modes are behavioural and they repeat across industries.

  • Scores are negotiated down before the pack goes up. A red risk demands an owner, a plan and an awkward conversation; amber demands a sentence. The gravitational pull towards amber is constant, and it is strongest just before board meetings.
  • Everything clusters in the middle. Scorers avoid the corners because extremes invite challenge, producing the watermelon register: green and amber on the outside, red underneath.
  • Likelihood is guessed without reference to base rates. Teams score their own programme as "unlikely to overrun" in a category of programmes that overrun more often than not.
  • The arithmetic gets abused: multiplying ordinal scores (a 4 × 5 = 20) manufactures false precision from labels that were never numbers, and a high-likelihood trivial risk can outrank a plausible catastrophic one.
  • The register becomes a filing cabinet. Risks are logged to discharge the obligation of having logged them, mitigations are described in the passive voice, and nothing has an owner or a date.

Keeping it honest with outside eyes

The matrix cannot correct the incentives of the people scoring it: a programme team scoring its own risks is grading its own homework. Independent perspectives from operators who have run comparable programmes recalibrate the two dimensions the team least wants to move: the likelihood of the risks everyone hopes are unlikely, and the impact of the ones being managed by optimism. A grid the whole team agrees with is not necessarily an honest grid. It may just be a shared set of hopes.

Frequently asked questions

Is a five-by-five matrix better than a three-by-three?

Rarely. Extra cells add resolution the underlying judgements do not possess, and they widen the space for score negotiation. A coarser grid with brutal honesty beats a finer grid with diplomatic scoring. Spend the effort on evidence for likelihood, not on scale design.

How should low-likelihood, catastrophic risks be handled?

Never by the cell's colour alone. Severity of that order does not average away, so these risks need contingency planning and explicit board visibility even when the matrix paints them amber. If a risk could end the programme or the company, its likelihood score should not decide whether it is discussed.

Who should own the risk register: the PMO or the business?

The PMO can administer it, but each risk needs a business owner senior enough to fund the mitigation. A register owned wholly by the PMO becomes reporting; risk sits with people who can actually change the exposure.

Amber on the slide. Red in reality?

Challenge the assumptions before committing