The grid itself
A risk matrix places each identified risk on two axes: how likely it is to occur, and how severe the consequence would be. A simple three-by-three version is shown below; five-by-five variants add granularity but not accuracy. The output is a shared picture of where exposure concentrates, used to prioritise mitigation, assign owners and decide what the board needs to hear about.
| Likelihood \ Impact |
Low impact |
Medium impact |
High impact |
| High likelihood |
Monitor |
Mitigate actively |
Act now or stop the activity |
| Medium likelihood |
Accept and review |
Mitigate |
Mitigate and prepare contingency |
| Low likelihood |
Accept |
Accept and review |
Contingency plan: severity does not average away |
Where it pays off in a decision process
- Before approval of a major commitment, forcing the sponsoring team to write down what could go wrong while there is still a choice.
- As the standing spine of programme governance, provided each risk has a named owner, a mitigation with a date, and a trigger for escalation.
- In diligence, comparing the target's or vendor's own risk register against what an outside operator would put on it. The gaps are the finding.
A quick illustration
A retailer approving a warehouse automation programme drafts its matrix. "Key supplier delivery slippage" lands at high likelihood, medium impact: annoying but manageable. "Peak-season cutover failure" lands at low likelihood, high impact. The instinct is to spend the meeting on the first risk because it will probably happen. The discipline the matrix should enforce is the opposite: the second risk gets the contingency plan, because a failed cutover in November is the scenario the company cannot absorb, however unlikely the team believes it to be.
How the matrix gets gamed
The failure modes are behavioural and they repeat across industries.
- Scores are negotiated down before the pack goes up. A red risk demands an owner, a plan and an awkward conversation; amber demands a sentence. The gravitational pull towards amber is constant, and it is strongest just before board meetings.
- Everything clusters in the middle. Scorers avoid the corners because extremes invite challenge, producing the watermelon register: green and amber on the outside, red underneath.
- Likelihood is guessed without reference to base rates. Teams score their own programme as "unlikely to overrun" in a category of programmes that overrun more often than not.
- The arithmetic gets abused: multiplying ordinal scores (a 4 × 5 = 20) manufactures false precision from labels that were never numbers, and a high-likelihood trivial risk can outrank a plausible catastrophic one.
- The register becomes a filing cabinet. Risks are logged to discharge the obligation of having logged them, mitigations are described in the passive voice, and nothing has an owner or a date.
Keeping it honest with outside eyes
The matrix cannot correct the incentives of the people scoring it: a programme team scoring its own risks is grading its own homework. Independent perspectives from operators who have run comparable programmes recalibrate the two dimensions the team least wants to move: the likelihood of the risks everyone hopes are unlikely, and the impact of the ones being managed by optimism. A grid the whole team agrees with is not necessarily an honest grid. It may just be a shared set of hopes.