Skip to content

Risk matrices

A risk matrix is the encoded judgement that turns “likely, and severe” into “critical”. It is a lookup table mapping a probability and an impact to a resulting risk level, and it is what lets a risk assessment produce comparable numbers instead of a collection of opinions.

Catalog → Risk matrices in the sidebar.

Every matrix has four parts:

  • Probability levels — the ordered likelihood scale, for example negligible, low, medium, high, very high.
  • Impact levels — the ordered severity scale, expressed however your organization measures consequence.
  • Risk levels — the resulting categories, usually colour-coded: low, medium, high, critical.
  • The grid — the lookup from each probability-by-impact cell to a risk level.

The grid is the substance. Two matrices with identical axis names can produce very different answers depending on which cells they call critical, which is why “we use a five-by-five matrix” says almost nothing on its own.

Like frameworks, matrices are packaged as libraries and loaded, so this page offers an import shortcut rather than an add button. It takes you to Libraries filtered to matrix content. The Enabled column controls whether a loaded matrix is offered when someone creates a risk assessment — a quick way to steer everyone onto the one matrix you have standardised on without deleting the others.

When a risk assessment is created, its matrix is captured and stays fixed for the life of that assessment. This is not a limitation to work around — re-scoring existing scenarios against a different grid would silently change every risk level after the fact, which is exactly what an auditor will object to.

If your organization changes matrices mid-programme, create a new risk assessment against the new matrix and migrate the scenarios. The old assessment keeps its history; the new one starts clean on the new scale.

Each scenario in an assessment is read against the same matrix three times, with a different probability-and-impact pair at each tier:

  • Inherent — what the risk would be with no controls at all.
  • Current — what it is today, given the controls actually in place.
  • Residual — what it will be once the planned controls are implemented.

The gap between current and residual is the argument for your action plan; the gap between inherent and current is the argument for the controls you already run.

How a matrix is drawn is a display preference, separate from its definition. General settings let you swap which axis carries probability and which carries impact, flip the grid vertically, and choose between ISO and EBIOS axis terminology. Changing any of these alters the rendering everywhere, not the underlying grid, so nobody’s scores move.

Start from a published matrix that matches your method rather than designing one. Designing a grid well is harder than it looks — the interesting judgements live in the corners, and a grid that marks too much as critical trains people to ignore the label. If you do need your own, adapt an existing definition instead of starting from a blank sheet, and author it as a library so it can be loaded, versioned and upgraded like any other catalog content.