Skip to main content
All articles

Risk Governance

How to Build a Risk Assessment Matrix—and Avoid Misleading Scores

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

How to Build a Risk Assessment Matrix—and Avoid Misleading Scores: original RiskSensai editorial cover

A matrix helps organize judgment

A risk matrix places a scenario against likelihood and consequence bands. It can help people compare their concerns and agree which decisions need attention. It becomes misleading when the colors appear more certain than the evidence behind them.

NIST SP 800-30 discusses qualitative and quantitative assessment approaches and uncertainty.1 Your choice should fit the information available and the decision being made. A five-point scale does not create precise probabilities or financial estimates by itself.

Before designing a matrix, decide what it should support. Prioritizing a small operational backlog is different from deciding whether to accept a potentially severe safety event. One matrix may not be appropriate for both.

Define the assessment boundary

State the activity, scenario and horizon. “Likelihood next quarter” and “likelihood over five years” are different questions. A matrix without a horizon invites owners to answer whichever version they find easiest.

Name the consequence dimensions that matter: service interruption, financial effect, privacy, safety, contractual exposure or customer harm. Explain whether the overall consequence follows the highest applicable dimension or another agreed method. Do not bury a severe impact by averaging it with less consequential dimensions.

Record the treatment stage. Current residual risk reflects controls currently operating. Target risk reflects a future state after proposed improvements. Place them in different fields so a planned control cannot improve today's rating.

An illustrative three-band matrix

This is an original fictional design for discussion, not a recommended universal scale. A business would need to adapt the bands, criteria and authorities to its own activity.

Consequence / likelihoodLower likelihoodPlausibleMore likely
Limited consequenceRoutine owner reviewRoutine owner reviewPlanned improvement
Significant consequencePlanned improvementManagement decisionPriority management decision
Severe consequenceEscalate for explicit decisionEscalate for explicit decisionImmediate escalation

Here the cells direct a decision process rather than merely display a color. “Escalate” means a named authority receives the scenario, assumptions and proposed response. It does not automatically mean the activity must stop; that decision requires the relevant authority and circumstances.

Define consequence in business language

For a customer-support service, a limited consequence might be a short interruption recoverable through existing procedures. A significant consequence could affect a contractual response commitment. A severe consequence could involve a sustained inability to serve customers or another material exposure.

Replace these descriptions with your own approved thresholds and obligations. If financial values are used, explain the currency, period and estimation basis. If several effects differ, record them individually before selecting an overall band.

Define likelihood with reasons

Use observations such as incident history, exposure, dependency changes and control evidence. If reliable probabilities are unavailable, do not label a band “exactly 10%” merely to make it look quantitative.

An owner might record “plausible during the next quarter because this dependency has failed twice, and the corrective action is unverified.” Another may record “lower likelihood based on a tested alternate arrangement, with limited data about an extended outage.” The narrative explains both the rating and its limits.

Why multiplying scores can mislead

Suppose a team uses likelihood and consequence scales from one to five. A likelihood of two multiplied by consequence five produces ten. Likelihood five multiplied by consequence two also produces ten.

Those scenarios can require very different responses. A frequent minor delay may warrant operational improvement; a less frequent severe event may require leadership acceptance or a mandatory safeguard. Equal products do not establish equal importance.

The scale is also ordinal: five means a higher band than four, not necessarily a consequence exactly 25% greater. Treating those labels as measured quantities can introduce false precision. If multiplication is retained for sorting, show the underlying bands and apply separate escalation rules.

Worked example: two service interruptions

This fictional company depends on a ticketing tool and a payment-processing service. Its horizon is the next quarter.

ScenarioEstimated bandWhy the response differs
Ticketing tool slows briefly during peak demandMore likely, limited consequenceStaff can use a tested temporary process; improvement can be scheduled
Payment service becomes unavailable before an important cutoffLower likelihood, severe consequenceCurrent fallback is unverified; leadership needs a decision and a checked response

If both receive the same numeric product, the team should not place them in an identical work queue. The matrix must preserve the payment cutoff consequence, evidence gap and escalation requirement.

NIST IR 8286A Revision 1 supports documenting scenarios and their estimates in a risk register.2 Keep that scenario record behind the matrix so a reviewer can inspect what the cell represents.

Add confidence and a sensitivity check

Confidence describes how well the evidence supports the estimate. The evidence-collection checklist can help record source, coverage and limitations. It should not be mixed into the risk score without a clear method. Use a brief explanation: “low confidence because the supplier has not provided outage-duration information.”

Then vary a material assumption. If the payment interruption lasts two hours instead of one day, does the response change? If the fallback handles half the transactions rather than all, is it still acceptable?

Record the assumption range and decision effect. When the same response is appropriate across plausible estimates, spending weeks debating a score may add little value. When the decision changes, better evidence may be the most important next action.

Verify controls before lowering the rating

A control's existence and its effectiveness are different questions. A recovery policy may define a target while a restore exercise reveals that essential configuration is missing.

NIST SP 800-53A describes examining, interviewing and testing as assessment methods.3 Use an appropriate method to check a claimed control. Do not require a destructive production test; choose a safe, authorized way to establish the relevant evidence.

Record scope, date, result and exceptions. If the control is untested, show that uncertainty. If a treatment is incomplete, keep the current rating and proposed target separate until the evidence supports a change.

Make the matrix accessible and explainable

Use text labels such as “management decision” alongside colors. A grayscale printout or a reader with color-vision differences should retain the meaning. Show the band definitions near the matrix and preserve the assessment date.

Assign review responsibility for inconsistent ratings. When two owners rate similar exposures differently, discuss the assumptions rather than force superficial agreement. A documented difference may be reasonable when scope or consequences differ.

Review checklist before adoption

Confirm that the matrix has:

  1. A stated activity and time horizon.
  2. Written likelihood and consequence definitions.
  3. A rule for multiple consequence dimensions.
  4. Separate current and target states.
  5. Reasons and evidence for each estimate.
  6. Confidence notes and material assumptions.
  7. Escalation rules for severe or constrained exposures.
  8. Named authority for acceptance decisions.
  9. Review dates and change triggers.
  10. Text meanings that remain readable without color.

Use the matrix to improve the quality of decisions, then judge it by those decisions. A precise-looking dashboard is less valuable than a modest scoring method that exposes uncertainty and directs accountable action.

Sources and references

  1. NIST. Guide for Conducting Risk Assessments, SP 800-30 Revision 1 (2012-09). Risk-assessment guidance originally developed for federal information systems; business examples here are an adaptation. ↩

  2. NIST. Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management, IR 8286A Revision 1 (2025-12-18). Current revision supports scenario-based risk registers and likelihood/impact estimates; supersedes the 2021 publication. ↩

  3. NIST. Assessing Security and Privacy Controls, SP 800-53A Revision 5 (2022-01). Describes examination, interview and testing methods; source examples are adapted, not a claim to meet federal requirements. ↩

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • Risk Assessment
  • Risk Matrix
  • Risk Scoring
Connecting to your conversation workspace…