Risk matrix #
Objective #
The Risk Matrix menu distributes the scenarios on an interactive 5 × 5 grid. The selector chooses the raw, current or residual score.
Calculation #
Likelihood and impact range from 1 to 5; the score is their product. Default: low up to 4, moderate up to 9, high up to 16, critical above. The organization can customize these thresholds.
Usage #
Change the assessment type, select a cell then open the associated risks. The color is only a marker: the level and the score remain textual.
Best practices #
Compare the three views to explain the effect of the controls and the remaining risk. An empty cell does not prove the absence of risk: check the register and filters.
Read the axes #
The matrix crosses likelihood and impact. A cell brings together the scenarios having the same combination for the chosen type. The text level depends on the tenant's thresholds, not just the displayed color.
Analysis path #
- Select Raw to view the intrinsic exposure.
- Change to Current to measure the effect of existing controls.
- See Residual for the target after treatment.
- Open high or critical cells.
- Check responsible, review date, processing and actions.
Thresholds #
Default values are low 1–4, moderate 5–9, high 10–16, and critical 17–25. An organization can customize them. Document any modification: it can change the level displayed without changing likelihood, impact or score.
Interpretation #
A migration to a lower cell is only relevant if it is based on documented measures or decisions. Also compare the number of risks: an average improvement can hide several critical scenarios.
Accessibility and export #
Don't be fooled by the color. Use score, level and list of scenarios. For a report, export the corresponding log and record the type of assessment and thresholds used.