Skip to main content
Category: Risk Assessment & Analysis

Risk Matrix

Also known as: Risk Assessment Matrix, 5x5 Risk Matrix
Simply put

A risk matrix is a visual tool, usually shown as a grid or table, that helps people judge how serious a risk is by combining how likely it is to happen with how much harm it could cause. Teams use it to compare risks and decide which ones to address first. It supports decision-making but does not itself remove or eliminate the underlying risks.

Formal definition

A risk matrix is a grid-based instrument used during risk assessment to characterize the level of risk by cross-referencing a likelihood (or probability) category against an impact (or consequence) category, with each cell typically mapped to a qualitative risk rating. Common implementations include the 5x5 matrix, which represents five likelihood levels against five impact levels as a table or grid. It functions as a prioritization and communication aid to rank and triage risks for mitigation, rather than as a quantitative measurement or control mechanism. The specific scoring conventions, category definitions, and rating schemes vary by organization and application context, and are not standardized across all frameworks.

Why it matters

A risk matrix matters because organizations rarely have the resources to address every identified risk simultaneously, and they need a defensible way to decide which risks warrant attention first. By combining likelihood against impact, the matrix gives teams a shared visual language for comparing dissimilar risks and communicating priorities to stakeholders who may not share a technical background. In AI governance and model risk management contexts, this makes it a common triage aid for ranking risks surfaced during assessment, so that mitigation effort can be directed toward the highest-rated concerns.

Its value, however, is bounded and frequently overstated. A risk matrix supports decision-making but does not itself remove, reduce, or control any underlying risk; the mitigation work happens elsewhere. Because scoring conventions, category definitions, and rating schemes vary by organization and are not standardized across frameworks, two teams can rate the same risk differently, and a matrix can create a false sense of precision when the inputs are qualitative judgments. Professionals should treat a matrix as a prioritization and communication instrument rather than a quantitative measurement of risk.

A further limitation worth flagging is that the matrix's usefulness depends entirely on the quality of the likelihood and impact estimates fed into it. Poorly calibrated categories, inconsistent application across assessors, or treating a completed matrix as evidence that risk has been handled can all undermine its purpose. Used carefully, it clarifies where to focus; used uncritically, it can obscure rather than inform.

Who it's relevant to

Model Risk Managers
Those responsible for identifying, measuring, monitoring, and controlling model-related risks may use a risk matrix to triage and prioritize the risks surfaced during assessment. It helps rank concerns for mitigation, but it does not measure model risk quantitatively or substitute for the underlying controls and monitoring work.
AI Governance and Compliance Professionals
Governance and compliance teams often rely on a risk matrix as a communication tool to present prioritized risks to oversight bodies and stakeholders in an accessible visual form. They should be aware that ratings reflect qualitative judgment and that category definitions are not standardized across frameworks, so consistent internal conventions matter.
Auditors and Reviewers
Auditors reviewing risk assessment processes may encounter risk matrices as evidence of how risks were prioritized. They should evaluate whether the likelihood and impact categories were applied consistently and whether the matrix was treated as a triage aid rather than as proof that risk has been mitigated or eliminated.
Risk Assessment and Project Teams
Teams conducting assessments use the matrix to plot potential threats and focus mitigation efforts on the highest-rated items. Its usefulness depends on the quality and calibration of the estimates entered, so teams should guard against treating a completed matrix as a false signal of precision.

Inside Risk Matrix

Likelihood (Probability) Axis
One dimension of the matrix, typically representing the estimated frequency or probability that a given risk event will occur, often expressed on an ordinal scale (for example, rare to almost certain). The chosen scale and its labels are defined by the organization and are not standardized across frameworks.
Impact (Severity/Consequence) Axis
The other dimension, typically representing the magnitude of harm or consequence should the risk materialize, often ranging from negligible to severe. As commonly applied, impact categories may cover financial, operational, reputational, legal, or safety dimensions, depending on scope.
Risk Cells and Rating Bands
The intersecting cells formed by the two axes, each yielding a composite risk level (for example, low, medium, high, or critical). Bands are usually color-coded and reflect organizational thresholds rather than a universal standard.
Scoring or Weighting Convention
The method used to combine likelihood and impact into a rating, which may be a simple lookup, a multiplicative score, or a qualitative judgment. The convention is an organizational design choice and can materially affect the resulting prioritization.
Inherent Versus Residual Risk Positioning
A matrix may be used to plot risk before controls (inherent) and after controls (residual). These are distinct positions on the same matrix and should not be conflated; residual placement assumes controls are effective, which itself typically requires validation.
Response or Escalation Thresholds
Predefined rules linking a risk's placement to required actions, such as escalation, additional controls, or acceptance. Thresholds connect the matrix to governance and oversight processes rather than being intrinsic to the matrix itself.

Common questions

Answers to the questions practitioners most commonly ask about Risk Matrix.

Does a risk matrix measure risk objectively?
No. A risk matrix organizes and communicates risk assessments, but the underlying likelihood and impact ratings are typically the product of expert judgment and defined scoring criteria rather than objective measurement. The tool structures and displays those judgments; it does not itself produce objective values. Professionals often err by treating a matrix cell as a precise measurement when it usually reflects qualitative or semi-quantitative estimates whose reliability depends on the inputs and the rating definitions used.
Does placing a risk in a low cell mean the risk has been eliminated?
No. A low rating typically indicates that, under the assessment's assumptions, the combination of likelihood and impact is judged to be comparatively minor or within tolerance. It does not mean the risk no longer exists or that controls have removed it. As commonly framed, a matrix supports prioritization and helps distinguish inherent from residual risk, but it manages and communicates risk rather than eliminating it, and low-rated risks may still require monitoring.
How should likelihood and impact scales be defined for a risk matrix?
In many frameworks, scales are defined in advance using explicit, documented criteria so that ratings are applied consistently across assessors and over time. Definitions can be qualitative, semi-quantitative, or quantitative depending on the organization's methodology. The exact number of levels, thresholds, and labels varies by organization and is not standardized across all contexts, so the definitions should be documented as part of the assessment methodology.
Should a risk matrix use inherent or residual risk ratings?
Practice varies, and the two are distinct. Some assessments plot inherent risk (before controls), some plot residual risk (after controls), and some display both to show the effect of controls. Because inherent and residual risk answer different questions, it is generally advisable to state explicitly which basis a given matrix reflects to avoid misinterpretation.
How often should a risk matrix be reviewed and updated?
Review cadence typically depends on the organization's policies, the volatility of the risks involved, and any applicable governance requirements. Because ratings reflect judgments made under specific assumptions, they can become outdated as conditions, controls, or model behavior change. Many organizations tie reassessment to defined triggers such as material changes or scheduled review cycles, but no single universal frequency applies across all contexts.
Who should be responsible for populating and approving a risk matrix?
Responsibility often maps to an organization's lines-of-defense structure, where risk-owning functions perform initial assessments and independent oversight functions review or challenge them, though specific roles vary by organization. Because a matrix reflects judgment-based inputs, documenting who assigned ratings, who reviewed them, and on what basis supports accountability and traceability within the broader governance process.

Common misconceptions

A risk matrix produces objective, quantitative risk measurements.
In most applications a risk matrix relies on ordinal, qualitative ratings and expert judgment. The numbers or bands express relative prioritization rather than precise, additive quantities, and combining ordinal scales arithmetically can be misleading. It supports, but does not substitute for, more rigorous quantitative measurement where that is warranted.
Placing a risk in a lower band means the risk has been eliminated.
A lower residual rating reflects the assessed effect of controls that reduce or manage risk; it does not eliminate risk. Residual positioning also depends on controls actually operating as intended, which typically needs ongoing monitoring and, for models, validation.
A single risk matrix and its scales apply uniformly across all frameworks and sectors.
Axis definitions, scale granularity, and band thresholds are organizational design choices and vary by context (for example, banking model risk versus general enterprise AI). There is no single authoritative matrix definition, so matrices are not directly comparable across organizations without alignment of their scales and conventions.

Best practices

Explicitly document the definitions, scales, and thresholds for both the likelihood and impact axes so that ratings are applied consistently and are interpretable by reviewers.
Distinguish and, where useful, separately plot inherent and residual risk, and record the specific controls assumed when assigning a residual rating.
Treat the matrix as a prioritization and communication aid rather than a precise measurement, and reserve quantitative analysis for higher-severity or high-uncertainty risks where it is warranted.
Link matrix bands to predefined escalation and response actions so that placement drives clear governance decisions rather than remaining a static rating.
Involve appropriate subject-matter experts across relevant lines of defense to reduce single-assessor bias in likelihood and impact judgments.
Review and recalibrate the matrix periodically and after material changes, since risk positions can shift as conditions, controls, or model performance change over time.