How to build a risk matrix step by step
A risk matrix is one of the most useful tools for making decisions with a clear head. In this article we explain what it is and how to put one together, step by step.
What is a risk matrix?
It's a table (or a grid of colors) that shows how serious each risk is, by combining two questions:
- How likely is it to happen?
- If it happens, how strong would the impact be?
By crossing those two answers, each risk lands in a cell with a color: green (low), yellow (medium) or red (high). That way, at a glance, you know where to focus first.
Step 1: Gather the information
Before you start, keep at hand whatever you already have documented: policies, manuals, procedures, previous reports. It doesn't need to be perfect; begin with whatever you have.
Step 2: Identify the risks
For each important process, ask yourself: what could go wrong? Think in terms of cause → event → consequence. For example:
Cause: the payment system does not validate identity properly. Event: a third party makes a fraudulent transaction. Consequence: loss of money and damage to reputation.
Writing risks out this way, in full, prevents confusion later on.
Step 3: Rate likelihood and impact
Use a simple scale, usually from 1 to 5:
- Likelihood: 1 = very rare, 5 = almost certain.
- Impact: 1 = minor nuisance, 5 = serious harm.
Be honest and consistent. What matters is not the exact figure, but being able to compare some risks against others.
Step 4: Place them on the matrix
Multiply or cross both values and place each risk in its cell. The ones that land in red are your priority; the yellow ones, to watch; the green ones, under control.
| Low impact | Medium impact | High impact | |
|---|---|---|---|
| High likelihood | 🟡 | 🔴 | 🔴 |
| Medium likelihood | 🟢 | 🟡 | 🔴 |
| Low likelihood | 🟢 | 🟢 | 🟡 |
Step 5: Decide what to do with each one
For the important risks, choose an action:
- Prevent or reduce: put a control in place (for example, a double check).
- Transfer: insurance, a specialized third party.
- Accept: if the cost of avoiding it is greater than the risk itself.
Step 6: Review it often
A risk matrix is not a document you make once and file away. The business changes, new risks appear and others go away. Review it from time to time (quarterly or every six months is a good habit).
The most common mistake
Building the matrix from memory and from a single perspective. Whatever one person doesn't remember simply doesn't get in. That's why it helps to involve several viewpoints (operations, compliance, strategy) or to rely on a tool that reviews the documents for you.
In short: identify, rate, place, decide and review. With those five steps you already have a professional risk matrix.
If you want to skip the manual work, Fractal Risk builds your complete risk matrix in minutes and leaves it ready to present.
Ready to identify your company's risks in minutes?
Book a free demo