Explainer · method
How a risk assessment is built – and where a matrix helps.
A matrix makes risks comparable. It does not make them measurable. That difference decides whether the result holds or merely looks colourful.
A risk assessment follows the same sequence everywhere: establish the context, collect risks, analyse, evaluate, treat, monitor. ISO 31000 describes this cycle as guidance without prescribing a method.
The matrix enters at the analysis step. It assigns two values to each risk – how likely it is and how severely it would act – and turns them into a position in a grid. Its value lies in comparability: twenty risks can be prioritised in one meeting without everyone holding all twenty in mind.
Its danger is false precision. Two estimates become a product that looks like a measurement. Without described levels you produce a number without meaning – and then make decisions on that basis.
The sequence in five steps
- Establish contextWhat is to be protected, and from what point is a risk no longer bearable?The acceptance threshold is set before the assessment, not after. Otherwise it gets adjusted to the result.
- Collect risksWhat could endanger your objectives?From several sources: past incidents, processes, suppliers, dependencies, regulation. Not only from the memory of the management meeting.
- AnalyseHow likely, how severe?Both axes need described levels. A “3” must mean the same to everyone, otherwise assessments are not comparable.
- EvaluateAbove or below the threshold?Only here is it decided whether treatment is required. The position in the grid is the basis, not the outcome.
- Treat and monitorAvoid, reduce, transfer or consciously carry.Every measure gets an owner and a date. The residual risk is assessed again.
How the matrix is built
Both axes need described levels. Without a description, a five is not an assessment but a feeling.
| Level | Likelihood | Impact, example business interruption |
|---|---|---|
| 1 — very low | Not known in the sector, theoretically conceivable | Barely noticeable, absorbed in daily work |
| 2 — low | Less often than every five years | Under one day, no customer effect |
| 3 — medium | Roughly every one to five years | Up to a week, delivery delays towards customers |
| 4 — high | Possible several times a year | Up to four weeks, penalties or loss of customers |
| 5 — very high | Regularly, or already occurred | Over four weeks, the business line itself at stake |
Impact needs more than one dimension. Alongside interruption, at least people, legal exposure and reputation belong in – and the highest one counts, not the average.
A worked example
A single source for a casting, with no qualified alternative.
| Step | Assessment | Reasoning |
|---|---|---|
| Likelihood | 3 — medium | Two supply shortages in the sector over five years, one plant with a known capacity peak. |
| Impact | 5 — very high | Without the part, final assembly stops. Bringing up a new source including first article inspection: about three months. |
| Gross risk | 15 — above the threshold | The acceptance threshold sits at 8. Treatment is therefore not optional. |
| Measure | Qualify a second source | Owner: purchasing, deadline: six months, interim step first article inspection after four. |
| Residual risk | 6 — below the threshold | Likelihood unchanged at 3, impact falls to 2 because an approved alternative exists. |
Six pitfalls
- Undescribed scales
- A 5×5 matrix without described levels produces numbers that are not comparable between two people.
- Everything is medium
- When nobody wants to rate high, everything gathers in the middle. One remedy is requiring a top risk to be named per category.
- Averaging across dimensions
- A risk with low financial damage and danger to life is not “medium”. The highest affected dimension governs.
- Assessing without a threshold
- Without a pre-set acceptance threshold, what is bearable gets decided afterwards – and that is visible in an audit.
- Residual risk not assessed
- Reassessment after treatment is rare. That leaves open whether the measure sufficed.
- Nobody decides
- Who may consciously carry a risk must be defined. Otherwise nobody carries it in fact and everybody formally.
The matrix is a tool for shared understanding, not a calculator. Its value arises in the conversation about the rating – not in the number that ends up on the page.
Supplier risk from data rather than estimates
Criticality, incident history, single sources and deadlines exist as data in SCRM. Assessment then rests on observation rather than memory – and can be compared year on year.
Request a consultation What risk-based thinking means Go to risk management