A Heat Map Cannot Answer a Budget Question

A heat map tells you a risk is red. It does not tell you whether a control is worth buying. Why ordinal scales fail the management question, and what changes when risk is expressed in money.

RisikomanagementPublished:

The risk report to the board shows twelve red cells, twenty-eight amber, the rest green. Then comes the question the deck reliably breaks on: which of these should we treat first, and what may it cost? A colour has no answer to that, because it lacks the unit in which budgets are allocated.

What the matrix is good for

The risk matrix has its place. It is cheap, quickly explained, works in a workshop and does a decent job of first-pass sorting through an unfamiliar population. For the question of what needs discussing at all, it is a serviceable tool.

It becomes a problem only where it is used beyond what it can support: as the basis for prioritisation, for budget decisions, and for the statement that a risk is acceptable. It was not built for those three.

Four design problems with ordinal scales

Categories are not numbers. Rate likelihood and impact from one to five, multiply them, and you have a value you can compute with and that measures nothing. The distance between levels is undefined; a four is not twice as severe as a two. Two risks in the same cell can differ in real impact by orders of magnitude.

Ratings are not comparable across functions. "High" means one thing in manufacturing, another in IT and another again in procurement. Without common calibration, the group report adds up judgements made on different scales. It is rarely visible, because everybody is using the same colours.

Ordinal values cannot be aggregated. You can count red risks; you cannot add them. The board's question about total exposure, how much is at stake altogether, is fundamentally unanswerable from a heat map.

The colour conceals the spread. A rare event with existential impact and a frequent event with contained damage land in the same cell while demanding entirely different treatment: one needs continuity provision and insurance, the other needs process improvement. The matrix makes them indistinguishable.

The question the traffic light cannot answer

A board does not decide about colours. It decides about the use of money. The relevant question is: should we put 200,000 into this measure, or is that money more effective somewhere else? That question compares two quantities in the same unit. A scale point cannot be compared with a budget; an expected annual loss can.

That is the actual advantage of quantification, and it is less mathematical than communicative. It moves the security discussion into the language in which the company already makes decisions.

A worked example

The figures below are freely chosen and serve only to illustrate the arithmetic. They are not a survey and not industry values.

Suppose two risks both sit at red in the report:

Risk ARisk B
Descriptionfailure of the manufacturing execution systemfailure of the online shop
Expected frequencyroughly every five years (0.2 per year)roughly twice a year
Estimated loss per eventEUR 300,000 to 1,200,000EUR 10,000 to 30,000
Rough annual expected lossaround EUR 150,000around EUR 40,000

Both carry the same colour, yet their annual expected loss differs by almost a factor of four, and their treatment needs differ by more than that, because Risk A can contain a single near-existential excursion and Risk B cannot. A measure costing EUR 60,000 a year that halves the frequency of A is now something you can argue about. The same sum spent on B would not be. Neither statement can be made with two red cells.

What quantification is not

It is not precision. An estimate stays an estimate when it is written in money. The difference is that it becomes checkable. A range with a stated assumption can be contested, corrected and held against reality after an incident. A colour can only be felt differently.

It is not objectivity either. Publishing point values without ranges replaces honest uncertainty with dishonest precision. That is why quantitative methods work with intervals, expected values and simulations rather than a single number, and why every estimate travels with the assumption it rests on.

And it is not a substitute for judgement. Threats to life and limb, legal breaches and certain kinds of reputational damage are not treated because the arithmetic works out, but because they are not negotiable. Other quantities are already denominated in money in any case: the fine framework in Article 83 GDPR is defined in millions of euros and percentages of turnover, not in traffic-light colours.

Finally, not every risk needs quantifying. A two-stage approach works well: rough first-pass sorting across the whole population, and a defensible valuation for the risks that decisions actually hang on.

What changes in how you steer

Three things only become possible once there is a monetary unit.

First, a risk appetite you can say out loud. "We carry up to an expected annual loss of X" is testable. "We accept no red risks" is not.

Second, prioritisation by effect per unit of spend, rather than by order of appearance in the report.

Third, a residual risk that leadership can consciously accept, because it knows what it is deciding about. In Germany this works in support of the early risk detection duty under § 91(2) AktG, the Stock Corporation Act, and the wording there repays attention: the management board has to take suitable measures, in particular to set up a monitoring system, so that developments endangering the continued existence of the company are recognised early. The statutory yardstick is therefore an order of magnitude, not a colour: whether a development endangers the company's continued existence is a question you can put in euros and cannot put in red. What the provision prescribes is a procedure for early recognition, not a particular valuation method; money is simply the unit in which the statute's own yardstick becomes testable at all. For the GmbH, the corresponding duty of care of the managing directors follows from § 43(1) GmbHG, the Limited Liability Companies Act.

The transition does not have to be large. Define once how damage categories translate into money: cost of downtime per hour, recovery effort, contractual penalties, lost contribution margin. Estimate in ranges, record the assumption, and after every real incident compare the estimate against what actually happened. After a handful of iterations the estimates are better calibrated than any colour scale ever was. The monetary risk evaluation page sets out how such a valuation can be set up methodically.

What an amount lets you calculate

The piece argues that ordinal scales fail the management question. That is exactly why, in Rizzqo, impact is an amount in euros and likelihood a percentage, and the two stay apart. The verbal levels come from configurable scale bands, and the risk level from a configurable matrix rather than from a condensed score.

The real gain shows on the task side, because only an amount makes the investment question answerable. A task carries its planned risk reduction with it: how far a particular assessment should fall, in amount or in likelihood. While it is planned, that reduction counts as reserved and shows only in the residual figure; completion lowers the current one, and cancelling releases the reservation. The sentence "this task buys us this much reduction" can then be evidenced rather than asserted.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework