What is a risk matrix?
A risk matrix is the rating grid of a risk analysis: two scales form a grid, and an assignment rule gives each cell a risk level. One axis describes how likely an event is, the other how large the damage would be. Under IT-Grundschutz, chapter 5 of BSI Standard 200-3 from the German Federal Office for Information Security (BSI) sets out this rating.
Each risk level carries a rule for action: accept, monitor, treat or escalate to management. Only that rule turns a rating into a decision. The guide to risk analysis methods compares the techniques that support identification and evaluation alongside the matrix.
How are the axes and scales of a risk matrix built?
Each organization sets its own axes and scales. Chapter 5 of BSI Standard 200-3 gives an example with four categories per axis and expressly leaves the number of levels and their criteria open:
| Axis | Categories in BSI Standard 200-3 | How they are described |
|---|---|---|
| Likelihood of occurrence | rare, medium, frequent, very frequent | with a time reference, from "at most once every five years" to "several times a month" |
| Impact | negligible, limited, considerable, existence-threatening | from "minor" up to an "existentially threatening, catastrophic scale" |
| Risk level (result) | low, medium, high, very high | for each level, a statement on whether the existing safeguards are sufficient |
For tailoring the matrix, the standard sets three rules:
- Choose no more than five categories per axis.
- Agree the descriptions with the business departments, so that two employees rate the same risk the same way.
- Have management set the thresholds at which likelihood and damage count as "high", for example measured against reserves, revenue or liquidity (Annex 9.1.2).
A level without a time reference or an amount leaves room for interpretation: "rare" means something different in the data center than in purchasing.
Risk matrix 3x3, 4x4 or 5x5 compared
The size of a risk matrix follows from the number of levels per axis: three, four or five.
| Grid | Cells | Strength | Limitation |
|---|---|---|---|
| 3x3 | 9 | quick to explain, quick to rate | widely differing risks land in the same cell |
| 4x4 | 16 | the grid of the example in BSI Standard 200-3; an even number of levels, so no neutral middle row | each level covers a wider range than in a 5x5 grid |
| 5x5 | 25 | finest distinction within the BSI cap | each level needs a sharp definition, or ratings scatter |
When choosing, sharp definitions count for more than the number of cells. A 5x5 matrix with scales in percent and euros, acceptance rules and a spreadsheet formula is in the risk matrix template.
The cell assignment sets the risk appetite
Which cell gets which level is not a calculation but a statement of the organization's risk appetite. If the assignment weights impact more heavily than likelihood, an unlikely but severe event ranks higher than a likely one with minor damage.
In Annex 9.1.2, BSI Standard 200-3 shows how the same matrix makes different risks bearable at high and at low risk appetite. High risks, it says, should not be taken on without the permission of top management. That is why executive management approves the assignment and the rules for action per level; ISO/IEC 27001 requires such risk acceptance criteria in clause 6.1.2.
Risk matrix example: same expected loss, different levels
The figures in this example are invented for illustration. Scales and cell assignment are taken from the risk matrix template.
| Risk A | Risk B | |
|---|---|---|
| Scenario | ERP system outage caused by ransomware | Recurring posting errors caused by an interface fault |
| Likelihood per year | 8% (level 2) | 80% (level 5) |
| Loss per event | EUR 500,000 (level 4) | EUR 50,000 (level 2) |
| Risk level in the matrix | medium | high |
| Expected loss per year | EUR 40,000 | EUR 40,000 |
Both risks have the same annual expected loss yet land on different levels. That is what the matrix is for: its assignment weights likelihood and severity the way the organization decided. It becomes a problem only when that weighting is justified nowhere, or when the level alone decides the budget.
To decide which control pays off, you need the amount. That calculation is the subject of the article on quantifying risk in money.
Where does a risk matrix reach its limits?
A risk matrix reaches four limits as soon as budget decisions are meant to follow from the rating:
| Limit | Consequence | Remedy |
|---|---|---|
| Levels are ranks, not measurements | The product of two levels sorts risks but does not measure them | Keep an expected loss from percent and euros next to the level |
| The resolution is coarse | Risks that differ widely in size get the same level, and a smaller risk can get a higher one | Record loss and likelihood as values |
| Levels cannot be added up | Twelve red cells do not add up to a total exposure | Sum the expected losses |
| Uncertainty stays invisible | A dot in a cell hides the range of the estimate | Document the range, for example as error bars |
The second limit was shown mathematically in a study published in the journal Risk Analysis in 2008. BSI Standard 200-3 itself uses error bars for the uncertainty of an estimate in Annex 9.1.2. How rated risks are then tracked is covered in the entry on the risk register.
What is the Nohl risk matrix?
The Nohl risk matrix comes from occupational safety and supports the workplace hazard assessment. Under § 5(1) ArbSchG, the German Occupational Safety and Health Act, that assessment determines which protective measures an employer must take. The Institute for Occupational Safety and Health of the German Social Accident Insurance (IFA) describes it with three risk levels that set the need for protective measures.
| Nohl risk matrix | Risk matrix in an ISMS | |
|---|---|---|
| Origin | Occupational safety, workplace hazard assessment | Information security, enterprise risk |
| What is protected | Safety and health of employees | Information, processes and assets of the organization |
| Impact axis | Severity of harm to people | Financial, legal, operational and reputational damage |
| Reference framework | § 5 ArbSchG | ISO/IEC 27001 clause 6.1.2, BSI Standard 200-3 |
For information security, the grid carries over but the scales do not. The severity of an injury is no yardstick for data loss or business interruption.
How Rizzqo computes the matrix with euro values
Rizzqo computes each risk assessment from likelihood in percent and impact in euros and derives the level through a configurable matrix. Scale bands translate both values into the levels of your risk policy, so the level remains a traceable lookup in a cell. Next to it sits the expected loss in euros, which can be summed across risks.
Each assessment is linked to the affected assets and keeps inherent, current and residual risk separate. Controls run as tasks: while a task is open, its planned reduction is reserved, and only its completion lowers the current risk.