Risk matrix

A risk matrix is a table that rates risks by likelihood and impact and assigns each cell a risk level. BSI Standard 200-3 recommends no more than five categories per axis and leaves the number of levels and their criteria open. Unlike the Nohl matrix from occupational safety, it rates damage to information and processes.

RisikomanagementLast reviewed:

What is a risk matrix?

A risk matrix is the rating grid of a risk analysis: two scales form a grid, and an assignment rule gives each cell a risk level. One axis describes how likely an event is, the other how large the damage would be. Under IT-Grundschutz, chapter 5 of BSI Standard 200-3 from the German Federal Office for Information Security (BSI) sets out this rating.

Each risk level carries a rule for action: accept, monitor, treat or escalate to management. Only that rule turns a rating into a decision. The guide to risk analysis methods compares the techniques that support identification and evaluation alongside the matrix.

How are the axes and scales of a risk matrix built?

Each organization sets its own axes and scales. Chapter 5 of BSI Standard 200-3 gives an example with four categories per axis and expressly leaves the number of levels and their criteria open:

AxisCategories in BSI Standard 200-3How they are described
Likelihood of occurrencerare, medium, frequent, very frequentwith a time reference, from "at most once every five years" to "several times a month"
Impactnegligible, limited, considerable, existence-threateningfrom "minor" up to an "existentially threatening, catastrophic scale"
Risk level (result)low, medium, high, very highfor each level, a statement on whether the existing safeguards are sufficient

For tailoring the matrix, the standard sets three rules:

  • Choose no more than five categories per axis.
  • Agree the descriptions with the business departments, so that two employees rate the same risk the same way.
  • Have management set the thresholds at which likelihood and damage count as "high", for example measured against reserves, revenue or liquidity (Annex 9.1.2).

A level without a time reference or an amount leaves room for interpretation: "rare" means something different in the data center than in purchasing.

Risk matrix 3x3, 4x4 or 5x5 compared

The size of a risk matrix follows from the number of levels per axis: three, four or five.

GridCellsStrengthLimitation
3x39quick to explain, quick to ratewidely differing risks land in the same cell
4x416the grid of the example in BSI Standard 200-3; an even number of levels, so no neutral middle roweach level covers a wider range than in a 5x5 grid
5x525finest distinction within the BSI capeach level needs a sharp definition, or ratings scatter

When choosing, sharp definitions count for more than the number of cells. A 5x5 matrix with scales in percent and euros, acceptance rules and a spreadsheet formula is in the risk matrix template.

The cell assignment sets the risk appetite

Which cell gets which level is not a calculation but a statement of the organization's risk appetite. If the assignment weights impact more heavily than likelihood, an unlikely but severe event ranks higher than a likely one with minor damage.

In Annex 9.1.2, BSI Standard 200-3 shows how the same matrix makes different risks bearable at high and at low risk appetite. High risks, it says, should not be taken on without the permission of top management. That is why executive management approves the assignment and the rules for action per level; ISO/IEC 27001 requires such risk acceptance criteria in clause 6.1.2.

Risk matrix example: same expected loss, different levels

The figures in this example are invented for illustration. Scales and cell assignment are taken from the risk matrix template.

Risk ARisk B
ScenarioERP system outage caused by ransomwareRecurring posting errors caused by an interface fault
Likelihood per year8% (level 2)80% (level 5)
Loss per eventEUR 500,000 (level 4)EUR 50,000 (level 2)
Risk level in the matrixmediumhigh
Expected loss per yearEUR 40,000EUR 40,000

Both risks have the same annual expected loss yet land on different levels. That is what the matrix is for: its assignment weights likelihood and severity the way the organization decided. It becomes a problem only when that weighting is justified nowhere, or when the level alone decides the budget.

To decide which control pays off, you need the amount. That calculation is the subject of the article on quantifying risk in money.

Where does a risk matrix reach its limits?

A risk matrix reaches four limits as soon as budget decisions are meant to follow from the rating:

LimitConsequenceRemedy
Levels are ranks, not measurementsThe product of two levels sorts risks but does not measure themKeep an expected loss from percent and euros next to the level
The resolution is coarseRisks that differ widely in size get the same level, and a smaller risk can get a higher oneRecord loss and likelihood as values
Levels cannot be added upTwelve red cells do not add up to a total exposureSum the expected losses
Uncertainty stays invisibleA dot in a cell hides the range of the estimateDocument the range, for example as error bars

The second limit was shown mathematically in a study published in the journal Risk Analysis in 2008. BSI Standard 200-3 itself uses error bars for the uncertainty of an estimate in Annex 9.1.2. How rated risks are then tracked is covered in the entry on the risk register.

What is the Nohl risk matrix?

The Nohl risk matrix comes from occupational safety and supports the workplace hazard assessment. Under § 5(1) ArbSchG, the German Occupational Safety and Health Act, that assessment determines which protective measures an employer must take. The Institute for Occupational Safety and Health of the German Social Accident Insurance (IFA) describes it with three risk levels that set the need for protective measures.

Nohl risk matrixRisk matrix in an ISMS
OriginOccupational safety, workplace hazard assessmentInformation security, enterprise risk
What is protectedSafety and health of employeesInformation, processes and assets of the organization
Impact axisSeverity of harm to peopleFinancial, legal, operational and reputational damage
Reference framework§ 5 ArbSchGISO/IEC 27001 clause 6.1.2, BSI Standard 200-3

For information security, the grid carries over but the scales do not. The severity of an injury is no yardstick for data loss or business interruption.

How Rizzqo computes the matrix with euro values

Rizzqo computes each risk assessment from likelihood in percent and impact in euros and derives the level through a configurable matrix. Scale bands translate both values into the levels of your risk policy, so the level remains a traceable lookup in a cell. Next to it sits the expected loss in euros, which can be summed across risks.

Each assessment is linked to the affected assets and keeps inherent, current and residual risk separate. Controls run as tasks: while a task is open, its planned reduction is reserved, and only its completion lowers the current risk.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework