Risk matrix template for an ISMS: scales, 5x5 matrix and thresholds

This risk matrix template contains likelihood and impact scales in euros, a 5x5 matrix, acceptance thresholds and a worked example to rebuild in Excel. Written for information security and risk management, freely readable, no registration required.

TemplateRisikomanagementLast reviewed:

This risk matrix template contains the five building blocks of a defensible risk assessment in an ISMS as tables you can rebuild in Excel; this page offers no file download. The building blocks are a likelihood scale with a time reference, an impact scale in euros, a 5x5 matrix with risk levels assigned to each cell, acceptance thresholds with decision authority, and the link to a risk register. A worked example and a checklist before approval complete the template.

Key takeaways

  • Every likelihood level needs a time reference, in this template for example “below 5% per year” for level 1.
  • You must adapt the euro thresholds of the impact scale to your organization's revenue, earnings or liquidity.
  • The 5x5 matrix has 25 cells; derive the risk level in Excel with an INDEX lookup instead of multiplying levels.
  • BSI Standard 200-3 recommends no more than five categories per dimension.
  • ISO/IEC 27001 clause 6.1.2 requires defined risk acceptance criteria; step 4 of the template documents them.

The template is written for information security officers, risk managers and executives who are setting up a first methodology or want to make an existing traffic-light matrix more defensible. What a risk matrix is and where it reaches its limits is covered in the glossary entry on the risk matrix; how the matrix fits into identification, analysis and evaluation is covered in the entry on risk analysis. Which other techniques come into question alongside the matrix is compared in the guide to risk analysis methods.

Step 1: how do you define the likelihood scale?

Every level needs a time reference, otherwise “rare” means something different in every department. The template shows frequency and annual likelihood side by side, so both ways of thinking lead to the same level.

LevelLabelFrequencyLikelihood per year
1very rareless than once every 20 yearsbelow 5%
2rareroughly every 5 to 20 years5% to below 20%
3possibleroughly every 2 to 5 years20% to below 50%
4likelyroughly every 1 to 2 years50% to below 80%
5very likelyonce a year or more often80% or more

Step 2: define the impact scale in euros and other dimensions

The euro thresholds are the part of the template you must adapt. BSI Standard 200-3 notes that organizations typically anchor these thresholds in their financial figures, for example a percentage of revenue or the question of whether the organization would remain solvent after the event. The amounts below assume a company with 40 million euros in annual revenue; they are chosen freely and serve purely as illustration.

LevelLabelFinancial (example)Legal and complianceOperationsReputation
1negligiblebelow 20,000 eurosno breachdisruption under one hournot noticeable
2limited20,000 to below 100,000 eurosminor breach, no reporting dutyoutage up to one working dayisolated customer complaints
3significant100,000 to below 500,000 eurosreportable incidentoutage of several daysregional press coverage
4severe500,000 to below 2 million eurosregulatory proceedings, fine possiblecritical processes down for over a weeknational press coverage, customer loss
5critical2 million euros or moreprohibition, personal liability of managementbusiness continuity at stakelasting loss of trust

Several impact dimensions: the highest level counts

The rule for multiple dimensions: the highest applicable level counts. An event with little financial damage but a reportable personal data breach is rated level 3, not level 1.

Step 3: how do you assign the cells of the 5x5 matrix?

The cell assignment is a statement about your risk appetite. This template weights impact more heavily than likelihood; change the cells if your executive management weighs things differently.

Impact / likelihood1 very rare2 rare3 possible4 likely5 very likely
5 criticalmediumhighhighvery highvery high
4 severemediummediumhighhighvery high
3 significantlowmediummediumhighhigh
2 limitedlowlowmediummediumhigh
1 negligiblelowlowlowlowmedium

How do you build the matrix in Excel?

Lay out the matrix with rows running from impact 5 (top) to 1 (bottom) and columns from likelihood 1 to 5, for example in the range B2:F6. With the likelihood level in column G and the impact level in column H, =INDEX($B$2:$F$6,6-H2,G2) returns the risk level as a lookup. To derive a level from a percentage, use =MATCH(E2,$K$2:$K$6,1) with the lower bounds 0, 5%, 20%, 50% and 80% in K2:K6. Avoid the obvious formula of likelihood times impact on level numbers: it produces scores from 1 to 25 whose intervals mean nothing, and it hides the weighting that the cell assignment makes visible.

Step 4: who may accept which risk level?

A matrix without a rule for action produces a list, not a decision. The review intervals in this table are suggestions, not normative requirements.

Risk levelMeaningTreatmentWho may acceptReview
lowExisting controls protect adequatelyno additional control neededrisk ownerannually
mediumControls may not be sufficientassess treatment and decide with a rationalehead of department with a rationaleevery six months
highProtection is not adequatetreatment plan with a deadline is mandatoryexecutive management, time-limitedquarterly
very highProtection is not adequate, acceptance is the exceptionimmediate measures, escalation to executive managementexecutive management, in writing and time-limitedmonthly until reduced

The meanings of the levels follow the risk categories of BSI Standard 200-3. ISO/IEC 27001 clause 6.1.2 requires defined risk acceptance criteria; this table is one way to document them.

Step 5: connect the matrix to the risk register

The matrix assesses, the register records the results. Each row of the register is one risk with asset, scenario, likelihood, impact, the risk level from this matrix, expected loss, treatment, risk owner and review date. The full 17 columns with dropdown lists and formulas are in the risk register template; it takes its scales and matrix from this template so that both speak the same language.

Worked example: ransomware on the ERP system

The figures in this example are chosen freely and serve purely as illustration. They use the scales from steps 1 and 2.

StateLikelihood per yearImpact per eventCell (L / I)Risk levelExpected loss per year
Inherent, no controls30% (level 3)1,200,000 euros (level 4)3 / 4high360,000 euros
Current, with offline backups and endpoint protection15% (level 2)600,000 euros (level 4)2 / 4medium90,000 euros
Residual, after segmentation and a tested recovery8% (level 2)250,000 euros (level 3)2 / 3medium20,000 euros

What the ransomware example shows

The example shows the strength and the limit of the matrix at once. Between current and residual risk the level stays at medium, yet the expected loss falls from 90,000 to 20,000 euros. If the planned controls cost 30,000 euros a year, they are set against an expected reduction of 70,000 euros. The matrix cannot make that trade-off; it needs the amount, as the article A heat map cannot answer a budget question argues. Under step 4, accepting the residual risk sits with the head of department, with a rationale and a review in six months.

What should you check before approving the risk matrix?

Before executive management approves the matrix, all eight points on this checklist should be met:

  • Every likelihood level has a time reference.
  • The euro thresholds are derived from revenue, earnings or liquidity and confirmed by executive management.
  • Non-financial dimensions are defined, and the highest applicable level counts.
  • The cell assignment is justified and approved.
  • Every risk level has a treatment rule, an acceptance authority and a review interval.
  • Two departments have rated the same test risks independently and reached the same result.
  • The register keeps inherent, current and residual risk apart.
  • Every assumption behind an estimate is recorded in one sentence.

From template to living assessment: Rizzqo

A spreadsheet template works as long as the register is small and one person maintains it. It gets harder once assets change, controls are completed and several departments assess at the same time. In Rizzqo, the building blocks of this template are configuration: scale bands translate percentages and euros into your levels, the risk level is a lookup in a configurable matrix, and the expected loss is computed from likelihood and impact. Each risk assessment is linked to the affected assets from the inventory and keeps inherent, current and residual risk apart. Controls are tracked as tasks with a planned reduction in likelihood or impact: while planned, the reduction is reserved; once completed, it lowers the current risk, and tasks sync with Jira in both directions. The euro bands and the cell assignment are a decision for your executive management.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework