How likely is it, and how much would it hurt? A risk assessment matrix asks those two questions of every risk on your list, from the ageing cooling unit to the supplier everything depends on, and turns the answers into a score out of 25.
Each rating runs from one to five. The sections below go through what every level means and then score a worked example from a logistics operation, so you can see one done from start to finish before you try your own.
Get your free 5x5 risk matrix template below. The scales are already written in, the multiplication is handled for you, and a few example risks are scored in already so you can see how yours should look. Use it as a spreadsheet starter, then move the same scoring fields into a custom register when owners, evidence, reviews, and reports need to stay connected.
Guardzy turns matrix scores into configurable fields inside custom registers, linked to owners, controls, evidence, assets, review dates, and reports. Start free with Guardzy.
What is a risk assessment matrix?
A risk assessment matrix is a grid that ranks risks by combining two ratings: likelihood, meaning how probable the risk is, and impact, meaning how much damage it would cause. Each risk lands in a cell where its likelihood and impact meet, and that cell tells you how serious the risk is relative to everything else on your list.
Most teams use a 5x5 version, which rates both likelihood and impact from 1 to 5 and produces 25 possible cells. The grid is colour-coded, so a glance shows you which risks need attention now and which can wait. It is the format referenced across ISO 31000 and SafeWork Australia guidance, and it works the same for operational, financial, supplier, and compliance risk.
The 5x5 risk matrix levels
Both axes run across five levels. These are the standard definitions to start from, worded for a working business rather than an audit manual.
Likelihood and impact scales
| Score | Likelihood | Impact |
|---|---|---|
| 1 | Rare: would only happen in exceptional circumstances | Insignificant: barely noticed, absorbed in a day |
| 2 | Unlikely: could happen, but you would not expect it | Minor: a manageable disruption or small cost |
| 3 | Possible: might happen at some point | Moderate: a real hit to operations, budget, or reputation |
| 4 | Likely: will probably happen at some point | Major: serious disruption, significant cost, hard to recover from quickly |
| 5 | Almost certain: expected to happen regularly | Severe: threatens the business, a site, or people's safety |
The wording matters less than the agreement. Write down what each level means for your business before you score anything, because a "moderate" impact has to mean the same thing to your operations manager as it does to your finance lead.
How to calculate risk on a matrix
The scoring is deliberately simple:
Those scores usually group into four bands:
- 1 to 4, Low: acceptable, monitor it.
- 5 to 9, Moderate: plan to reduce it.
- 10 to 15, High: needs action soon.
- 16 to 25, Critical: act now.
The colour bands do the communicating. Plot every risk on the grid and the serious ones cluster in the top-right corner, which gives you a priority list the whole team can read without any training. A board member who never opens a spreadsheet understands a heat map in seconds.
A worked example
Take a logistics operator with a single refrigerated warehouse. The cooling system is a decade old and a failure spoils stock within hours.
Cooling system risk score
| Assessment step | Decision | Why |
|---|---|---|
| Likelihood | Likely (4) | The unit is ageing and has had two callouts this year. |
| Impact | Severe (5) | A full failure spoils an entire warehouse of stock and breaches customer contracts. |
| Score | 4 x 5 = 20 | Critical: the risk needs action now. |
That score of 20 puts the cooling system above the cosmetic warehouse repairs everyone keeps mentioning, and it justifies the maintenance budget to whoever signs it off.
Inherent risk vs residual risk
Before you score anything, decide which version of each risk you are measuring, because the choice changes what the numbers mean.
Score a risk as it stands today, with your current controls in place, and you are measuring residual risk. Score it as if those controls vanished, and you are measuring inherent risk. Both are useful. Inherent risk shows how much your controls are doing, and residual risk shows what you are still carrying.
For most SME purposes, score residual risk, the real level you live with now, and note the controls holding it there. If a control lapses, the score climbs, which is exactly the warning you want.
Get the free 5x5 risk matrix template
Prefilled with example risks. Works in Excel and Google Sheets, and gives you the field model for a custom risk register.
The download gives you a ready-made 5x5 matrix with:
- Likelihood and impact scales defined in plain language, so scoring stays consistent.
- Automatic colour-coding, so each risk lands in the right band as you enter it.
- A scoring column that multiplies likelihood by impact for you.
- Worked examples from property, manufacturing, logistics, and energy operations.
Common mistakes with risk matrices
The template handles the maths, so what is left to get right is the judgement. The slips that catch most teams:
- Scales that are not defined, so "likely" means different things to different people and the scores stop being comparable.
- Everything rated moderate, because nobody wants to call a risk severe or dismiss it as rare.
- Scoring once and never again, when the whole value is in re-scoring as things change.
- Treating the matrix as the finish line, when it is really the sorting step before the real work of assigning owners and controls.
That last one is the most common. Sorting your risks is the start of the job, and the work of treating them still needs owners and plans behind it.
From matrix to custom register
A scored matrix answers "which risks matter most." The next question is "who is doing something about each one, and how do I know it is handled?"
Guardzy builds a custom risk register around your matrix scores: risks ranked by severity, linked to the assets they threaten and the controls treating them, with reminders that chase the owner instead of you, and reports pulled from live register data.
Turn risk scores into a live register
Create a custom risk register with matrix scoring, owners, controls, evidence, review dates, and reports connected from the start.
- Track likelihood, impact, inherent risk, residual risk, and treatment status.
- Link each scored risk to assets, controls, evidence, tasks, owners, and reviews.
- Export clean reports for leadership, audits, customers, and internal reviews.
About the author
Hamish Lister writes practical register, security, compliance, and workflow guides for SMEs that need audit-ready structure without an enterprise rollout.
Frequently asked questions
What is a 5x5 risk matrix?
A 5x5 risk matrix is a grid that scores risks by rating likelihood and impact from 1 to 5 each, creating 25 possible combinations. Multiplying the two ratings gives a risk score from 1 to 25, which maps to a colour band from low to critical, so teams can see at a glance which risks need attention first.
How do you calculate risk on a matrix?
You calculate risk by multiplying the likelihood rating by the impact rating. A risk rated 4 for likelihood and 5 for impact scores 20, placing it in the critical band. The multiplication keeps scoring consistent, so two people assessing the same risk with the same scales reach the same number.
What do the colours on a risk matrix mean?
The colours show risk severity at a glance: green is low and acceptable, yellow is moderate and worth planning for, orange is high and needs action soon, and red is critical and needs action now. Colour-coding turns a table of numbers into a picture your whole team can read without training.
What is the difference between a risk matrix and a risk register?
A risk matrix is the scoring tool that ranks your risks by severity, while a risk register is the custom register that manages them over time. The matrix tells you which risks matter most; the register holds the owner, controls, evidence, and review dates that keep each one under control.
Is a 5x5 matrix better than a 3x3?
A 5x5 matrix gives finer prioritisation than a 3x3, which helps once you are managing more than a handful of risks and need to tell a high risk from a critical one. A 3x3 is quicker for very small teams or one-off assessments. Most growing SMEs settle on 5x5 because it separates the genuinely urgent risks from the merely important ones.