A meeting to score risks

I was in a meeting once. Two experienced risk practitioners. Same risk register. Same row. One scored it a 16. The other scored it a 9. A lively debate followed. It was collegial, well-intentioned, and entirely unnecessary because both of them were right. Not because the risk had changed. Because the risk register they were using had no shared definition of what the numbers actually meant.

That is the problem I see in almost every organisation I walk into. “A score of 16 is not twice as bad as a score of 8. It is simply higher on a priority list. But treat it like mathematics, and you will make overconfident decisions.” This is not about competency. It is about calibration. And it is the reason most Risk Assessment Matrices (RAMs) that sit at the centre of how organisations prioritises risk can be uniquely and quietly misleading them.

By now if you have been following our YouTube channel you know what a risk register is and what the tripod (Event, Cause, Consequence) formula for risk descriptions looks like in practice. Today we go one layer deeper: how do you actually rate your risks once you have described them? By the end of this post, you will understand what a Risk Assessment Matrix is doing when it multiplies likelihood by impact and why most of them need calibration.

*This content is for informational and educational purposes only. This is not financial, legal, or professional advice. Please always consult an appropriately qualified professional before making any decisions that affect your organisation.*

What is a Risk Assessment Matrix (RAM)

Let us start with the anatomy. A Risk Assessment Matrix has two axes. Likelihood: how likely is this to happen? and Impact: how bad is it if it does? Multiply them together and you get a score. Plot that on a colour coded grid and you get a priority.

That is the whole thing. That is all there is to it.

But here is what most people miss. The multiplication is not mathematics. You are not measuring a physical quantity. You are ranking risks relative to each other. A score of 12 is not twice as bad as 6 it is simply higher on a priority list. The matrix is a comparison tool, not a formula.

And colour bands are just ranges to easily spot at glance their priority. Everything that lands between 12 and 15 might be red. That means a score of 12 and a score of 15 get the same treatment even if they are meaningfully different in reality. That is the first place things go wrong. But we will come back to that.

Weighting your scores with the help of a RAM

This is the part I get asked quite frequently in my work. Most Risk Assessment Matrices give you one impact score. You rate the risk once, you get one number. And that number goes into the register. The problem: impact is not one thing. It is several things at once. Here is what I mean.

I worked with an organisation that had a critical software vendor. This vendor provided the core platform the whole team ran on. The risk: the vendor becomes unavailable for an extended period. Now. What is the impact of that?, Medium? High? You cannot capture the full impact in just one cell score.

So here is what I do in practice and this is how you weight the impacts. Instead of one impact score, in this example I use four: Financial. Operational. Reputational. Regulatory.

Each one rated separately, on its own scale. Same risk:
• Financial impact: 5 (catastrophic).
• Operational impact: 2 (minor disruption).
• Reputational impact: 3 (moderate).
• Regulatory impact: 4 (major).

Now I have a more complete picture. And I can average those four scores which gives me a composite of 3.5 which is about medium-high. But the individual dimensions tell me something a single number never could: this risk is primarily a regulatory and financial problem. Operationally, it is manageable. That shapes where I put my mitigation effort.

“High” alone tells you almost nothing. High because the financial impact is devastating but operationally it is completely manageable that is a useful sentence. That is a conversation you can do something about.

If you rate the impact of a risk using one single perspective that is a start. If you have four perspectives, you are doing it well. If you have ten, you are running a sophisticated operation and you probably have the governance to support it. More perspectives give you richer information. But they also require more work to keep it consistent. This is a spectrum. Pick your level and own it. That is what a properly dimensioned RAM gives you.

How to calibrate a RAM

So. We have a matrix. We have dimensions. We have scores. Now, who decides what “Likely” means? This is where calibration comes in. And this is the thing that fixes the opening problem two people, two different scores, same risk register. Without calibration, “Likely” is whatever the assessor thinks it is. Which means two competent, well-intentioned people will give you two different ratings. And then your risk register is inconsistent which in turn means decisions made from it are unreliable.

The fix: define the criteria. Build the scale with words attached. Have a look to our free Risk Register Template, specifically tab “3.RAM” where you can refer to a sample likelihood and magnitude/consequence scale to get started. Adjust them to your organisation and once you have done that (at least once) you use the same scale for years. You are not calibrating before every assessment. You are building a shared language that the whole organisation can speak.

And this matters, that shared language is not valid until your board formally adopts it. Without that authority, someone will always reinterpret the numbers when the answer is uncomfortable. The calibration conversation needs to be institutionalised, not just documented. Two people using the same calibrated scale should land to a very similar risk scoring result. That is the goal.

Manual vs Automated

There is software that does all of this. Enterprise GRC platforms. Integrated risk management tools. Automated risk registers that generate scores for you. Here is my honest view on that. Manual or automated the logic is the same. If you do not know what the software is doing when it generates a score, if you do not understand likelihood calibration and impact dimensions, then you do not understand your own system. You are clicking buttons and trusting output you cannot explain. And that is a problem.

“Software nobody understands is a more expensive spreadsheet. It is a black box. And when leadership asks you to justify a score, ‘the system generated it’ is not an answer.”

But someone who understands the fundamentals can challenge the output. They can maintain the system when the business changes. They can make the case to leadership for why a score should be recalibrated. They are useful in a way that someone who just knows how to click the software is not. Whether you use a spreadsheet or an enterprise platform, knowing what the numbers mean is what gives you the edge.

Closing thoughts

Here is what I want you to take away. The Risk Assessment Matrix multiplies likelihood by impact. That is the mechanics. But the moment it becomes useful is when you attach criteria to both sides of that equation, when you define what your scale actually means and when you separate impact into the dimensions that matter to your organisation.

Calibrate once. Use it for years. Score consistently. Then your risk register stops lying to you. The next time someone asks you to explain a risk score you will be able to. Not because the software told you so. Because you understand what the numbers mean. That is what makes you genuinely useful in any organisation.