Place a risk on a 3×3, 4×4 or 5×5 heatmap with multiplicative or additive scoring, and see the zone, quadrant and appetite verdict.
Multiplicative scoring spreads risks out and pushes anything with a severe impact towards the top, while additive scoring compresses the range and treats a rare catastrophe much like a frequent nuisance. Both are shown against the same appetite line so you can see how much of the answer comes from the scoring convention rather than from the risk, and the red-cell count exposes whether the matrix itself is generous. Heatmaps drive real funding decisions, and two teams using the same words with different matrices routinely rank the same risk two zones apart. It is a communication and prioritisation tool producing management estimates, not a measurement.
Risk Heatmap
Score = likelihood × impact (multiplicative) or likelihood + impact (additive); the maximum is size² or 2 × size respectively, and the zone is read off the score as a share of that maximum.
Matrix geometry
Red-zone cells are those scoring at least 70% of the maximum; the percentile counts how many of the size² cells score at or below this risk.
Score = likelihood × impact (multiplicative) or likelihood + impact (additive); the maximum is size² or 2 × size respectively, and the zone is read off the score as a share of that maximum. Multiplicative scoring spreads risks out and pushes anything with a severe impact towards the top, while additive scoring compresses the range and treats a rare catastrophe much like a frequent nuisance. Both are shown against the same appetite line so you can see how much of the answer comes from the scoring convention rather than from the risk, and the red-cell count exposes whether the matrix itself is generous.
Heatmaps drive real funding decisions, and two teams using the same words with different matrices routinely rank the same risk two zones apart. It is a communication and prioritisation tool producing management estimates, not a measurement.
This calculator takes 5 inputs: Matrix size, Likelihood, Impact, Scoring method, Appetite line — treat above this score. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Multiplicative is the common default and is better at surfacing severe-impact risks, but it creates gaps — no cell scores 7, 11 or 13 on a 5×5 — and exaggerates differences at the top. Additive is smoother and easier to explain, at the cost of treating a rare catastrophe like a routine annoyance. Pick one, write it in the methodology and never mix them in one register.
Only if your inputs justify the resolution. Five likelihood levels imply you can distinguish rare from unlikely with evidence; if you cannot, the extra granularity is false precision and a 3×3 will produce more honest and more consistent scoring across assessors.