Risk Heatmap Calculator
Place a risk on a 3×3, 4×4 or 5×5 heatmap with multiplicative or additive scoring, and see the zone, quadrant and appetite verdict.
Inputs
Risk Score
20points
Share of the Maximum Score
80.0%
Maximum Possible Score
25points
Cells in the Red Zone
3cells
Cells at or Below This Score
96%
Matrix Cell
L4 × I5 on a 5×5 matrix
Heatmap Zone
Red — extreme, escalate now
Quadrant Strategy
High likelihood, high impact — mitigate, and expect this to be the most expensive quadrant
Appetite Verdict
Above the appetite line — treatment required or formal acceptance with sign-off
Step by step
Values used
Matrix size = 5×5 — twenty-five cells; Likelihood = 4 — Likely; Impact = 5 — Severe; Scoring method = Multiplicative — likelihood × impact; Appetite line — treat above this score = 12 points
Risk Heatmap
Score = likelihood × impact (multiplicative) or likelihood + impact (additive); the maximum is size² or 2 × size respectively, and the zone is read off the score as a share of that maximum.
Matrix geometry
Red-zone cells are those scoring at least 70% of the maximum; the percentile counts how many of the size² cells score at or below this risk.
Risk Score
= 20 points
Share of the Maximum Score
= 80.0
Maximum Possible Score
= 25 points
Cells in the Red Zone
= 3 cells
Cells at or Below This Score
= 96
Matrix Cell
= L4 × I5 on a 5×5 matrix
How it works
Multiplicative scoring spreads risks out and pushes anything with a severe impact towards the top, while additive scoring compresses the range and treats a rare catastrophe much like a frequent nuisance. Both are shown against the same appetite line so you can see how much of the answer comes from the scoring convention rather than from the risk, and the red-cell count exposes whether the matrix itself is generous. Heatmaps drive real funding decisions, and two teams using the same words with different matrices routinely rank the same risk two zones apart. It is a communication and prioritisation tool producing management estimates, not a measurement.
Formulas
Risk Heatmap
Score = likelihood × impact (multiplicative) or likelihood + impact (additive); the maximum is size² or 2 × size respectively, and the zone is read off the score as a share of that maximum.
- size
- Matrix dimension, 3, 4 or 5
- score
- Position of the risk in the matrix
- maxScore
- Top-right cell of the matrix
Matrix geometry
Red-zone cells are those scoring at least 70% of the maximum; the percentile counts how many of the size² cells score at or below this risk.
- redCells
- How many of the cells are extreme, which shows how coarse or generous your matrix is
- percentile
- Where this risk sits among all possible cells
Frequently Asked Questions
How is Risk Heatmap calculated?
Score = likelihood × impact (multiplicative) or likelihood + impact (additive); the maximum is size² or 2 × size respectively, and the zone is read off the score as a share of that maximum. Multiplicative scoring spreads risks out and pushes anything with a severe impact towards the top, while additive scoring compresses the range and treats a rare catastrophe much like a frequent nuisance. Both are shown against the same appetite line so you can see how much of the answer comes from the scoring convention rather than from the risk, and the red-cell count exposes whether the matrix itself is generous.
Why does Risk Heatmap matter?
Heatmaps drive real funding decisions, and two teams using the same words with different matrices routinely rank the same risk two zones apart. It is a communication and prioritisation tool producing management estimates, not a measurement.
What values do I need to enter?
This calculator takes 5 inputs: Matrix size, Likelihood, Impact, Scoring method, Appetite line — treat above this score. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Multiplicative or additive scoring?
Multiplicative is the common default and is better at surfacing severe-impact risks, but it creates gaps — no cell scores 7, 11 or 13 on a 5×5 — and exaggerates differences at the top. Additive is smoother and easier to explain, at the cost of treating a rare catastrophe like a routine annoyance. Pick one, write it in the methodology and never mix them in one register.
Is a 5×5 matrix better than a 3×3?
Only if your inputs justify the resolution. Five likelihood levels imply you can distinguish rare from unlikely with evidence; if you cannot, the extra granularity is false precision and a 3×3 will produce more honest and more consistent scoring across assessors.
You might also need
- Inherent Risk CalculatorCommonly used together
- Risk Register CalculatorCommonly used together
- Risk Priority Number CalculatorCommonly used together
- Residual Risk CalculatorAlso in Compliance & GRC
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC