Skip to content
Calcrivo

Risk Matrix Calculator

Score a 5×5 likelihood-versus-impact risk matrix, apply control effectiveness for residual risk and test it against your risk appetite.

Inputs

%

How much of the inherent risk your existing controls remove

Inherent Risk Score

16/ 25

Inherent Risk Level

High

Residual Risk Score

9.60/ 25

Residual Risk Level

Medium

Against Risk Appetite

Outside appetite — residual 9.6 exceeds 8

Recommended Treatment

Treat — add controls or formally accept with an owner and review date

Control Effectiveness Needed

50.0%

Step by step

  1. Values used

    Likelihood = 4 — Likely (several times a year); Impact = 4 — Major; Control effectiveness = 40 %; Risk appetite threshold = Cautious — residual 8 or below

  2. Risk Matrix

    Inherent risk = likelihood × impact on a 5×5 matrix; residual risk = inherent × (1 − control effectiveness); levels are 1–2 Very Low, 3–5 Low, 6–11 Medium, 12–19 High, 20–25 Extreme.

  3. Control gap

    Required control effectiveness = (inherent − appetite) ÷ inherent, the fraction of the risk you must remove to land inside appetite.

  4. Inherent Risk Score

    = 16 / 25

  5. Inherent Risk Level

    = High

  6. Residual Risk Score

    = 9.60 / 25

  7. Residual Risk Level

    = Medium

  8. Against Risk Appetite

    = Outside appetite — residual 9.6 exceeds 8

  9. Recommended Treatment

    = Treat — add controls or formally accept with an owner and review date

How it works

The multiplicative matrix keeps the two axes independent, so a catastrophic-but-rare risk (5 × 1) and a trivial-but-constant one (1 × 5) both score 5 — which is exactly the ambiguity a matrix is meant to expose rather than hide. Residual risk applies control effectiveness as a straight proportional reduction, and the required-effectiveness output inverts the same relationship to tell you how much control you still owe. A matrix score is the language your risk register, your board pack and your auditor all speak, and stating control effectiveness explicitly is what stops residual risk from being wishful thinking.

Formulas

Risk Matrix

Inherent risk = likelihood × impact on a 5×5 matrix; residual risk = inherent × (1 − control effectiveness); levels are 1–2 Very Low, 3–5 Low, 6–11 Medium, 12–19 High, 20–25 Extreme.

likelihood
1 Rare … 5 Almost certain
impact
1 Insignificant … 5 Catastrophic
control effectiveness
Fraction of inherent risk removed by existing controls
appetite
Highest residual score the organisation accepts

Control gap

Required control effectiveness = (inherent − appetite) ÷ inherent, the fraction of the risk you must remove to land inside appetite.

Frequently Asked Questions

How is Risk Matrix calculated?

Inherent risk = likelihood × impact on a 5×5 matrix; residual risk = inherent × (1 − control effectiveness); levels are 1–2 Very Low, 3–5 Low, 6–11 Medium, 12–19 High, 20–25 Extreme. The multiplicative matrix keeps the two axes independent, so a catastrophic-but-rare risk (5 × 1) and a trivial-but-constant one (1 × 5) both score 5 — which is exactly the ambiguity a matrix is meant to expose rather than hide. Residual risk applies control effectiveness as a straight proportional reduction, and the required-effectiveness output inverts the same relationship to tell you how much control you still owe.

Why does Risk Matrix matter?

A matrix score is the language your risk register, your board pack and your auditor all speak, and stating control effectiveness explicitly is what stops residual risk from being wishful thinking.

What values do I need to enter?

This calculator takes 4 inputs: Likelihood, Impact, Control effectiveness, Risk appetite threshold. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Are 5×5 matrices statistically sound?

Not rigorously — ordinal scales multiplied together produce range compression and ties, and a quantitative model is better where you have data. Matrices survive because they are auditable and communicable; use one for triage and reach for expected-loss maths when the decision is expensive.

How do I justify a control effectiveness figure?

From evidence: test results, detection coverage, exercise outcomes. If you cannot point to a test, cap the figure at 50% — untested controls fail more often than teams assume.

You might also need