Score a 5×5 likelihood-versus-impact risk matrix, apply control effectiveness for residual risk and test it against your risk appetite.
The multiplicative matrix keeps the two axes independent, so a catastrophic-but-rare risk (5 × 1) and a trivial-but-constant one (1 × 5) both score 5 — which is exactly the ambiguity a matrix is meant to expose rather than hide. Residual risk applies control effectiveness as a straight proportional reduction, and the required-effectiveness output inverts the same relationship to tell you how much control you still owe. A matrix score is the language your risk register, your board pack and your auditor all speak, and stating control effectiveness explicitly is what stops residual risk from being wishful thinking.
Risk Matrix
Inherent risk = likelihood × impact on a 5×5 matrix; residual risk = inherent × (1 − control effectiveness); levels are 1–2 Very Low, 3–5 Low, 6–11 Medium, 12–19 High, 20–25 Extreme.
Control gap
Required control effectiveness = (inherent − appetite) ÷ inherent, the fraction of the risk you must remove to land inside appetite.
Inherent risk = likelihood × impact on a 5×5 matrix; residual risk = inherent × (1 − control effectiveness); levels are 1–2 Very Low, 3–5 Low, 6–11 Medium, 12–19 High, 20–25 Extreme. The multiplicative matrix keeps the two axes independent, so a catastrophic-but-rare risk (5 × 1) and a trivial-but-constant one (1 × 5) both score 5 — which is exactly the ambiguity a matrix is meant to expose rather than hide. Residual risk applies control effectiveness as a straight proportional reduction, and the required-effectiveness output inverts the same relationship to tell you how much control you still owe.
A matrix score is the language your risk register, your board pack and your auditor all speak, and stating control effectiveness explicitly is what stops residual risk from being wishful thinking.
This calculator takes 4 inputs: Likelihood, Impact, Control effectiveness, Risk appetite threshold. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Not rigorously — ordinal scales multiplied together produce range compression and ties, and a quantitative model is better where you have data. Matrices survive because they are auditable and communicable; use one for triage and reach for expected-loss maths when the decision is expensive.
From evidence: test results, detection coverage, exercise outcomes. If you cannot point to a test, cap the figure at 50% — untested controls fail more often than teams assume.