Which risks actually matter?
Score on your own grid, plot before and after controls, and see immediately which controls are moving the number and which are decoration.
Probability × impact, on your own scale
Plot inherent and residual risk on the same grid, so the gap between them shows whether the controls are doing anything.
The register
The matrix
Ranked
How scoring and banding work
score = probability × impact, each on the scale you chose.
Bands are proportions of the maximum, not fixed thresholds. On a 5×5 the maximum is 25; on a 3×3 it is 9. A score of 15/25 and one of 6/9 are both 60% of maximum and both land in the same band.
Fixed thresholds are how a risk rated High by one team becomes Medium at another with no change in the underlying judgement, purely because the grids differed.
Inherent is before controls; residual is after. The register tracks both because the difference is the only evidence that a control is worth its cost.
The score is a sorting device, not a measurement
Probability 3 times impact 4 gives 12, and 12 looks like a fact. It is two judgements multiplied. A risk scoring 12 is not meaningfully worse than one scoring 11, and treating the ordering as precise is how registers end up with forty items ranked to two decimal places and no decisions attached.
What the score is genuinely good for is separating the top few from the rest. Use it for that and stop.
What a matrix systematically misses
Multiplying probability by impact under-weights the rare catastrophe. A one-in-a-hundred event that ends the project scores low and belongs at the top of the agenda anyway.
This is a known limitation of every probability-impact matrix rather than of any particular implementation. The practical defence is to look separately at anything whose impact is at the top of the scale, whatever its probability, and to treat "unlikely but fatal" as its own category.
Residual risk is where the argument is
A register that records only one score cannot tell you whether your controls work. Recording inherent and residual separately makes the claim explicit: we believe this control moves this risk from 15 to 8.
That claim can then be challenged, which is the point. When the residual equals the inherent, either the control does nothing or nobody has updated the numbers since it was put in — and both are worth discovering.
An unowned risk is not managed
The most reliable predictor of a risk being ignored is having no name against it. A risk owned by "the project" or "the team" is owned by nobody, and it will be discussed at every review and acted on at none.