Which risks actually matter?

Score on your own grid, plot before and after controls, and see immediately which controls are moving the number and which are decoration.

HomeProject Management › Risk Matrix

Probability × impact, on your own scale

Plot inherent and residual risk on the same grid, so the gap between them shows whether the controls are doing anything.

Local tool — your project data stays in your browser
A simpler register without the residual comparison is on the business decisions page. This one is for registers where controls are being tracked.

The register

The matrix

Ranked

Your project stays in this browser. Task names, owners, durations, dates and estimates are calculated on your own device. Nothing is uploaded, stored on a server, or included in analytics — project content is never passed to the advertising or analytics scripts on this page.
How scoring and banding work

score = probability × impact, each on the scale you chose.

Bands are proportions of the maximum, not fixed thresholds. On a 5×5 the maximum is 25; on a 3×3 it is 9. A score of 15/25 and one of 6/9 are both 60% of maximum and both land in the same band.

Fixed thresholds are how a risk rated High by one team becomes Medium at another with no change in the underlying judgement, purely because the grids differed.

Inherent is before controls; residual is after. The register tracks both because the difference is the only evidence that a control is worth its cost.

The score is a sorting device, not a measurement

Probability 3 times impact 4 gives 12, and 12 looks like a fact. It is two judgements multiplied. A risk scoring 12 is not meaningfully worse than one scoring 11, and treating the ordering as precise is how registers end up with forty items ranked to two decimal places and no decisions attached.

What the score is genuinely good for is separating the top few from the rest. Use it for that and stop.

What a matrix systematically misses

Multiplying probability by impact under-weights the rare catastrophe. A one-in-a-hundred event that ends the project scores low and belongs at the top of the agenda anyway.

This is a known limitation of every probability-impact matrix rather than of any particular implementation. The practical defence is to look separately at anything whose impact is at the top of the scale, whatever its probability, and to treat "unlikely but fatal" as its own category.

Residual risk is where the argument is

A register that records only one score cannot tell you whether your controls work. Recording inherent and residual separately makes the claim explicit: we believe this control moves this risk from 15 to 8.

That claim can then be challenged, which is the point. When the residual equals the inherent, either the control does nothing or nobody has updated the numbers since it was put in — and both are worth discovering.

An unowned risk is not managed

The most reliable predictor of a risk being ignored is having no name against it. A risk owned by "the project" or "the team" is owned by nobody, and it will be discussed at every review and acted on at none.