A risk matrix is a simple yet powerful risk analysis tool in project planning and management. It assesses, ranks, and prioritizes the potential risks of events that may negatively affect a project’s success. By increasing risk visibility, a risk matrix can help you develop risk management strategies and contingency plans, as well as allocate resources for mitigation efforts in a more effective way.
With those goals in mind, our team developed a template to address project risks based on (a) how likely they are to occur (Likelihood), and (b) how severe their impact will be (Consequence). The result was a 5 x 5 color-coded grid system where the individual values of Likelihood and Consequence are combined to determine the overall risk level.
Now let’s explore our matrix in more detail:
How Our Template Works
Step 1: Risk identification
We start by listing down all the potential risks to your project or business. If you used our Risk Register template, you should already have this list handy.
From natural disasters to data breaches and budget overruns, risks vary depending on the industry or business area you are operating in. So make sure you make a thorough assessment with input from all project team members and stakeholders, especially those with experience working on similar projects.
In general, it may be a good idea to categorize risks into internal project risks, such as operational, technological, performance, cost, or time-related risks, or external project risks, such as changes in economic or political conditions or new laws or regulations that may affect your project.
Step 2: Risk allocation
In this step, you assign each risk a value from 1 to 5 for both, Likelihood and Consequence.
Each value for Likelihood will indicate a different level of probability: starting from Almost Certain (1), Likely (2), Moderate (3), Unlikely (4) to Rare (5).
We repeat the same exercise for our other risk-determining variable, Consequence. Each value for Consequence will point to a different level of severity of impact ranging from Insignificant (1), Minor (2), Significant (3), Major (4) to Severe (5). In other words, the higher the impact of a risk, the higher its Consequence Value.
Step 3: Risk prioritization
Now that you have assigned a value to each risk variable, it’s time to use our grid. At the bottom-left of our grid, we have two drop-down menus where you can input these two values for each risk. Once you do this, we automatically place the risk in one of the cells inside the grid, assigning it an overall risk level and value.
Note that the final risk value is identified using three descriptors: High, Medium, and Low. A final risk value that falls between 1 to 5 is categorized as Low, while a final value in the range of 6 to 12 is qualified as Medium. For a risk to be considered High, it must have a value between 13 to 15. We also assign a different color to each Risk Level to help you more easily visualize the final risk value.
Example
Let’s say, you are working on a construction project in a coastal area and want to calculate the overall risk value of a potential flood around the construction site. Based on local meteorological data from the past 6 months, you assess the likelihood of this happening to be substantial but not certain, so you assign it a Likelihood Value of Moderate (3).
However, considering the delicate stage of the construction phase you are in, you are sure that a flood will have a devastating effect on the newly laid down foundation of your building, so you assign it a Consequence Value of Severe (15).
When you add these values to the drop-down menus, you have a final value – a risk value of High (15).
Risk Scenarios Ranked by Priority
- Low priority: Risks such as lack of communication and scheduling errors can leave projects open to scope creep and missed deliverables.
- Medium priority: Risks such as unplanned or additional work can cause teams to struggle with productivity and create unclear objectives.
- High priority: Risks such as data security and theft can leave your company open to revenue loss and should be prioritized.
Who Is This Template For?
- Project managers
- Risk management teams
- Business leaders and executives
- Team leaders
- Compliance officers/safety managers
- Consultants/Helping organizations
Final Thoughts
A systematic way to find out which risks require more immediate attention and which ones are less critical. Regardless of whether you are a government agency responsible for flood control or a big oil-drilling company risking a blowout at an oil well, our Risk Matrix template is a useful tool as it can support proactive risk management by identifying potential threats early in the project or business process.
Our free Risk Matrix Template is available for download in Excel format!
Be aware that spreadsheets are somewhat prone to error. Even if the spreadsheet is completely free of errors at the time you download it, there is always a possibility that you might accidentally introduce errors as you edit it. That’s why we would recommend using this Risk Matrix template only if you are comfortable using Excel and can identify and fix errors that may be introduced. With that said, download and enjoy!









