Likelihood and Impact Matrix

Grid that scores a risk by how likely it is against how bad it would be, turning the two into a single rating used to prioritise treatment.

A likelihood and impact matrix, also called a risk matrix or a probability and impact matrix, scores a risk on two axes: how likely the event is, and how bad it would be if it happened. The two scores combine into one rating, which decides how urgently the risk is treated and who has to sign it off.

The 5×5 likelihood and impact matrix

Read the likelihood down the side and the impact across the top. Each cell shows likelihood multiplied by impact, and the band that score falls into. The scales and bands below are the ones Tidal Control uses, so a score you read here is the score you get in the product; see Conducting Risk Assessments for the workflow around it.

Likelihood / Impact1 Insignificant2 Minor3 Moderate4 Major5 Extreme
5 Almost certain5 Low10 Medium15 Medium20 High25 High
4 Likely4 Low8 Medium12 Medium16 High20 High
3 Possible3 Low6 Low9 Medium12 Medium15 Medium
2 Unlikely2 Low4 Low6 Low8 Medium10 Medium
1 Remote1 Low2 Low3 Low4 Low5 Low

The bands are 1-6 Low, 7-15 Medium and 16-25 High. Those cut-offs are a choice rather than a formula: this one is deliberately forgiving at the bottom, so a rare event with a serious consequence does not automatically outrank a frequent one. Where you draw them is the risk appetite decision, and it belongs to whoever owns the risk.

Scoring the two axes

A matrix is only as good as the definitions behind its numbers. Tidal Control pins likelihood to an annual probability, which is what stops two assessors scoring the same risk differently and averaging their disagreement away.

ScoreLikelihoodImpact
5Almost certain: over 90% chance per yearExtreme: critical threat to the organisation
4Likely: 51-90% chance per yearMajor: serious impact on business operations
3Possible: 11-50% chance per yearModerate: significant but manageable consequences
2Unlikely: 1-10% chance per yearMinor: limited impact on the organisation
1Remote: under 1% chance per yearInsignificant: negligible consequences

What each band means for treatment

The score is not the output; the decision attached to it is. In Tidal Control the score is calculated for you, and the next step is choosing one of four treatments: reduce, accept, transfer or avoid. Only reduce requires linking controls, because controls are what actually move the score.

BandUsual treatment
High (16-25)Reduce, or avoid the activity outright where an alternative exists. Needs a named owner and linked controls, not an acceptance.
Medium (7-15)Usually reduce, sometimes transfer where the exposure is financial. Accepting one is a decision someone has to record.
Low (1-6)Commonly accept, particularly where treatment costs more than the exposure. Record the reasoning either way.

Score the risk again after the controls are in place. The second score is the residual risk, and it is the one to compare against the risk appetite: anything still above it needs more than what is already there.

What ISO 27001 and ISO 27005 actually require

ISO 27001:2022 clause 6.1.2 requires a defined information security risk assessment process: criteria for accepting risk, criteria for performing assessments, and results that are consistent, valid and comparable. It says nothing about a matrix. The matrix is one way to make assessments repeatable; the requirement is the repeatability, not the grid.

ISO/IEC 27005 gives the supporting guidance on assessing information security risk, and ISO 31000 covers risk management generally. Both describe likelihood-and-consequence analysis without prescribing a size or a colour scheme. An auditor will ask to see your criteria and a sample of risks scored against them, not a particular matrix.

Common mistakes

The most consequential one is treating the numbers as arithmetic. The scores are ordinal: 4 is worse than 2, but not twice as bad. Multiplying them gives you a rank, not a quantity, and a 3×4 is not the same situation as a 4×3 even though both read as 12.

That is the substance of the long-standing academic criticism of risk matrices, most associated with Tony Cox: a matrix can rank a genuinely smaller risk above a larger one. Use it to structure the conversation, not to end it.

Two practical failures follow from that. Scores cluster in the middle, because 3 is the answer nobody has to defend, and a register that is four fifths Medium has sorted nothing.

And impact gets scored against the wrong subject: the inconvenience to your team rather than the consequence for the customer, the data subject or the obligation. Tighten the axis definitions and both usually resolve.

Last, a matrix records a judgement made on one particular day. Give each risk a review date and a trigger for re-scoring. Without them you are left with an artefact of what people feared a year ago, which is exactly what an auditor notices.

Frequently asked questions

What is a likelihood and impact matrix?
A likelihood and impact matrix is a risk-assessment tool that plots the probability of a risk against its potential consequences, so risks can be prioritised.
How does a likelihood and impact matrix work?
Each risk is scored on how likely it is to occur and how severe the impact would be; the combined score places it in a grid, often colour-coded, that shows which risks to address first.
Why use a likelihood and impact matrix?
It gives a consistent, visual way to compare and prioritise risks, which is a core part of risk assessment under ISO 27001 and other frameworks.