A likelihood and impact matrix, also called a risk matrix or a probability and impact matrix, scores a risk on two axes: how likely the event is, and how bad it would be if it happened. The two scores combine into one rating, which decides how urgently the risk is treated and who has to sign it off.
The 5×5 likelihood and impact matrix
Read the likelihood down the side and the impact across the top. Each cell shows likelihood multiplied by impact, and the band that score falls into. The scales and bands below are the ones Tidal Control uses, so a score you read here is the score you get in the product; see Conducting Risk Assessments for the workflow around it.
| Likelihood / Impact | 1 Insignificant | 2 Minor | 3 Moderate | 4 Major | 5 Extreme |
|---|---|---|---|---|---|
| 5 Almost certain | 5 Low | 10 Medium | 15 Medium | 20 High | 25 High |
| 4 Likely | 4 Low | 8 Medium | 12 Medium | 16 High | 20 High |
| 3 Possible | 3 Low | 6 Low | 9 Medium | 12 Medium | 15 Medium |
| 2 Unlikely | 2 Low | 4 Low | 6 Low | 8 Medium | 10 Medium |
| 1 Remote | 1 Low | 2 Low | 3 Low | 4 Low | 5 Low |
The bands are 1-6 Low, 7-15 Medium and 16-25 High. Those cut-offs are a choice rather than a formula: this one is deliberately forgiving at the bottom, so a rare event with a serious consequence does not automatically outrank a frequent one. Where you draw them is the risk appetite decision, and it belongs to whoever owns the risk.
Scoring the two axes
A matrix is only as good as the definitions behind its numbers. Tidal Control pins likelihood to an annual probability, which is what stops two assessors scoring the same risk differently and averaging their disagreement away.
| Score | Likelihood | Impact |
|---|---|---|
| 5 | Almost certain: over 90% chance per year | Extreme: critical threat to the organisation |
| 4 | Likely: 51-90% chance per year | Major: serious impact on business operations |
| 3 | Possible: 11-50% chance per year | Moderate: significant but manageable consequences |
| 2 | Unlikely: 1-10% chance per year | Minor: limited impact on the organisation |
| 1 | Remote: under 1% chance per year | Insignificant: negligible consequences |
What each band means for treatment
The score is not the output; the decision attached to it is. In Tidal Control the score is calculated for you, and the next step is choosing one of four treatments: reduce, accept, transfer or avoid. Only reduce requires linking controls, because controls are what actually move the score.
| Band | Usual treatment |
|---|---|
| High (16-25) | Reduce, or avoid the activity outright where an alternative exists. Needs a named owner and linked controls, not an acceptance. |
| Medium (7-15) | Usually reduce, sometimes transfer where the exposure is financial. Accepting one is a decision someone has to record. |
| Low (1-6) | Commonly accept, particularly where treatment costs more than the exposure. Record the reasoning either way. |
Score the risk again after the controls are in place. The second score is the residual risk, and it is the one to compare against the risk appetite: anything still above it needs more than what is already there.
What ISO 27001 and ISO 27005 actually require
ISO 27001:2022 clause 6.1.2 requires a defined information security risk assessment process: criteria for accepting risk, criteria for performing assessments, and results that are consistent, valid and comparable. It says nothing about a matrix. The matrix is one way to make assessments repeatable; the requirement is the repeatability, not the grid.
ISO/IEC 27005 gives the supporting guidance on assessing information security risk, and ISO 31000 covers risk management generally. Both describe likelihood-and-consequence analysis without prescribing a size or a colour scheme. An auditor will ask to see your criteria and a sample of risks scored against them, not a particular matrix.
Common mistakes
The most consequential one is treating the numbers as arithmetic. The scores are ordinal: 4 is worse than 2, but not twice as bad. Multiplying them gives you a rank, not a quantity, and a 3×4 is not the same situation as a 4×3 even though both read as 12.
That is the substance of the long-standing academic criticism of risk matrices, most associated with Tony Cox: a matrix can rank a genuinely smaller risk above a larger one. Use it to structure the conversation, not to end it.
Two practical failures follow from that. Scores cluster in the middle, because 3 is the answer nobody has to defend, and a register that is four fifths Medium has sorted nothing.
And impact gets scored against the wrong subject: the inconvenience to your team rather than the consequence for the customer, the data subject or the obligation. Tighten the axis definitions and both usually resolve.
Last, a matrix records a judgement made on one particular day. Give each risk a review date and a trigger for re-scoring. Without them you are left with an artefact of what people feared a year ago, which is exactly what an auditor notices.