Risk Matrix¶
Artifact — instantiates Risk Aversion Calibration
Plots likelihood and consequence categories in a grid so risks can be triaged quickly and communicated to non-specialists.
When a decision faces not one risk but twenty, the first problem is not analysis but sorting — which few deserve attention and which are noise. Risk Matrix is the artifact that does the sorting: a grid with likelihood on one axis and consequence on the other, each divided into qualitative bands (rare/likely/almost-certain, minor/serious/catastrophic), so every risk drops into a cell and the cells carry a shared colour — green to tolerate, amber to watch, red to treat. Its defining property is that it is a qualitative communication and triage tool, not a calculation. It does not compute a number; it places risks into categories that a room of non-specialists can read at a glance and agree on. That is its whole value — it makes a sprawling risk landscape legible and prioritizable in one shared picture — and, as its critics stress, its whole danger too, because the same coarseness that makes it readable can distort what it sorts.
Example¶
An airline's maintenance-and-safety group is reviewing thirty open hazards on a fleet ahead of a scheduling change — everything from a fraying cabin trim clip to a rare-but-serious hydraulic anomaly. Reading thirty engineering write-ups in a meeting is hopeless, so the group uses a risk matrix. Each hazard is scored on two qualitative axes: how likely it is to occur (from remote to frequent) and how bad it would be if it did (from negligible to catastrophic). Each lands in a coloured cell. The fraying clip — frequent but negligible — sits in green and is logged for routine attention. The hydraulic anomaly — remote but catastrophic — lands in red and is escalated for immediate treatment before the schedule changes.
In twenty minutes the thirty hazards are triaged into a picture the whole cross-functional group can see and argue over — engineers, operations, and management reading the same grid. The matrix has not told anyone how to fix the hydraulic issue or how likely it truly is to the third decimal; it has done the prior job of making the field of risks legible enough to prioritize and communicate.
How it works¶
- Define the bands. Fix the qualitative categories for each axis — the likelihood tiers and the consequence tiers — and what colour each combined cell carries. The bands are the artifact's whole vocabulary.
- Place each risk. Assign every risk to a likelihood tier and a consequence tier and drop it into its cell, using expert judgment where hard numbers are absent.
- Read the triage. Let the cell colour set the priority: red demands treatment, amber watching, green tolerance — a fast, shared ranking of where attention goes.
- Route, don't resolve. Hand each high-priority risk to the mechanism that actually treats it (a cap, a hedge, a pilot); the matrix's job ends at pointing.
Tuning parameters¶
- Grid resolution — a 3×3 versus a 5×5 (or finer) grid. More cells discriminate better but slow the read and invite false precision on axes that are only qualitative.
- Band definitions — where the lines between "unlikely" and "likely," "serious" and "catastrophic" fall. Shifting them re-colours whole regions of the grid and quietly changes what gets escalated.
- Colour thresholds — how aggressively cells are painted red. A cautious scheme escalates more and can flood the red zone; a permissive one keeps focus but can wave through a genuine hazard.
- Aggregation rule — how a cell's colour combines likelihood and consequence (worst-of, product-of, lookup table). Different rules can rank the same two risks in opposite orders.
When it helps, and when it misleads¶
Its strength is triage and communication: it turns a pile of incommensurable risks into one legible, colour-coded picture that specialists and non-specialists can share, prioritize, and act on fast. For a first-pass sort of many risks with little quantitative data, nothing is quicker.
Its danger is that the coarse grid can lie about what it sorts. Because the axes are qualitative bands, two quantitatively very different risks can land in the same cell and look identical, and — depending on how the bands and aggregation rule are drawn — the grid can even rank some risks in the wrong order relative to a proper quantitative assessment.[1] The classic misuse is treating the coloured grid as the analysis rather than the index to it: acting on cell colour as if it were a measured risk, or letting a green cell license an exposure that a real estimate would flag. The guarding discipline is to treat the matrix as a triage front-end only — a way to decide what to look at harder — and to hand any consequential red or borderline cell to a quantitative review before betting on it.
How it implements the components¶
Risk Matrix fills the triage-facing slots:
objective_risk_estimate— it captures a coarse, qualitative estimate of each risk as a likelihood tier and a consequence tier, made legible in a shared grid.hedge_or_commitment_choice— its colour-coded triage feeds the decision by ranking which risks are tolerated, watched, or routed for treatment.
It does not anchor its tiers on base rates or compute a number — the calibration_reference_class and the quantitative average belong to its nearest twin, Expected-Value Review, which collapses the same two axes into one figure where the matrix keeps them as qualitative cells. It also does not itself bound or treat any risk (downside_protection is Downside Cap's); the grid sorts, it does not fix.
Related¶
- Instantiates: Risk Aversion Calibration — the Risk Matrix triages a field of risks into a shared, prioritized picture the rest of the calibration can act on.
- Sibling mechanisms: Risk Framing · Small Experiment · Downside Cap · Hedging or Insurance · Reversible Pilot · Expected-Value Review · Opportunity Cost Reflection
Editorial Notes¶
Form Classification¶
Form family: Representation, Specification & Plan
Rationale: Risk Matrix operates as a static representation, map, specification, schema, or prospective plan that externalizes information because it plots likelihood and consequence categories in a grid so risks can be triaged quickly and communicated to non-specialists.
Independent corroboration: The frozen evidence defines Risk Matrix as 'Plots likelihood and consequence categories in a grid so risks can be triaged quickly and communicated to non-specialists', so its operative form is Representation, Specification & Plan.
Nearest alternative: Decision, Gate & Allocation — Risk Matrix includes features of a case-specific gate, selection, routing, prioritization, or resource disposition, but its defining operation is a static representation, map, specification, schema, or prospective plan that externalizes information.
Review outcome: Independent reviewer agreement; medium confidence.
Origin Attribution¶
Primary origin: Engineering & Design
Origin pattern: Convergent development
Present-day reach: Universal
Rationale: The likelihood-by-consequence matrix is a canonical engineering safety and program-risk device used to assign risk levels and treatment priorities. Disaster management, organizational governance, statistics, and public administration independently institutionalized closely related matrices.
Related originating lineages:
- Disaster Management & Risk Reduction — disaster_management contributes preparedness, continuity, hazard containment, and recovery practice to the mechanism’s formative or independently convergent form; that contribution does not displace the primary engineering_design lineage.
- Organizational & Management Science — organizational_management contributes decision records, operating routines, knowledge reuse, and institutional learning to the mechanism’s formative or independently convergent form; that contribution does not displace the primary engineering_design lineage.
- Public Administration & Policy — public_administration_policy contributes program oversight, public allocation, implementation, and continuity obligations to the mechanism’s formative or independently convergent form; that contribution does not displace the primary engineering_design lineage.
- Statistics & Experimental Design — statistics_experimental_design contributes prospective protocols, uncertainty, longitudinal follow-up, and model validation to the mechanism’s formative or independently convergent form; that contribution does not displace the primary engineering_design lineage.
Review resolution: The blind reviewers disagreed on primary lineage (engineering_design versus disaster_management); authoritative or primary research supports engineering_design as the best historical origin. The likelihood-by-consequence matrix is a canonical engineering safety and program-risk device used to assign risk levels and treatment priorities. Disaster management, organizational governance, statistics, and public administration independently institutionalized closely related matrices. The cited NASA Goddard Risk Management Reporting; NASA Risk Management Handbook directly supports the defining operation used in that choice. All independently supported contributing domains are retained without an arbitrary cap, while domain_reach=universal records later applicability separately from provenance.
Review outcome: Researched adjudication after independent review; high confidence.
Sources consulted:
Notes¶
The matrix is the one mechanism here that is purely a communication artifact — it produces no safeguard, no estimate refinement, no posture on its own. Its right place is at the front of a calibration, as the triage that decides which risks earn the more expensive mechanisms, never as the thing a decision finally rests on.
References¶
[1] A well-known analysis of risk matrices (Cox, 2008, Risk Analysis) shows that qualitative likelihood-by-consequence grids can assign identical cells to quantitatively very different risks and, under some band and aggregation choices, rank risks in an order that a proper quantitative assessment would reverse. The lesson taken here is to use the matrix for triage and communication, not as the final quantitative judgment. registry ↩