Risk Matrix Calculator
Calculate a risk score from likelihood and impact ratings on a 5x5 matrix, with the risk level from low to critical for risk assessments.
Last reviewed by the Radiatus Cloud team
Calculate a risk score and level from likelihood and impact.
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Calculate a risk score
A risk matrix is a standard tool for assessing risks by combining how likely an event is with how severe its impact would be. This calculator uses a five-by-five matrix, where likelihood and impact are each rated from one to five, and multiplies them to give a risk score from one to twenty-five. The score maps to a risk level: low, medium, high or critical. A likely event with a major impact, rated four and four, scores sixteen, a high risk.
Scoring risks consistently this way lets you compare and prioritise them objectively.
Using risk matrices
Risk matrices are widely used in information security, health and safety, project management and compliance to prioritise where to focus mitigation effort. The score and level help decide which risks need immediate action, which can be monitored, and which are acceptable. Plotting many risks on the matrix gives a quick visual sense of a risk landscape and supports a risk register.
The thresholds between levels can be tuned to your organisation appetite for risk, so treat the bands here as a common default. All calculation happens locally in your browser.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
How is the risk score calculated?
By multiplying the likelihood rating by the impact rating, each from one to five, giving a score from one to twenty-five.
What do the risk levels mean?
They group scores into low, medium, high and critical bands to help prioritise which risks need attention first.
Can I change the thresholds?
The bands here are a common default. In practice they are tuned to an organisation risk appetite, so adjust your interpretation accordingly.
Where are risk matrices used?
In information security, health and safety, project management and compliance, wherever risks must be assessed and prioritised consistently.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose the likelihood and impact ratings.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.