Risk Matrices: 7 Things Yours Is Probably Getting Wrong

Almost every risk assessment you will ever see contains a coloured grid. Likelihood along one axis, severity along the other, a number in each cell, and a red, amber and green scheme that tells you what to worry about.
It is so universal that most people assume it is required. It is not. No provision of health and safety law in Great Britain requires a matrix, a score, or a colour. What the law requires is different, and understanding the gap between the two improves both your assessments and your ability to defend them.
None of what follows is an argument for abandoning matrices. It is an argument for knowing what yours is doing.
1. The law asks a different question
Regulation 3 of the Management of Health and Safety at Work Regulations 1999 requires a suitable and sufficient assessment of the risks to the health and safety of employees and others, for the purpose of identifying the measures needed to comply with statutory duties.
The purpose is identifying measures. Not producing a number. And the duty those measures answer to, under section 2 of the Health and Safety at Work etc. Act 1974, is qualified by what is reasonably practicable, which is a comparison between risk and the sacrifice of reducing it.
A matrix score does not answer that comparison. It ranks. The question of whether a further control is required is answered by weighing risk against effort, and no cell in a grid contains that analysis. HSE's own guidance on managing risk is notably free of scoring schemes.
2. The multiplication is not really multiplication
The methodological problem at the centre, and once seen it is hard to unsee.
Likelihood and severity are almost always ordinal scales: rankings, not measurements. A severity of four is worse than a three, but it is not four times as bad as a one, and nothing establishes that the intervals between levels are equal.
Multiplying two ordinal numbers produces a figure with no defensible meaning. That is why a likelihood of three with a severity of four scores the same as a likelihood of four with a severity of three, when those two situations may warrant completely different responses. One is a fairly likely serious event; the other is a very likely moderate one.
The number looks precise. Its precision is manufactured.
3. The grid compresses risks that are not alike
Need Expert H&S Guidance?
Our qualified consultants can help you implement the right health & safety measures for your business.
Following directly from the above.
A five by five matrix has twenty-five cells and typically three or four action bands. Very different situations land in the same band, and the band is what drives the response.
The compression is worst at the extremes. A catastrophic outcome with very low likelihood and a minor outcome with very high likelihood frequently score similarly, and the appropriate responses are not similar at all. Low-probability high-consequence events are exactly the category where organisations under-invest, and a matrix that scores them mid-range endorses that.
4. Nobody agrees what severity means
The definitional gap that makes scores incomparable across an organisation.
Severity of what, exactly? The worst outcome that could conceivably occur, the worst credible outcome, or the most likely outcome? Each is defensible and they produce very different numbers.
In practice, most matrices do not say, so assessors apply their own convention. Cautious ones score the worst conceivable case, pragmatic ones score the likely case, and the resulting figures are then compared, aggregated and reported as though they measure the same thing.
If your organisation uses a matrix, defining this one term does more for consistency than any amount of training.
5. Inherent and residual get mixed
The second definitional gap, and it distorts reporting rather than individual assessments.
Is the score before controls or after them? Both are legitimate and they serve different purposes. Inherent risk shows what you are dealing with. Residual risk shows where you have got to.
Teams routinely mix them within one register, sometimes within one assessment, because nobody specified. The consequence appears at board level, where a register showing a mixture of inherent and residual scores cannot support any conclusion at all.
6. Scoring can substitute for thinking
The behavioural failure, and the most consequential.
The value of a risk assessment lies in identifying hazards, understanding who is exposed and how, and working out what would actually reduce the risk. A scoring exercise can absorb the available effort into calibrating numbers, and produce a document that is arithmetically complete and analytically empty.
The tell is an assessment where every hazard has a score and the control column reads "staff to be careful", "training provided" or "policy in place". Those are not controls in the sense the hierarchy contemplates, and the score has concealed that.
7. The hierarchy matters more than the number
What should be doing the work instead.
Controls are supposed to be considered in order: eliminate the hazard, substitute, engineer, apply administrative controls, and use personal protective equipment last. The question at each level is whether that measure is reasonably practicable, and the answer determines whether you move down.
A matrix tells you which hazards to look at first. It does not tell you what to do about them, and an organisation that has scored diligently and never worked down the hierarchy has done the easier half of the exercise. HSE's risk assessment templates and examples are structured around what you will do rather than around what you scored.
Where matrices genuinely earn their place
To be clear, because none of the above means throw the grid away.
Matrices are good at three things. Consistency across a large estate, where many assessors need to reach comparable conclusions. Prioritisation where resources are finite and something has to come first. And communication, because a board that will not read forty assessments will read a heat map.
Those are real benefits and they depend on the conventions being defined. A matrix with documented severity definitions, a stated position on inherent versus residual, and an explicit note that the score prioritises rather than decides is a useful instrument. One inherited from a template, with none of those settled, is decoration.
Fixing yours in an afternoon
| Element | Question | Fix |
|---|---|---|
| Severity basis | Worst conceivable, worst credible or most likely? | Define it, once, in writing |
| Inherent or residual | Which does the register hold? | Choose, and label the columns |
| Scale meaning | Do assessors read the levels the same way? | Anchor each level with examples |
| Extremes | How are low-likelihood, high-consequence risks treated? | Route them out of the scoring band |
| Controls | Does the control column contain real measures? | Test against the hierarchy |
| Purpose | Does the score decide, or prioritise? | State that it prioritises |
| The legal test | Is reasonable practicability recorded anywhere? | Record the reasoning, not just the score |
The last row is the one that matters if anything ever goes wrong. Under British law the burden falls on the employer to show that it was not reasonably practicable to do more, and a score does not discharge that. The written reasoning does.
For international groups
A group matrix is one of the few things that genuinely does transfer, and that makes it valuable for exactly the reason above: consistency across entities assessing very different environments.
What does not transfer is the conclusion. Several jurisdictions in this series require prescribed instruments rather than free-form assessment: Mexico and Colombia specify psychosocial questionnaires, Chile requires a particular questionnaire dimension to be analysed, Hungary reserves the assessment itself to a qualified specialist, and Greece requires it to be authored by the appointed safety technician and physician.
So the sensible group position is a common methodology and matrix feeding national artefacts produced locally, which is the same conclusion this series reaches on almost every topic. Holding that in one register is where health and safety consultants and software are worth more together than either alone, and periodic health and safety audits test whether the scores reflect the workplace or the template.
Where Arinite fits
Arinite writes assessments that identify measures rather than generate numbers, which is what the duty actually asks for. We support 1,500+ businesses across 50+ countries and protect 100,000+ employees, with 95%+ client retention over 15+ years. Our health and safety consultants work extensively with legal, finance and banking and IT and software organisations, where the significant risks are organisational and score poorly on grids designed for physical hazards.
Where a group operates internationally, our global health and safety consultants map one methodology onto each national requirement, and our international health and safety consultants confirm what each jurisdiction expects the output to look like.
If your register is full of scores and thin on controls, a free gap analysis will show you the difference. HSE's framework for managing health and safety is a reasonable reference in the meantime.
Related Articles
Written by
Arinite Health & Safety Consultants
Health & Safety Expert at Arinite


