Quick Answer:

A 5×5 risk matrix is a grid that rates each risk on two axes, likelihood and consequence, each scored 1 to 5. Multiply the two and you get a risk score from 1 to 25, which maps to four bands: low (1 to 4), medium (5 to 9), high (10 to 15) and extreme (16 to 25). The full grid is below. Use it to prioritise, not to decide. A score tells you which risks to look at first. It does not tell you what to do about them, and it is only as good as the definitions your organisation agrees for each level.

Before any new project or change, the same question comes up. What could go wrong, and how much should we worry about it?

A 5×5 risk matrix is the most widely used tool for answering that. It gives you a consistent way to rate risks so that two people looking at the same hazard reach roughly the same conclusion, and so that a list of thirty risks can be sorted into the handful that need attention now.

The matrix shows you where the risks sit. Acting on them is a separate problem, and that is where a risk management software matters, because it tracks the risk over time, assigns ownership and keeps the audit trail.

This guide covers what the matrix is, the full grid with scores, how to define each level, how to use it in seven steps, a worked workplace example, and the limitations worth knowing before you rely on it.

Sentrient builds workplace compliance software for Australian and New Zealand organisations, including a risk management system that applies one rating scale across every risk in the register.

What Is A 5×5 Risk Assessment Matrix?

A 5×5 risk assessment matrix is a visual tool for evaluating and prioritising risk. It is also called a risk assessment matrix, a risk matrix or a risk assessment table, and the terms are interchangeable.

It is a grid that helps you understand how serious a risk could be and how likely it is to happen.

The “5×5” refers to its structure. Five levels of likelihood on one axis, five levels of consequence on the other, giving 25 cells.

  • Likelihood axis, sometimes labelled probability. How probable the risk is, from rare through to almost certain
  • Consequence axis, sometimes labelled impact or severity. How severe the outcome would be if it happened, from insignificant through to severe

Where the two axes meet you get a risk level, usually shown in colour coding: green, yellow, orange and red. It works like a traffic light for risk.

A risk assessment matrix is not only for large corporations or high-stakes projects. Construction, healthcare, finance, education, aged care and technology all use it, and it adapts to organisations of any size.

Australian organisations often use a version of the risk assessment matrix aligned to local regulatory expectations.

Note on terminology. Many organisations label the axes probability and impact rather than likelihood and consequence.

The two pairs mean the same thing: probability is likelihood, and impact is consequence.

Australian WHS practice tends to use likelihood and consequence, which is the convention followed here, but if your existing risk assessment matrix says probability and impact there is no need to change it.

What matters is that your organisation picks one set of terms and applies it everywhere.

The 5×5 Risk Matrix, With Scores

In a 5×5 risk matrix, each cell is the likelihood score multiplied by the consequence score, giving a risk score from 1 to 25.

Likelihood ↓ / Consequence → Insignificant Minor Moderate Major Severe
Almost certain 5 10 15 20 25
Likely 4 8 12 16 20
Possible 3 6 9 12 15
Unlikely 2 4 6 8 10
Rare 1 2 3 4 5

Read the score against these four bands.

Score Band What it means Typical response
16 to 25 Extreme Unacceptable. Work should not proceed in its current form Act immediately. Escalate to executive or board. Stop or redesign the activity
10 to 15 High Needs active management with a named owner and a date Treat as a priority. Senior manager owns it. Review monthly
5 to 9 Medium Manageable with existing controls, provided they are working Assign an owner, monitor, review quarterly
1 to 4 Low Acceptable at current levels Monitor. Review annually or when something changes

Example Of A 5×5 Risk Assessment Matrix

Example of a 5x5 risk assessment matrix with colour coded risk levels

The same grid shown visually. Likelihood runs down the vertical axis, consequence across the horizontal.

One thing the score does not tell you

A score of 12 reached through “likely x moderate” is a different problem from a 12 reached through “rare x severe”, even though the number is identical. The first needs the frequency reduced. The second needs the consequence reduced, and often justifies more spending than the score alone suggests. Always read the two components, not just the product.

The 5 Likelihood Levels

Definitions matter more than the labels. Two teams using the same five words but different meanings will produce ratings that cannot be compared, which is the most common reason a matrix stops being useful.

Level Score Plain definition A rough guide
Almost certain 5 Expected to occur in most circumstances More than once a year, or already happening
Likely 4 Will probably occur at some point Roughly once a year
Possible 3 Might occur at some time Once every one to five years
Unlikely 2 Could occur but is not expected Once every five to ten years
Rare 1 May occur only in exceptional circumstances Less than once in ten years

The frequency guide on the right is the part most organisations skip, and it is what makes ratings consistent between people. Agree it once, write it down, and apply it everywhere.

An event example makes it concrete. At a music festival, “attendees will use social media during the event” is almost certain. “Some attendees arrive late” is likely. “Light rain” is possible. “A headline artist cancels at short notice” is unlikely. “A meteor strikes the venue” is rare.

The 5 Consequence Levels

Consequence should be assessed across several dimensions, not just cost. A risk that is minor financially can be severe in safety terms.

Level Score Safety Financial Operational Reputational
Severe 5 Fatality or permanent disability Threatens viability Business stops National coverage, regulator involvement
Major 4 Serious injury, hospitalisation Significant unbudgeted loss Major disruption for days Industry or local media
Moderate 3 Injury requiring medical treatment Noticeable budget impact Disruption to one function Complaints, some external awareness
Minor 2 First aid only Absorbed within budget Brief, contained disruption Internal only
Insignificant 1 No injury Negligible No real disruption No impact

Rate against the highest applicable dimension. If an event would cause a serious injury but only a minor financial loss, it is major, not minor.

Safety outranks cost in a WHS context, and a matrix that lets a financial view override a safety view will under-rate the risks that matter most.

Using the festival example again: a few attendees forgetting warm clothing is insignificant. An ice cream vendor arriving late is minor. Intermittent sound system failures are moderate. A delayed headline act is major. A severe storm during the event is severe, because it creates genuine safety issues.

Why Use A 5×5 Risk Matrix?

1. It prioritises risks

Any project or organisation faces multiple risks, and they are not equal. Some are minor inconveniences, others could stop the business.

A matrix shows which need attention now, so time, budget and effort go where they matter rather than where they are loudest.

2. It supports proactive risk management

Handling a risk before it becomes an incident is always cheaper. Using a matrix forces you to consider what could go wrong early in planning rather than after, and identifying risks early is what makes prevention possible at all.

3. It can support better insurance and risk outcomes

Insurers and brokers respond to evidence of active risk management.

A documented risk assessment with ratings, owners and controls demonstrates that exposures are understood and managed, which is a factor in how an organisation is assessed.

Confirm any specific effect on premiums with your broker rather than assuming it.

4. It builds a risk and safety culture

A matrix is not only paperwork. Regularly assessing and discussing risk signals that safety is taken seriously.

People become more aware of hazards and more willing to raise them, which is the foundation of a risk-aware culture and, over time, of cultural risk management.

Fewer incidents and better decisions follow from that, not from the grid itself.

5. It improves project and operational risk outcomes

Being prepared for problems makes them easier to navigate. Systematically identifying and addressing risk reduces the chance of an unexpected issue derailing delivery, which helps with schedule, budget and confidence.

Stakeholders who can see risk is being managed tend to give more support and fewer surprises.

How To Use A 5×5 Risk Matrix, In 7 Steps

How to use a 5x5 risk matrix in seven steps

Step 1: Identify potential risks

Work out what could go wrong. Several approaches help:

  • Brainstorming: Get the team together and work through it systematically
  • Historical data: Look at past projects and incidents. What went wrong before is likely to recur
  • Expert judgement: People with experience in the field will spot risks others miss
  • Incident and near-miss records: Usually the richest source, and the most often overlooked

Involve a range of people. The IT lead will see technical risks the operations team will not, and the reverse is equally true.

Step 2: Assess likelihood, or probability

Estimate the probability of each risk using the five levels and the agreed frequency guide. Two approaches work:

  • Qualitative: Based on judgement and experience. A risk is likely or unlikely based on what you know
  • Quantitative: Based on data and statistics, such as a 30% chance of rain from weather records

A 5×5 matrix suits qualitative assessment, which is what most organisations use. If you have solid data, use it, but the matrix does not require it.

Sentrient GRC software for Australian organisations

Step 3: Assess consequence, or impact

Consider the impact if the risk occurred, across all four dimensions: safety, financial, operational and reputational. Rate against the highest.

Be as objective as you can. It is easy to overstate consequence out of caution or understate it out of optimism, and both distort the register.

Step 4: Plot risks on the matrix

Fill in your risk assessment matrix template. Place each risk on the grid based on its likelihood and consequence, and record the resulting score.

Light rain at an outdoor event might be possible likelihood and minor consequence, giving a score of 6, which sits in the medium band.

Digital tools help here, particularly with a large number of risks or when the matrix has to be shared and kept current across a team.

Step 5: Analyse the results

Step back and look at the pattern rather than the individual entries.

  • Are most risks clustered in one area of the matrix?
  • Is anything sitting in the extreme band that needs attention today?
  • Were there surprises, where a risk rated higher or lower than expected?
  • Are the ratings spread sensibly, or has everything been rated medium to avoid an argument?

That last one is worth checking. A register where nothing is low and nothing is extreme usually means the scale is not being applied honestly.

Step 6: Develop risk response strategies

Decide what to do. There are four standard responses:

  • Avoid: Eliminate the risk. Move an outdoor event indoors
  • Transfer: Transfer the financial consequence to someone else through insurance or contract
  • Mitigate: Reduce the likelihood or the impact. Hire marquees to mitigate rain
  • Accept: For low-band risks, decide no action is needed and monitor

Focus on the orange and red bands first. Two cautions worth carrying.

Insurance moves the cost of a risk, not the duty, and under Australian WHS law a business cannot contract out of its primary duty of care.

And for work health and safety risks, mitigation is not open-ended: regulation 36 of the model WHS Regulations sets a ranked hierarchy of control that must be worked through in order, starting with elimination.

Step 7: Implement and monitor

Put the responses into action, then keep watching. Risk assessment is a cycle, not a one-off exercise.

Are the controls working as expected? Have new risks appeared? Update the matrix as things change.

Regulation 38 makes this specific for WHS risk.

Control measures must be reviewed when they are not working, before a workplace change likely to create a new risk, when a new hazard is identified, when consultation indicates it, or when a health and safety representative requests it. Those are events, not calendar dates.

This is where a system earns its place. Revisiting a spreadsheet when someone remembers is not a monitoring process.

Software monitors risks continuously, flags early warning through key risk indicators and produces the reporting without manual chasing. Why manual risk registers fail covers the specific failure modes.

A Worked Risk Assessment Matrix Example

Festival examples make the levels easy to picture. Here is the same method applied to the kind of risk an Australian employer actually carries.

Risk Likelihood Consequence Score Band Response
Manual handling injury in the warehouse, no refresher training in 18 months Likely (4) Major (4) 16 Extreme Eliminate or substitute the lift first. Training alone is an administrative control and sits near the bottom of the hierarchy
Sustained excessive workload in a small team after two resignations Likely (4) Moderate (3) 12 High Redesign the work. An employee assistance program does not reduce the demand, so it should not move the rating
Personal information emailed to the wrong recipient Possible (3) Moderate (3) 9 Medium Technical control first, such as external-recipient warnings, then training
Contractor works on site without induction records Possible (3) Major (4) 12 High System control at the gate. Do not rely on the contractor to self-report
Key compliance knowledge held by one person Unlikely (2) Major (4) 8 Medium Document and cross-train. Low likelihood, high consequence, so treat the consequence

Two rows are worth pausing on. The workload entry is the one most often mis-rated, because support measures get recorded as controls when they do not reduce the demand creating the risk.

And the compliance-knowledge entry scores only 8, yet it is the sort of risk that becomes urgent the day a resignation letter arrives. That is the limitation of any score, and it is the reason for the next section.

What A Risk Matrix Cannot Do

The 5×5 risk matrix is useful and it is not a decision engine. Knowing where it stops is what keeps it credible with a board.

  • It compresses judgement into a number: Two people can justify a 3 or a 4 for the same risk. The score looks precise and is not, which is why the definitions and the frequency guide matter more than the arithmetic
  • It hides low-likelihood, catastrophic risks: A rare event with severe consequence scores 5, which sits in the medium band next to genuinely routine problems. Those risks usually deserve treatment the score does not justify
  • It says nothing about control effectiveness: A rating assumes your controls work. Unless you have tested them, the residual figure is an assumption rather than a measurement
  • It encourages clustering: Where ratings are contested, people settle on the middle. A register where everything is medium has stopped discriminating and is no longer doing its job
  • It is a snapshot: A rating made in March describes March. Without review triggers it quietly stops being true

None of that argues against using one. It argues for rating twice, before and after controls, and for treating residual risk as the number leadership decides against.

Bringing It Together

The 5×5 risk matrix does one job well. It turns a long list of concerns into a ranked set you can act on, using language everyone in the organisation can share.

The 5×5 risk matrix grows in value when it stops being a standalone template and becomes part of a system that tracks every risk, assigns accountability, links controls to outcomes and produces reporting without manual effort.

That is the difference between knowing your risks and managing them.

Sentrient’s risk management system applies one rating scale across the register, holds the controls and evidence alongside each risk, and is used by over 1,000 Australian organisations.

Book a no-obligation demonstration to see how it works at your size.

Frequently Asked Questions

1. What is a 5×5 risk matrix?

A grid that rates risks on two axes, likelihood and consequence, each scored 1 to 5. Multiplying the two gives a risk score from 1 to 25, which maps to four bands: low, medium, high and extreme. It is used to prioritise risks consistently so that the most serious get attention first.

2. How do you calculate a risk score on a 5×5 matrix?

Multiply the likelihood score by the consequence score. Likely (4) multiplied by major (4) gives 16, which falls in the extreme band. The four bands are 1 to 4 low, 5 to 9 medium, 10 to 15 high, and 16 to 25 extreme.

3. What do the colours on a risk matrix mean?

Green is low risk, acceptable at current levels. Yellow is medium, manageable with existing controls. Orange is high and needs active management with a named owner. Red is extreme and generally means the activity should not proceed in its current form.

4. What is the difference between likelihood and consequence?

Likelihood is how probable it is that the risk occurs. Consequence is how severe the outcome would be if it did. A risk can be highly likely with minor consequence, or rare with severe consequence, and the two need different responses even when the scores match.

5. Is a 5×5 matrix better than a 3×3?

Not automatically. A 5×5 gives more granularity, which helps when you have many risks to separate. A 3×3 is quicker and often enough for a smaller organisation. What matters more than the size is that each level has a written definition and everyone applies it the same way.

6. Who should complete the risk matrix?

The people who do the work, supported by someone who knows the rating scale. Assessments completed only by a manager or a consultant tend to miss operational detail, and assessments completed only by frontline staff tend to be inconsistent between teams. Both perspectives are needed.

7. How often should a risk matrix be reviewed?

At least quarterly for high and extreme risks, and annually for the full register. On top of that, review whenever an event triggers it. Regulation 38 of the model WHS Regulations lists those triggers, including a workplace change likely to create a new risk, a newly identified hazard, or a control that is not working.

8. What are the limitations of a risk matrix?

It compresses judgement into a number that looks more precise than it is, it under-rates rare but catastrophic risks, it assumes controls work unless you have tested them, and it invites clustering in the middle when ratings are contested. Use it to prioritise, not to make the decision for you.

9. Does a risk matrix meet Australian WHS requirements?

A matrix helps you assess and prioritise risk, which supports the duty to manage it, but the matrix alone is not the obligation. Under the model WHS Regulations you must eliminate risk so far as is reasonably practicable and, where you cannot, minimise it by working through the hierarchy of control in regulation 36. The matrix tells you what to look at. The hierarchy tells you what to do.

10. Can a 5×5 risk matrix be used for psychosocial risk?

Yes, and it should be. Australian WHS law requires psychosocial hazards to be identified, assessed and controlled using the same framework as physical hazards. The common error is rating them as controlled on the strength of support measures such as an employee assistance program, which help people cope with pressure without reducing the pressure itself.

Sources

  • ISO 31000 Risk Management, International Organization for Standardization
  • Work Health and Safety Regulations 2011, regulation 36, Hierarchy of control measures
  • Work Health and Safety Regulations 2011, regulation 38, Review of control measures
  • Safe Work Australia, Identify, assess and control hazards
  • Safe Work Australia, Psychosocial hazards

Read More About Risk Management

Disclaimer: This guide is general information current at the date of publication and is not legal advice. Work health and safety duties differ between jurisdictions and change over time. Confirm your obligations with your work health and safety regulator or a qualified adviser.