What a risk score cannot tell you: averages, rare disasters and different kinds of uncertainty

Likelihood times consequence ranks risks as if the business could average out its losses. Why that hides the risks that could end it, and how to match responses to each kind of uncertainty.

Most risk matrices work the same way. Rate each risk’s likelihood from 1 to 5, rate its consequence from 1 to 5, multiply the two, and sort the list. The number makes a long list manageable. Without it, risk discussions become a contest between whoever argues most forcefully. A comparable score is what makes it possible to decide where effort goes.

But the score is not neutral. Multiplying likelihood by consequence is a rough expected value: the average result if the same gamble were run many times. Ranking by that average makes sense for an organisation that will face the risk again and again and can absorb any single outcome. A small business usually cannot. It runs each year once. It has one bank facility, one key customer contract, one licence and one set of savings. It does not experience the average; it experiences what actually happens.

This article explains what the common risk score assumes, why the risks that could end a business often sit below the bottom of the scale, and why different kinds of uncertainty, such as technical, market, execution and structural, need different responses rather than one combined rating. It is general information; your accountant, insurer or adviser can help with specific exposures.

The multiplication is an assumption

Multiplying likelihood by consequence treats a loss of ten as exactly ten times worse than a loss of one. For a large, diversified organisation facing many similar exposures, that is roughly true, and the average is a sensible guide. For a business with a cash buffer, loan covenants or one obligation it cannot fail, it is false at the top of the range. Somewhere there is a level of loss beyond which the business cannot continue in its present form. Below that line, losses are painful but survivable. Above it, they are a different kind of thing altogether.

Two consequences follow, and you can check them on almost any 5 × 5 matrix:

  • Very different events get the same score. A catastrophe rated “rare” (1 × 5 = 5) scores the same as a trivial nuisance rated “almost certain” (5 × 1 = 5). The matrix prescribes the same response to both.
  • Frequency usually beats severity. A minor problem that happens almost every month (5 × 2 = 10) outranks a major one that happens rarely (2 × 4 = 8). That is what an average means. It only becomes a problem when the business could not survive the major one, and then the ranking is upside down relative to the business’s real interest.

Adding and multiplying give different answers

Some risk templates add the two ratings instead of multiplying them. This looks like a matter of house style, but it changes the order of risks, particularly in the region that matters most:

EventLikelihoodConsequenceAddedMultiplied
Rare, catastrophic1565
Unlikely, moderate2356

Adding ranks the catastrophe higher; multiplying ranks it lower. Same events, same judgements, opposite priority. Neither method is right in the abstract. Adding is cruder but more cautious about severe outcomes, because a small likelihood can never shrink a large consequence to nothing. Multiplying suits a business that genuinely cares about the average. The problem arises when a business uses one method without realising what it implies, or, worse, uses both in different documents.

Ratings are labels, not measurements

The inputs to a risk matrix are not measurements. They are ordered categories with descriptions: “unlikely”, “possible”, “likely”. Multiplying category 3 by category 4 gives 12, which looks like a number but does not behave like one. A risk scored 20 is not twice as bad as one scored 10. Colour bands set at particular scores, such as “12 and above is red”, give an impression of precision the inputs do not support.

That does not make matrices useless. They are good at sorting a long list into rough groups and starting a conversation. They are poor at deciding exactly how much to spend, or at comparing very different kinds of risk. The making a risk register change decisions article covers what a working register needs beyond its ratings.

The bottom of the scale

Every likelihood scale has a lowest category, and that category has a floor. A common template defines “rare” as less than 5% a year. That is the same as saying “nothing rarer than once in twenty years”. Other templates stop at 10% or even 20%. None offers a way to record something like “one in five hundred”.

That is where many business-ending events sit: a fire that destroys the premises, the failure of a sole supplier for a critical component, the loss of a licence or water allocation, the collapse of the customer that takes most of your output. If these were common, they would already have happened and the business would have adapted. They are rare, and their consequences are severe.

Lowest category as writtenRarest event it can expressWhat it hides
Below 20% a yearAbout once in five yearsAnything on a longer cycle
Below 10% a yearAbout once in ten yearsMost equipment-life and lease-length risks
Below 5% a yearAbout once in twenty yearsRare, severe and linked failures

When someone tries to record such an event, the scale forces a poor choice. Put it in the lowest band, and the entry claims it is far more likely than anyone believes, so others discount it as alarmist. Leave it out, and nobody owns it. Or record an honest severity with an overstated likelihood, and the score lands in a “monitor” band, producing a formal record that the business identified the risk and chose to do nothing, by arithmetic rather than by decision.

A clean register is therefore not evidence that the business is safe. It may only show what the scale can express.

Set a survival line and split the list

A simple fix is to stop ranking survivable and non-survivable risks together.

  1. Name your survival line. In your own terms, what loss would the business not survive as it is today? It might be a cash amount, breaching a loan covenant, losing a licence, losing a particular customer or being unable to trade for a certain number of weeks. Agree it with whoever owns the business and review it each year.
  2. Split the register. For each risk, ask whether its plausible severe outcome could cross that line. You now have two lists.
  3. Rank the survivable list by score. Here the average is a reasonable guide.
  4. Do not rank the survival list by score at all. Every risk on it needs an owner and a response, whatever its rating, and the question is how likely it is that any of them, or a combination, crosses the line.
  5. Give rare, severe events a home that does not need a likelihood rating. A continuity plan, a short list of “events we must survive” or a set of scenarios for your accountant to test against cash flow will do. Each needs an owner, a review date and a trigger.

A useful single question for each risk is: would we accept this exposure again and again, at these odds, for this stake? If yes, the score can stand. If no, it belongs on the survival list.

Also compare the scale with your commitment horizon: the length of your lease, your loan, your equipment’s life or your key contracts. If you have committed for fifteen years and your scale cannot see anything rarer than once in twenty years, events that could easily happen within your commitment are invisible.

Different kinds of uncertainty need different responses

A single score also hides what kind of uncertainty sits behind a risk. A red rating might mean an untested technology, uncertain demand, an unreliable supplier, a weak plan or a rare disaster. Each needs a different response, and a generic contingency budget resolves none of them.

Kind of uncertaintyTypical questionResponse that fits
TechnicalWill the design or process work?Tests, prototypes, trials, staged development
MarketWill customers buy, at this price, and keep buying?Customer evidence: pre-orders, pilots, small launches
ExecutionCan we deliver on time and on budget?Better estimates, past data, capacity planning, control
ExternalWill regulation, prices or conditions change?Monitoring, triggers, flexible terms
StructuralIs our own way of working creating the problem?Clearer roles, fewer competing priorities, changed sequencing
EmergingDo we even know what the question is yet?Small experiments, options, review points

Two observations from practice are worth holding on to. First, businesses tend to over-invest in reducing uncertainty they can control internally, such as engineering detail, while under-testing external demand. More engineering analysis does not tell you whether customers will buy. Second, some uncertainty is created inside the business: too many jobs competing for the same people, priorities that change weekly, information held in different places. A risk register can record the symptoms, but it will not fix the structure. Research on uncertainty in project portfolios, including work by Miia Martinsuo and colleagues published in 2014, highlights this internal source alongside external and project-level ones.

Not every important uncertainty can be turned into a register entry at all. Sometimes the information does not exist yet, and the best response is an experiment, a staged commitment or a trigger-based decision rather than another attempt at a precise rating. The uncertainty should change your options article covers staging and keeping options open.

Questions that classify a risk before you score it

Before scoring a significant risk, ask:

  • What exactly is uncertain, and why?
  • Can we reduce the uncertainty before we must decide, and how?
  • What shape is the consequence? Gradual, sudden, reversible, or capable of crossing the survival line?
  • When does it need to be resolved relative to our commitment?
  • Does our planned response address the cause, or does it just lower the score?

A worked example

This is an illustration. A family-owned winery with a cellar door keeps a 5 × 5 risk matrix. Its top-ranked risks are bottling line stoppages (likelihood 5, consequence 2, score 10), cellar door staff shortages at peak times (4 × 2 = 8) and late payment by a distributor (2 × 4 = 8). Further down sits “bushfire damages vineyard or winery” at 1 × 5 = 5, rated “rare”, the lowest likelihood the scale allows, which it defines as less than 5% a year.

The owners set a survival line: losing more than one vintage’s sales, or a cash loss large enough to breach their bank facility’s conditions. They then ask which risks could cross it:

  • A fire destroying the winery building and stock. Rare, but within the life of their fifteen-year loan, and not something the scale can describe properly.
  • Smoke affecting a whole vintage. Not on the register at all, because nobody could choose a rating.
  • Their main distributor failing. It handles about 60% of sales; a failure would remove most of the year’s income.
  • Loss of water supply in a long drought.

None of these was in the top five of the ranked list. All four now go on a separate survival list, each with an owner and a response: checking exactly what the business insurance covers and excludes, and talking to the insurer and broker about gaps; maintaining firebreaks and on-site water; setting up a second distribution channel through direct online sales; and agreeing a standing arrangement to buy in fruit from a neighbouring grower if their own crop is lost.

The owners also look at a proposal to launch a sparkling wine, which needs new equipment. The register had listed it as “new product risk: 3 × 3 = 9”. Classified properly, it has two different uncertainties. Technical: can they make it to a good standard? They answer that with a small contract-made trial batch. Market: will cellar door and online customers buy it at the planned price? They answer that by selling the trial batch before buying any equipment. A contingency budget would have addressed neither.

The bottling stoppages stay at the top of the ranked list, where an average-based ranking works: they are frequent, survivable and fixable with better maintenance.

How this applies to a small Australian business

  • Keep using a matrix to sort routine risks, but know what it assumes.
  • Check whether your template adds or multiplies, and use one consistently.
  • Write down your survival line.
  • Keep a separate list of risks that could cross it, and give each an owner and response regardless of score.
  • Check the bottom of your likelihood scale against your lease, loan and contract lengths.
  • Classify significant uncertainties before choosing a response.
  • Test demand as seriously as you test technology.
  • Look for uncertainty your own structure creates.
  • Review what your insurance actually covers. Exclusions and limits matter most for exactly the rare, severe events this article is about. Talk to your broker or insurer.

Signals worth watching

  • A risk register with nothing that could end the business on it.
  • Severe events rated “rare” and parked in a monitor band.
  • Many different risks with identical scores and identical responses.
  • Contingency budgets used as the answer to technical or market questions.
  • Risks that arise from your own competing priorities or unclear roles.
  • No one able to say whether the template adds or multiplies.

Common mistakes

  • Treating a score as a measurement.
  • Ranking survivable and non-survivable risks on one list.
  • Assuming a clean register means a safe business.
  • Extending the scale with an “extremely rare” band and believing the problem is solved.
  • Using one response for every kind of uncertainty.
  • Forcing every uncertainty into a rating when the honest answer is “we do not know yet”.

Frequently asked questions

Should we stop using a risk matrix? No. It is a useful sorting tool for routine risks. Just do not ask it to decide things it cannot, such as how to handle risks that could end the business.

How do we set a survival line? Start with your cash buffer, loan conditions, key contracts and licences. Ask your accountant what loss, or how many weeks without trading, the business could absorb. A rough figure is far better than none.

Is it alarmist to list rare disasters? Not if each has a sensible, proportionate response. The aim is to make sure someone owns them, not to dwell on them.

What if we cannot estimate a likelihood at all? Record the event without a rating on your survival list, with an owner and a response. Inventing a number adds false precision.

Can insurance solve the survival list? For some risks, partly. Check limits, exclusions and waiting periods carefully, because the events that matter most are often the ones with the most conditions attached.

Questions to ask

  • Does our risk template add or multiply, and did we choose that?
  • What loss would the business not survive?
  • Which risks could cross that line, and do they all have owners?
  • What is the rarest event our scale can express, and how does that compare with our lease and loan terms?
  • What kind of uncertainty sits behind each of our top risks?
  • Which of our responses address the cause, and which only lower the score?

Bringing it together

A risk score is a useful way to sort a long list, but it carries assumptions. Multiplying likelihood by consequence ranks risks by their average effect, which suits an organisation that can absorb any single loss, not a small business that experiences each outcome once. The bottom of most likelihood scales sits above the range where many business-ending events live. Set a survival line, keep the risks that could cross it on a separate list with owners and responses, and classify uncertainty by its kind before choosing how to respond. The goal is not a more elaborate score, but a clearer view of what the score cannot see.


Source: KEVOS notes, drawing on teaching material on qualitative risk assessment and risk matrices, and on M. Martinsuo, T. Korhonen and T. Laine, “Identifying, framing and managing uncertainties in project portfolios”, International Journal of Project Management (2014). Examples and figures in this article are illustrations. This article is general information, not financial, legal or insurance advice.

Need practical engineering, manufacturing or process support? KEVOS can help move the work forward.