Risk matrix Excel template: scored twice, before and after treatment

A register where you write cause, event and consequence, two scores from 1 to 5, and the severity works itself out. Then the same two scores once the action is done, so you can see whether it changed anything.

The idea: a matrix is not there to file risks away
It is there to decide which ones deserve your attention.

One score says nothing, two scores rank

A very likely but harmless risk does not deserve the same effort as an unlikely one that would cost you the project. Crossing probability and impact settles that in one multiplication, and the matrix makes it readable at a glance.

A badly worded risk cannot be treated

“Risk of delay” calls for nothing. “If the supplier underestimates the effort, testing slips by two weeks, and go-live lands after the change freeze” calls for three things. The workbook separates the cause, the event and the consequence to force that precision.

An action plan nobody measures is an intention

Most registers stop at the first assessment, then list actions nobody comes back to check. Scoring each risk again after treatment changes the nature of the exercise: the actions that move nothing show up immediately.

What the workbook contains

Five tabs, no macros, everything visible and editable. The calculation cells are locked so a formula does not get wiped by accident; the input cells stay free.

Two matrices, before and after treatment

The same five by five grid, drawn twice. On the left your risks as they stand today, on the right as they will be once the actions are done. Each cell carries the number of risks it holds and takes its colour from your thresholds. If the cloud does not move down and to the left, the action plan needs rewriting, not following.

A register that scores twice

Sixty rows, with cause, event and consequence kept apart, the response strategy, the action, the owner and the due date. Then the same two scores after treatment. Severity and level are calculated on both sides and coloured the same way, which makes the gap readable row by row.

Scales that say what they measure

Both 1 to 5 scales are documented, not just numbered: “has happened on a comparable project” for a probability of 3, “a committed deadline is at risk” for an impact of 4. That is what lets two people score roughly alike. The four severity thresholds are editable, and every colour follows.

A dashboard counting what stays open

Number of risks, how many are high or critical, average severity, and the drop obtained by the treatment as a percentage. Below, the split by level before and after, the load by category, and the ten most severe risks, ranked. A high risk with no action written is flagged in red in the register.

A useful register is not a long one. It is one where every row has moved since the last review.

How to use it

Five steps. The last one is the one almost nobody does, and it is what makes the other four worth doing.

1
Write cause, event, consequence
2
Score probability and impact
3
Read the matrix and rank
4
Pick a strategy and an action
5
Score again once the action is done
Step 1Write cause, event, consequence
Step 2Score probability and impact
Step 3Read the matrix and rank
Step 4Pick a strategy and an action
Step 5Score again once the action is done

Projects fail before execution

Among failed projects, the most cited causes all sit upstream. Multiple-choice answers: the percentages do not add up.

  • 35%

    inadequate requirements gathering

    PMI, Pulse of the Profession 2018, 4,455 practitioners
  • 29%

    inadequate vision or goal

    PMI, Pulse of the Profession 2018
  • 28%

    inadequate cost estimation

    PMI, Pulse of the Profession 2018
  • 26%

    poorly identified resource dependencies

    PMI, Pulse of the Profession 2018

Where this workbook stops

A register on a spreadsheet holds the first workshop well. What kills it afterwards has nothing to do with Excel: four things the format cannot carry.

How right the scores are

The spreadsheet cannot tell whether your 4 is a 4

Two people rarely score the same risk identically, and no formula reconciles that gap. The documented scales in the workbook reduce the spread, they do not remove it. Only an assessment with several voices does, and that is a meeting, not a file.

The link with the schedule

No risk is attached to a task

You know a supplier delay is critical, but not how far it would push the delivery, nor which other tasks depend on it. Until the project is broken down and the dependencies are declared, the impact stays a score out of five rather than a number of days.

History

A revised score overwrites the previous one

When you correct an assessment, the old one disappears. How a risk moved, creeping up for three months before it happened, stays invisible. That is exactly the signal a risk review is supposed to catch.

The review

Nothing reminds you to reopen it

A risk register goes stale in a few weeks. The workbook sends no reminder, chases no action owner and flags no overdue date. It is a snapshot, and someone has to decide to take a new one.

None of these four points is a flaw in the template. They are the limits of doing the exercise alone, in a file.

A register on its own, or a register on a project that is built

Avant

The register alone

You know what can go wrong, without knowing what it would cost.

  • The impact stays a score from 1 to 5, never a number of days
  • No risk is attached to a task in the schedule
  • Nobody knows which tasks depend on the one at risk
  • No way to compare the promised schedule with today's
  • The review depends entirely on someone remembering
Apres

With a project built in Orchesia

A risk stops being a score: it becomes a delay you can measure.

  • The project is broken down, every task carries its duration
  • Dependencies are declared, so the knock-on effect is calculated
  • The critical path says which tasks drive the end date
  • A baseline keeps the promised schedule, comparable at any time
  • A slip reads in days on the chart, not as a feeling

Doing it in Excel?

It is the most common tool for a risk register, and for a first pass it does the job. The file is sent immediately after you confirm, with no email to wait for.

What you get

  • 101 KB .xlsx workbook, no macros, works in Excel, LibreOffice and Google Sheets
  • Five tabs: how to use, settings, register, matrix, dashboard
  • 60 risks provided, editable scales and thresholds
  • Formulas visible, calculation cells protected against accidental overwriting

Your address is used to send you this file. Without ticking the box above, it joins no mailing list. Privacy policy

Frequently asked questions

Yes, and with nothing asked beyond your email address, which is used to send you the file. You are only subscribed to the newsletter if you tick the box for it, and the file is sent the same way either way.

Severity is probability multiplied by impact, a number from 1 to 25. The level is the band that number falls into: by default low from 1 to 4, moderate from 5 to 9, high from 10 to 14, critical from 15 to 25. Those four bounds are editable in the Settings tab, and every colour follows, register and matrices included.

Because the first score says what threatens you, and the second says whether your action plan changes anything. A critical risk whose residual assessment is still critical points to an action that does not address the cause. The gap between the two matrices is what makes the exercise useful, not the first one.

Avoid means removing the cause, even if that changes the scope. Reduce means lowering the probability or the impact without making the risk disappear. Transfer means handing the consequence to someone else, through a contract or insurance. Accept means deciding to do nothing and to live with it, which is still a decision and should be written down.

Yes. The labels and the descriptions of both scales are editable in the Settings tab. Do keep five levels though: the formulas, the matrix and its colours all rely on a five by five grid.

The file is a plain .xlsx with no macros. It opens in Excel, in LibreOffice Calc and in Google Sheets. On Google Sheets the conditional formatting that colours the matrix is converted, but the two dashboard charts may look slightly different.

Only the ones carrying a formula or a header, so a paste does not wipe them. Every input cell stays free: scales, thresholds, lists, and the register columns. If you want to change a formula, the protection comes off from the Review tab with the password “orchesia”.

No, and it is worth saying plainly: there is no risk management module in the software. What Orchesia does is build the project those risks threaten: breakdown, dependencies, critical path, baseline. That is what turns an impact scored 4 out of 5 into a number of days of delay.

Managing risks is pointless if the project is not built.

Without a breakdown and declared dependencies, nobody knows what a delay really pushes back. Break it down, link it up, calculate the date: free 30-day trial, no credit card.