Clause 4 asks you to understand your organisation's context, and clause 6.1 asks what you intend to do about it. Scoring is where the second half happens: a factor becomes a risk with a number on it, or an opportunity with a level, and the ones that need action stop hiding in a list.
Scoring a factor needs update_context_analysis - the same permission as adding one.
Scoring a risk
A risk carries a probability and a gravity, both on a five-point scale, and the product of the two is the risk score: R = P x G. The scale is yours; what matters at audit is that you applied it consistently.

Open the factor and go to its risk assessment.
Set the probability: how likely this is, in the year you are analysing.
Set the gravity: what it costs you if it happens.
Write the treatment - what you intend to do about it - for anything above your threshold.
A score with no treatment is an observation, not a plan. The treatment is what an auditor reads to see that clause 6.1 was actually answered.
Reading the matrix
The matrix plots every scored factor at once, so a year's risk profile is one glance rather than a spreadsheet. Opportunities are scored by level instead, and live on their own board.

A cluster in the red corner is a year that needs decisions, not more analysis.
An empty matrix means the factors were never scored - the list alone answers clause 4, not 6.1.
Click any dot to open the factor behind it.