Score risks and opportunities

Last updated August 25, 2026

Clause 4 asks you to understand your organisation's context, and clause 6.1 asks what you intend to do about it. Scoring is where the second half happens: a factor becomes a risk with a number on it, or an opportunity with a level, and the ones that need action stop hiding in a list.

Scoring a factor needs update_context_analysis - the same permission as adding one.

Scoring a risk

A risk carries a probability and a gravity, both on a five-point scale, and the product of the two is the risk score: R = P x G. The scale is yours; what matters at audit is that you applied it consistently.

The factor form with a risk assessment being scored, probability and gravity selected and the resulting score shown.
Pick probability and gravity and the score follows immediately, along with the zone it falls in.
  1. Open the factor and go to its risk assessment.

  2. Set the probability: how likely this is, in the year you are analysing.

  3. Set the gravity: what it costs you if it happens.

  4. Write the treatment - what you intend to do about it - for anything above your threshold.

A score with no treatment is an observation, not a plan. The treatment is what an auditor reads to see that clause 6.1 was actually answered.

Reading the matrix

The matrix plots every scored factor at once, so a year's risk profile is one glance rather than a spreadsheet. Opportunities are scored by level instead, and live on their own board.

The expanded risk matrix, a five by five grid with numbered dots for each scored factor and a low, medium and high legend.
Probability runs down the left, gravity across the top, and each numbered dot is a factor sitting at that pair. Green is low, amber medium, red high.
  • A cluster in the red corner is a year that needs decisions, not more analysis.

  • An empty matrix means the factors were never scored - the list alone answers clause 4, not 6.1.

  • Click any dot to open the factor behind it.

Next: record stakeholders and their needs.

Was this article helpful?