Back to Glossary

Entry · Business

Risk Heat Map

A risk heat map is a grid that places defined risk scenarios by assessed likelihood and impact, often using colours to show relative attention levels. It gives leaders a quick view of a risk register, but the colour is a management convention, not a probability or cash-loss estimate on its own.

The axes, thresholds and time horizon must be stated for the picture to be useful.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A board faces a long list of operational risks, and a heat map can show which assessed scenarios fall into higher or lower zones so leaders can discuss them. It should point back to detailed records, not replace the evidence behind each dot.

Write each risk as a scenario: 'Cyber' is too vague, whereas 'a ransomware attack stops order processing for three days' says what event and consequence are being assessed. Define likelihood over a time period, because 'possible' could mean within twelve months or within ten years, and use a shared scale with descriptions, data and assumptions so teams do not score similar events in incompatible ways.

Define impact against business objectives, since financial loss, safety, customer harm, legal exposure and service interruption may all matter. A small cash loss with serious safety consequences should not automatically be coloured green.

Many maps use a five-by-five grid in which a row or column represents one level of likelihood or impact. Some firms multiply 1-to-5 scores while others use a policy-defined combination, but these numbers are ordinal categories, not precise probabilities.

Colour conventions vary, with red often signalling an escalation or prompt response, amber a review and green routine monitoring, and a colour only means what the organisation's thresholds and risk appetite say it means, so include a legend. A high-likelihood, low-impact event and a low-likelihood, high-impact event can yield the same simple score, yet they may need very different responses, so read the scenario and potential severity before allocating money by colour alone.

A map also does not calculate expected loss merely because scores are multiplied: a likelihood category of four and impact category of five yield 20 on a chosen ordinal scale, not a 20% chance or a $20 million loss. NIST's enterprise-risk guidance notes that prioritisation is informed by the organisation's strategy and more than a raw exposure number, and it also discusses visualising priorities, which supports the point that a coloured cell is not the final decision.

Distinguish risk before controls from risk after controls: a warehouse fire may have a high inherent impact but lower residual likelihood after alarms and suppression, so show which view the map displays and whether a proposed control is already implemented. Record uncertainty too, because a likelihood estimate based on three incidents is not as reliable as a well-observed process failure rate, and mark low-confidence assessments or use a range so a bright colour does not create false certainty.

Link each map item to a risk register that identifies owner, cause, impact, controls, assessment date and response, since a map with anonymous dots makes it harder to move from discussion to action. Review changes over time, because a supplier's financial condition can worsen and a new regulation can raise impact, and update the map when new evidence appears, not only at the next annual board meeting.

Pair the map with action: for each priority risk, decide whether to reduce, transfer, accept or avoid it, with an owner and review date. For an owner, a risk heat map helps start a focused conversation, so define scenarios and scales, preserve the records behind the colours and use judgement about consequences before setting the response; a board presentation that changes no response is only a picture.

In practice

Real-world examples.

1

Example

A ransomware scenario is plotted at likelihood four and impact five under a named annual assessment scale. It is escalated to its owner, who must present a response plan at the next risk committee.

2

Example

A rare but severe safety event is reviewed despite a middling product score on a five-by-five map. The safety lead argues that the potential harm to people matters more than the arithmetic, and the board agrees to track it.

3

Example

A board sees that a supplier risk moved from amber to red after new evidence and asks for a dated response plan. The procurement owner returns with a second-source proposal and a cost estimate.

Formula

Calculation

One illustrative ordinal score = likelihood category x impact category. Four times five equals 20, which is 'red' only if the organisation's legend says so. It is not a 20% probability or a monetary loss estimate. Worked example. A fictional legend treats scores of 15 to 25 as red, 8 to 14 as amber and 1 to 7 as green. A ransomware scenario at likelihood 4 and impact 5 scores 4 x 5 = 20, which is red. A supplier-failure scenario at likelihood 3 and impact 4 scores 3 x 4 = 12, which is amber. A rare but severe safety event at likelihood 1 and impact 5 scores 1 x 5 = 5, which is green on the score alone, so the fictional policy adds a rule that any impact-5 scenario is reviewed by the board regardless of colour.

Case study

Seen in the real world.

This entirely fictional example concerns Crescent Logistics, an invented firm. Its board had 60 risks in a list and could not see which had changed. Management defined a five-by-five scale, mapped scenarios and linked each dot to an owner and response. A low-frequency warehouse safety risk received extra discussion despite a moderate numeric score.

The case illustrates why the map starts a decision, not why the colour alone determines it. At the following quarterly review, the board compared the new map with the previous one and asked owners to explain every dot that had moved. Two risks had fallen after new controls were installed, and one had risen after a supplier's accounts weakened. The discussion shifted from reading a list to deciding what to do next.

Watch out

Common mistakes.

  • Scoring a vague label without a defined scenario, time period or impact scale.
  • Treating ordinal score products and colours as precise probabilities or automatic priorities.
  • Leaving a map unchanged after controls, evidence or business objectives shift.

Questions

People also ask.

What is a risk heat map?

It is a visual grid showing assessed risk scenarios by likelihood and impact under stated scales.

What do the colours mean?

They mean the organisation's defined attention or escalation levels, not universal probabilities.

How is a risk scored?

Use agreed likelihood and impact categories, sometimes multiplied for an illustrative rank, then apply judgement and risk appetite.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.