
Guides
How to Build an Operational Risk Assessment Matrix Without Overweighting Recency
An operational risk assessment matrix goes wrong when the lookback window follows the last incident. Here are the failure cases and the fixes.
What to take away
- Recency bias enters an operational risk assessment matrix through the lookback window, not through the arithmetic. If the window starts at the last bad event, the score is already skewed.
- Fix the window and the anchors before anyone scores. OSHA's process safety rules revalidate hazard analyses on a set interval rather than after each incident.
- Record the spread, not only the average. Four scores of 2 and one score of 5 do not average into a 3.
- Write down why a score changed. That note is the audit trail a carrier or an auditor will ask for.
- Review the register on a calendar date, not when something breaks.
The costly one: a matrix rebuilt after one bad quarter
Situation: a metal fabricator in Ohio loses two weeks of output when a single-source casting supplier misses a delivery. At the next review, the plant manager pushes supply chain likelihood to 5 for every purchased part.
Consequence: the year's mitigation budget goes to supplier audits. The aging compressor and the two-person maintenance crew stay at 3, because nothing has failed yet.
Prevention: score likelihood from counts over a fixed window, such as 36 months of downtime records. Allow an override only with a written reason and a name attached.
The pull here is recency bias, which makes the latest event feel more probable than its base rate.
The ones that look fine at first
A blank five-point scale is the first problem. Situation: the template carries no definitions, so each scorer invents a meaning for a 4. Consequence: two departments compare numbers that measure different things. Prevention: define every level with a count, a dollar band, or an injury classification.
A five-point scale with no written anchors is five different scales wearing one label.
Averaging scores in a meeting is the second, and the risk owner sits in the room when the group settles on a number.
The score lands low and the spread vanishes, so collect individual scores first. Discuss only the rows where scores differ by two points or more. Averages hide that disagreement, which is why team management metrics start from a test rather than a spreadsheet.
Equal weighting is the third. Situation: a $4,000 tooling risk and a machine-guarding exposure both get likelihood times impact. Consequence: the tooling risk outranks one that can stop production or injure someone. Prevention: run a separate safety flag that no arithmetic can cancel.
The ones that only show up later
The mistake, knowledge concentration, stays invisible for months: turnover sits at 2 because no key employee has resigned in two years. The scheduler retires in June, the plant runs on memory through the season, and the register never flagged the exposure.
Score turnover by the number of processes covered by one person, not by how recently someone left.
Attach a single-person dependency flag to every critical task and review it each quarter. The bad delegation that creates those dependencies is covered in management foundations examples.
The second late-arriving mistake is register decay. Situation: no review date is set. Consequence: nine months pass, a supplier changes, and the scores still describe last spring. Prevention: put the review on the calendar and give one person ownership of the document.
What they have in common
Each case shares one mechanic. The score moved after an event, or it never moved because no event had happened. Neither is an estimate of risk.
The fixes repeat as plainly. A fixed lookback window, written anchors at every level, scores gathered before discussion, a named owner, and a review date.
Published methods handle the structure. A risk matrix is only two axes, so the anchors carry the weight. If your organization already ranks threats under a framework, reuse its tiers instead of inventing a sixth scale. (NIST Cybersecurity Framework)
When a score changes, the note matters more than the number. A performance management case study shows how thin written records fail months later, and the same logic applies to an override.
Scoring anchors that work
| Level | Likelihood anchor | Impact anchor |
|---|---|---|
| 1 | No event in 36 months | Under $2,000, no injury |
| 2 | Once in 24 months | $2,000 to $10,000 |
| 3 | Once in 12 months | $10,000 to $50,000, or restricted duty |
| 4 | Twice in 12 months | $50,000 to $250,000, or lost time |
| 5 | Monthly or more | Above $250,000, or a stop-work order |
These bands are illustrative, and yours should come from your own loss runs and maintenance logs. Counts matter more than labels, because a scorer can check a count against a record.
OSHA's standard for highly hazardous chemicals requires a fresh hazard analysis at least every five years, a window set by rule rather than by mood. (29 CFR 1910.119)
Checklist before the next scoring session
- Is the lookback window fixed and printed at the top of the matrix?
- Does every likelihood level carry a count or a frequency?
- Were individual scores collected before the group met?
- Does every risk have a named owner and a review date?
- Is single-person dependency a separate flag from turnover?
The management foundations checks that separate signal from ritual apply here too: if a control has no owner and no date, it is decoration.







