The Tuesday afternoon with the risk matrix
In most project meetings the same ritual plays out: someone shares their screen, a list of fifteen risks appears, and each line gets a probability and an impact score between 1 and 5. The result is a heatmap with a few red boxes, everyone nods, and the meeting moves on. Twenty minutes later, no one can recall which objective was actually at stake. The problem is not the time the exercise takes, but the question behind it.
What ISO 31000 actually says
The international standard for risk management, ISO 31000, does not define risk as probability times impact. Its definition is: risk is the effect of uncertainty on objectives. That is a different question from "how likely is this and how bad will it be if it happens." The question is: if this stays uncertain, what does that do to what you're trying to achieve? A risk can score low on probability and modest on impact to the schedule in a matrix, and still threaten an objective that was never even on the list. The standard also places laws and regulations explicitly within the risk domain itself (cl. 5.4.1) β not as a separate compliance question alongside it, but as part of the same uncertainty about objectives.
A case that doesn't fit in a matrix cell
FiReControl, a British government project to replace nine regional fire control centres with a single national network, ended in a loss of at least Β£469 million, according to the National Audit Office (2011). A large part of the explanation lay not in technology or planning, but in the fact that the local fire services who were meant to use the system had not been sufficiently involved. This is one case, not a representative sample, but it illustrates a pattern: the risk did not sit in a cell with a probability and impact score. It sat in the fact that an entire sector β stakeholders and communication β had barely been reviewed. No probability-times-impact calculation captures "we didn't take the users seriously"; that effect only becomes visible once you ask what uncertainty does to the objective there.
What this means in practice
The conclusion is not that the matrix should be scrapped. It's that a matrix is only worth something once the input is right, and the input is only right once you systematically check, per risk sector, what effect uncertainty has on your objectives β not just on your schedule or budget. That is why a fixed sector breakdown (scope, planning, budget, quality, stakeholders) does more than a free brainstorm: it forces you through every domain, including the ones nobody happens to think of that morning. Hillson (2002) called such a fixed breakdown a risk breakdown structure: not a research instrument, but a prompt list that prevents a sector from being skipped simply because no stakeholder was at the table that day.
The question you can ask yourself
For the next risk on your list: don't just ask "what's the probability and what's the impact," but also "which objective does this threaten if it goes wrong, and have I actually covered that sector." That doesn't require an extra meeting. It's a different question, asked in the same meeting.