← All articles

8 September 2026 Β· By Douwe Pietersma

Risk is not probability times impact

Risk management is not about probability times impact, but about the effect of uncertainty on your objectives β€” illustrated by a British government project as a cautionary example.

ISO 31000 risk management risk matrix FiReControl

The Tuesday afternoon with the risk matrix

In most project meetings the same ritual plays out: someone shares their screen, a list of fifteen risks appears, and each line gets a probability and an impact score between 1 and 5. The result is a heatmap with a few red boxes, everyone nods, and the meeting moves on. Twenty minutes later, no one can recall which objective was actually at stake. The problem is not the time the exercise takes, but the question behind it.

What ISO 31000 actually says

The international standard for risk management, ISO 31000, does not define risk as probability times impact. Its definition is: risk is the effect of uncertainty on objectives. That is a different question from "how likely is this and how bad will it be if it happens." The question is: if this stays uncertain, what does that do to what you're trying to achieve? A risk can score low on probability and modest on impact to the schedule in a matrix, and still threaten an objective that was never even on the list. The standard also places laws and regulations explicitly within the risk domain itself (cl. 5.4.1) β€” not as a separate compliance question alongside it, but as part of the same uncertainty about objectives.

A case that doesn't fit in a matrix cell

FiReControl, a British government project to replace nine regional fire control centres with a single national network, ended in a loss of at least Β£469 million, according to the National Audit Office (2011). A large part of the explanation lay not in technology or planning, but in the fact that the local fire services who were meant to use the system had not been sufficiently involved. This is one case, not a representative sample, but it illustrates a pattern: the risk did not sit in a cell with a probability and impact score. It sat in the fact that an entire sector β€” stakeholders and communication β€” had barely been reviewed. No probability-times-impact calculation captures "we didn't take the users seriously"; that effect only becomes visible once you ask what uncertainty does to the objective there.

What this means in practice

The conclusion is not that the matrix should be scrapped. It's that a matrix is only worth something once the input is right, and the input is only right once you systematically check, per risk sector, what effect uncertainty has on your objectives β€” not just on your schedule or budget. That is why a fixed sector breakdown (scope, planning, budget, quality, stakeholders) does more than a free brainstorm: it forces you through every domain, including the ones nobody happens to think of that morning. Hillson (2002) called such a fixed breakdown a risk breakdown structure: not a research instrument, but a prompt list that prevents a sector from being skipped simply because no stakeholder was at the table that day.

The question you can ask yourself

For the next risk on your list: don't just ask "what's the probability and what's the impact," but also "which objective does this threaten if it goes wrong, and have I actually covered that sector." That doesn't require an extra meeting. It's a different question, asked in the same meeting.

Want your project plan scanned?

Upload your project plan and receive an AI risk analysis across 5 categories with concrete recommendations within a minute.

Try RisicoRadar