Objectives · uncertainty · decisions
Company risk map:
from threats to action
A working risk map shows more than a list of possible problems. It links company objectives to the causes and consequences of risk, owners, chosen measures and signals that enable timely decisions.
Anton Konnov · 20 August 2026 · 10 minutes
Purpose
A risk map is for setting priorities
A long risk register quickly becomes an archive of phrasing. A managerial risk map answers different questions: which outcome is under threat, what could happen, why, how material it is and who must act.
It does not replace expertise, calculations or control procedures. Its job is to make uncertainty comparable and embed risk discussion into planning, budgeting and regular meetings.
Six steps
How to build a company risk map
Start with objectives
Record strategic, financial, operational and project outcomes, together with the decision horizon. Risk exists relative to an objective: without one, the phrasing "declining sales" does not explain which outcome and over what period is being protected.
Separate event, causes and consequences
Do not mix the source of uncertainty, the event itself and its effect in a single line. The format "because of a cause, an event may occur, leading to a consequence" simplifies the selection of preventive measures and response plans.
Assess materiality
Set consistent scales for likelihood and impact: financial, operational, legal, reputational or safety-related. Also consider how quickly the risk manifests and the time available for response. Assessment must include a rationale, not just a colour.
Assign a risk owner
The owner understands the risk, has authority to coordinate measures and can raise the issue at the right level. A performer of a single procedure is not always the owner of the overall risk; roles and escalation points must be separated.
Choose response and measures
Risk can be avoided, mitigated, transferred, accepted or used as an opportunity. For each measure, record the owner, deadline, resource, expected risk change and completion criteria. After active measures, assess the residual risk.
Embed monitoring
Define key indicators, thresholds, review frequency and decision format. Track not only the risk level but also measure completion, new causes, actual events and changes to objectives.
Risk card
Minimum set of fields
Context
Objective, process, horizon, event, causes and potential consequences.
Assessment
Likelihood, impact, speed, rationale and assessment date.
Accountability
Risk owner, measure performers and escalation level.
Response
Active controls, measure plan, indicators and target residual risk.
Heat map
Colour does not replace analysis
A probability-impact matrix helps compare risks, but creates a false sense of precision if the scales are undefined or assessments are set without evidence. Two risks of the same colour may require different responses because of development speed, interdependencies or irrecoverability.
In a managerial discussion, next to the rating there should be the reason for the change, a consequence scenario, measure status and the decision required.
Management cycle
Which risks require management attention
New and substantially changed risks, not the full register.
Deviation from the accepted risk level and reasons for the change.
Late or ineffective response measures.
Scenarios requiring resources, objective changes or separate decisions.
Interdependent risks that amplify the overall effect.
Mistakes
What turns a risk map into a formality
Common mistakes include starting from a universal catalogue, assigning a department instead of a specific role as owner, confusing risk with an incident that has already occurred and treating "strengthen control" as a measure without a deadline and an outcome.
A risk map also becomes outdated if it is reviewed only once a year. The frequency should match the pace of change for the specific risk and the management decision cycle.
Sources
Methodological references
ISO 31000:2018 — principles, framework and process for risk management ↗
COSO ERM — integrating risk with strategy and performance ↗
IIA Three Lines Model — roles in risk management and control ↗
This material is educational. Legal, tax, sector-specific and technical risks require appropriate specialised expertise.
First step
Start with one objective and a few decisions
We will define material risks, owners, assessment criteria and a practical review cycle.