Objectives · uncertainty · decisions

Company risk map:
from threats to action

A working risk map shows more than a list of possible problems. It links company objectives to the causes and consequences of risk, owners, chosen measures and signals that enable timely decisions.

Anton Konnov · 20 August 2026 · 10 minutes

Purpose

A risk map is for setting priorities

A long risk register quickly becomes an archive of phrasing. A managerial risk map answers different questions: which outcome is under threat, what could happen, why, how material it is and who must act.

It does not replace expertise, calculations or control procedures. Its job is to make uncertainty comparable and embed risk discussion into planning, budgeting and regular meetings.

Six steps

How to build a company risk map

01

Start with objectives

Record strategic, financial, operational and project outcomes, together with the decision horizon. Risk exists relative to an objective: without one, the phrasing "declining sales" does not explain which outcome and over what period is being protected.

02

Separate event, causes and consequences

Do not mix the source of uncertainty, the event itself and its effect in a single line. The format "because of a cause, an event may occur, leading to a consequence" simplifies the selection of preventive measures and response plans.

03

Assess materiality

Set consistent scales for likelihood and impact: financial, operational, legal, reputational or safety-related. Also consider how quickly the risk manifests and the time available for response. Assessment must include a rationale, not just a colour.

04

Assign a risk owner

The owner understands the risk, has authority to coordinate measures and can raise the issue at the right level. A performer of a single procedure is not always the owner of the overall risk; roles and escalation points must be separated.

05

Choose response and measures

Risk can be avoided, mitigated, transferred, accepted or used as an opportunity. For each measure, record the owner, deadline, resource, expected risk change and completion criteria. After active measures, assess the residual risk.

06

Embed monitoring

Define key indicators, thresholds, review frequency and decision format. Track not only the risk level but also measure completion, new causes, actual events and changes to objectives.

Risk card

Minimum set of fields

Context

Objective, process, horizon, event, causes and potential consequences.

Assessment

Likelihood, impact, speed, rationale and assessment date.

Accountability

Risk owner, measure performers and escalation level.

Response

Active controls, measure plan, indicators and target residual risk.

Heat map

Colour does not replace analysis

A probability-impact matrix helps compare risks, but creates a false sense of precision if the scales are undefined or assessments are set without evidence. Two risks of the same colour may require different responses because of development speed, interdependencies or irrecoverability.

In a managerial discussion, next to the rating there should be the reason for the change, a consequence scenario, measure status and the decision required.

Management cycle

Which risks require management attention

New and substantially changed risks, not the full register.

Deviation from the accepted risk level and reasons for the change.

Late or ineffective response measures.

Scenarios requiring resources, objective changes or separate decisions.

Interdependent risks that amplify the overall effect.

Mistakes

What turns a risk map into a formality

Common mistakes include starting from a universal catalogue, assigning a department instead of a specific role as owner, confusing risk with an incident that has already occurred and treating "strengthen control" as a measure without a deadline and an outcome.

A risk map also becomes outdated if it is reviewed only once a year. The frequency should match the pace of change for the specific risk and the management decision cycle.

Risk Management and Internal Control →

Sources

Methodological references

ISO 31000:2018 — principles, framework and process for risk management ↗

COSO ERM — integrating risk with strategy and performance ↗

IIA Three Lines Model — roles in risk management and control ↗

This material is educational. Legal, tax, sector-specific and technical risks require appropriate specialised expertise.

First step

Start with one objective and a few decisions

We will define material risks, owners, assessment criteria and a practical review cycle.