Workshop · Strategy
Likelihood, impact, and who answers for it
How to turn a list of worries into an instrument with an owner, a tolerance threshold and a date for the next review.
- Duration
- 2 hours 30 min
- Delivery
- On site · Virtual
- Participants
- From 6 to 16 participants
- Investment
- Request a quote
Investment depends on scope, number of participants and delivery mode. We prepare a proposal at no obligation.
The problem it solves
Most risk matrices in a small company are built once, usually because somebody outside asked for one, and never opened again. They look the part: colours, boxes, a sheet that can be shown. And they change no decision, because they are missing the one thing that makes a matrix work.
What they are missing is rarely technical rigour. It is that nobody wrote down how much of each risk the company is willing to tolerate before acting, nobody put an individual name beside each row, and nobody set a date to look again. With no threshold there is no trigger; with no owner there is nobody to act; with no date the matrix quietly ages while the operation changes underneath it.
There is also a calibration problem that repeats everywhere. Likelihood gets estimated on a scale nobody defined, so high means different things to the operations manager and to the owner, and both of them believe they agree.
What it covers
The workshop builds a matrix on the real risks of the companies in the room, not on a practice case. It starts with the step usually skipped: defining the scale. What likely means in this organisation, over what time horizon, and what a high impact means when it is measured in money, in operations stopped, in non-compliance or in a client relationship.
With the scale agreed, each risk is placed and argued. The argument matters more than the final position: when two people from the same company put the same risk in opposite corners, the conversation that follows usually uncovers that they were describing two different risks under one name.
The last part assigns. Every row leaves with an individual owner rather than a department, a threshold that defines when action is taken, the agreed action, and a review date. The cadence is set as well: what gets looked at monthly, what quarterly, and what only when something changes. A matrix without that calendar is a document. With it, it is an instrument.
What participants learn
- Define likelihood and impact scales that mean the same thing across the organisation.
- Place real risks using the evidence available rather than impressions.
- Set tolerance thresholds that say when action is taken and when it is not.
- Assign an individual owner and an agreed action to every risk on the register.
- Establish a review cadence the organisation can actually sustain.
Agenda
- What makes a matrix change decisions, and what leaves it as a document
- Likelihood scales: defining them before using them, and over what horizon
- Impact measured in money, in stopped operations, in non-compliance and in relationships
- Calibration: why high means different things inside the same room
- Tolerance: the threshold that separates monitoring from acting
- Individual owner against departmental responsibility
- Agreed action, evidence, and what gets recorded when a risk materialises
- Review cadence: monthly, quarterly or event-driven
What the organisation leaves with
- A risk matrix for your company, populated during the session.
- Your organisation's likelihood and impact scales, defined in writing.
- A tolerance threshold and a named owner for every risk on the register.
- A review calendar with a responsible person and the date of the next session.
Programme details
- Format
- Workshop
- Also available as
- Intensive workshop · Corporate training day
- Languages
- Español · English
- Includes
- Participant workbook
- Action plan
- Post-training resources
- Facilitation
- ALUD Consulting LLC — Global Business Transformation.
Who it is for
- Owners and directors who need a risk instrument and do not have one
- Operations, administration or compliance managers who maintain a risk register
- Companies asked for a matrix by a client, an insurer or a bank
- Leadership teams that built a matrix once and never used it again
Frequently asked questions
- Will the matrix we build satisfy what a third party requires of us?
- That depends on who is asking, and ALUD does not certify it. The instrument is built to run a company, not to satisfy a requirement; if a bank, a client or an insurer imposes a specific format, review it with whoever is asking.
- How many risks do we get through?
- Between eight and fifteen per company, which is usually enough. A matrix with sixty rows never gets reviewed, and the discipline of leaving the minor ones out is part of what the session practises.
- Do we need historical data to attend?
- It helps, but it is not required. The work uses what the company already has: remembered incidents, interruptions from the past year, and what the team knows. Where there is no evidence, it is recorded as an estimate and flagged for verification.
Related articles
Having information is not the same as being able to decide
Most businesses don't suffer from a lack of data. They suffer because the data they have doesn't arrive in time, together, or in a form that allows a choice.
Read more →The five calendars a Puerto Rico business runs at once
Income tax, sales tax, payroll, the municipal licence and property tax. Five different clocks, five different authorities, and nowhere they can be seen together.
Read more →Request this programme
Tell us the context and we will prepare a proposal tailored to your organisation. No obligation.
Working this inside the organisation
If this challenge will not be settled in one session, ALUD Consulting LLC works it as consulting: management consulting, human resources, strategy, organisational design, leadership development and business transformation.
