Building a 5×5 risk register that actually gets used

Likelihood × consequence scoring, descriptors that make scores repeatable, inherent vs residual risk, and how to wire the register to incidents and actions — for NHS and H&S assurance teams.

Most risk registers are write-only. They get populated for a committee, scored in an afternoon, and then quietly age until the next inspection prompts a panic refresh. Yet the 5×5 matrix behind them — long standard across the NHS and health & safety practice — is a genuinely useful tool when it's run properly. This guide covers how 5×5 scoring works, how to define descriptors so two assessors reach the same score, inherent versus residual risk, review cadence, and the pitfalls that turn a register into shelf-ware.

How 5×5 scoring works

A 5×5 matrix scores each risk on two axes:

  • Likelihood — how probable is it that the risk materialises? Scored 1 (rare) to 5 (almost certain).
  • Consequence (or impact/severity) — if it happens, how bad is it? Scored 1 (negligible) to 5 (catastrophic).

The risk score is the product: likelihood × consequence, giving a range of 1–25. Scores are then banded — a common NHS-style banding is 1–3 low (green), 4–6 moderate (yellow), 8–12 high (amber), 15–25 extreme (red). The bands, not the raw numbers, should drive behaviour: who owns the risk, how often it's reviewed, and what level of sign-off is needed to tolerate it. Many organisations set an escalation rule — for example, any risk scoring 15+ goes to the board-level register — so the arithmetic connects directly to governance.

Descriptors: the difference between scoring and guessing

A bare 1–5 scale invites inconsistency: one matron's "possible" is another's "likely". The fix is written descriptors for every point on both scales, agreed once and used everywhere. For likelihood, anchor each point to something checkable — either frequency ("expected to occur at least monthly") or probability ("will probably occur in most circumstances"). For consequence, build a descriptor table with a row per score and a column per impact domain relevant to your organisation — patient/staff harm, service disruption, statutory duty, finance, reputation. A consequence 4 might read "major injury leading to long-term incapacity" in the harm column and "prosecution or improvement notice" in the statutory column; the assessor scores against the worst applicable domain.

Two disciplines make descriptors work in practice:

  • Score consequence for the plausible severe outcome, not the theoretical worst case. Almost anything can kill someone in a sufficiently contrived scenario; scoring that way pushes everything red and destroys discrimination.
  • Use evidence for likelihood. Incident history, audit findings and near-miss data beat gut feel. If a risk scored "unlikely" has materialised twice this year, the score is wrong.

Inherent vs residual risk

Score each risk twice:

  • Inherent (gross) risk — the score with no controls in place, or if all controls failed.
  • Residual (net) risk — the score with current controls operating as they actually operate (not as the policy says they should).

The gap between the two is the value your controls are delivering — which is exactly what an assurance committee needs to see. A large gap on a critical risk means the controls carry heavy weight and deserve assurance activity (audits, spot checks) to confirm they really work. Inherent 20, residual 20 means your controls do nothing, or don't exist. Many teams add a third value, target risk — the level the organisation is willing to live with — so every risk either sits at target (tolerate, keep watching) or has actions to close the gap (treat). Be honest when scoring residual risk: score the control as it operates today, evidence and all, not the control as designed.

Review cadence: proportionate and enforced

A risk register is only as credible as its review dates. Tie cadence to the residual band and make it non-negotiable:

Residual bandTypical review cycleTypical oversight
Extreme (15–25)MonthlyBoard / executive committee
High (8–12)QuarterlyDirectorate / divisional governance
Moderate (4–6)Six-monthlyDepartment lead
Low (1–3)AnnualLocal owner

A review is more than initialling a date. At minimum: has anything changed (incidents, audit findings, new controls)? Is the score still right? Are the actions moving? Should the risk be closed, de-escalated or escalated? Record the answer, even when it's "no change" — an unchanged score with a documented reason is assurance; an unchanged score with a blank is neglect. Every risk needs a named owner (a person, not "the department") with the authority to progress the actions.

Link risks to actions and incidents

The register earns its keep when it's wired to the rest of your governance rather than floating alongside it:

  • Actions (CAPA). Every risk above target should carry specific corrective/preventive actions, each with an owner and a deadline. When actions complete, re-score the residual risk — if completing an action never changes a score, either the action was cosmetic or the scoring is.
  • Incidents. Map incident categories to register risks. A risk scored likelihood 2 that keeps appearing in incident reports is telling you its score is fiction; conversely, an incident with no corresponding risk exposes a register gap. This feedback loop is what turns scoring from opinion into measurement.
  • Audit and assurance. Log audit findings against the controls they tested, so "residual risk relies on control X" comes with evidence that control X actually operates.

Maintaining these links is the part that defeats spreadsheets — cross-referencing risks, actions and incidents by hand decays within months. Assurance platforms such as AssureIQ keep risks, CAPA actions and incident logs connected in one place so re-scoring and review evidence accumulate as a by-product of normal work. Tooling helps the discipline; it can't substitute for it.

Common pitfalls

  1. Everything scores 12. When most risks cluster in one amber cell, the register can't prioritise. Causes: vague descriptors, worst-case consequence scoring, and social pressure (high enough to look diligent, low enough to avoid escalation). Fix the descriptors and force-rank the register periodically.
  2. Stale reviews. Review dates six months past. If the cadence is unachievable, shrink the register rather than pretend to review it.
  3. Risks written as problems, not risks. "Staffing" is not a risk. "Risk that sustained nursing vacancies above X% lead to missed observations and patient harm" can be scored, controlled and acted on. Cause → event → consequence.
  4. Scores that never move. A register where nothing changes for a year isn't stable, it's ignored.
  5. Register as ritual. If the register never changes a decision — never redirects budget, staffing or audit effort — it is documentation theatre. The test of a working register is that leaders use it to choose.
  6. Orphaned risks. Owners who have left, actions assigned to teams that no longer exist. Ownership hygiene is part of review.

A register people actually use

Aim for fewer, better risks: articulate each one properly, score it against shared descriptors, give it an owner, wire it to incidents and actions, and review it on a cadence you can genuinely sustain. A twenty-risk register that is alive beats a two-hundred-risk register that is embalmed — and when an inspector or auditor asks "how do you know?", a living register is the most convincing answer you can give.

This guide is general information, not legal, tax or compliance advice. Rules change — always check the current official guidance for your situation.

Put it into practice

AssureIQ is built for exactly this — see what it does or book a free demo.

Keep risks, actions and incidents in one place

AssureIQ links your 5×5 risk register to CAPA actions and incident logs so reviews and re-scoring happen as part of normal work — the tooling helps the discipline, it doesn't replace it.

You own your dataUK-hostedUK GDPR compliant