Company Risk Analysis: Matrix, Template, and Examples
A risk analysis makes it visible what could derail the strategy — and who is doing something about it. Here you'll find categories, a risk matrix, a template with score and owner, and a methodology that keeps the analysis alive throughout the year.
Published · Updated · 7 min read
In short
- Risk analysis = event, probability, consequence, management, owner, and deadline.
- Use categories (market, suppliers, key personnel, economy, IT, compliance) as a checklist.
- Score = probability × consequence. Anything above 12 requires active action.
- 10-15 active risks at management level, reviewed quarterly at the strategy review.
What is a risk analysis?
A risk analysis is a systematic review of events that could prevent the company from achieving its goals. For each risk, probability and consequence are assessed, and a management strategy with a named owner is decided. The purpose is not to eliminate all risk, but to know which risks you consciously take — and which ones you address.
Strategic risk analysis is different from occupational health and safety or food safety risk, where legislation dictates the form. Here, it's about the business's resilience: customer concentration, key personnel, suppliers, liquidity, IT security, compliance, and market shifts.
The analysis is linked to the strategy. Opportunities and threats from PESTEL and SWOT become concrete when they are assigned probability, consequence, owner, and an agreed action.
Risk Categories for Danish SMEs
Use these categories as a checklist so you don't only see risks that have occurred recently.
Market and Customers
Dependence on a few customers, price pressure, loss of tenders, changed purchasing behavior.
Examples: One customer accounts for 30% of revenue; framework agreement expires next year.
Suppliers and Supply Chain
Single suppliers, delivery times, currency and raw material prices.
Examples: Only one approved supplier for a critical component.
Employees and Key Personnel
Knowledge concentrated in a few individuals, recruitment, illness, succession planning.
Examples: Only one person can operate the plant; no documented training.
Economy and Liquidity
Debtor days, credit limits, interest rate developments, investment commitments.
Examples: Liquidity is tight in Q1 every year due to seasonality.
IT and Data
Ransomware, outages, backup, access control, GDPR and NIS2.
Examples: Backup is not tested; several have administrator access.
Compliance and Reputation
Regulatory changes, documentation requirements in tenders, ESG, product liability.
Examples: Large customers demand CO2 data that is not yet reported.
Risk Matrix and Template
CONSEQUENCE
High │ Monitor closely│ Act now │ Act now
Medium│ Accept │ Monitor closely│ Act now
Low │ Accept │ Accept │ Monitor closely
└────────────────┴───────────────┴──────────────
Low Medium High
PROBABILITY
RISK │ PROB. │ CONSEQUENCE│ SCORE │ MANAGEMENT │ OWNER │ DEADLINE
───────┼───────────┼────────────┼───────┼────────────┼───────┼────────
… │ 1-5 │ 1-5 │ P×C │ … │ … │ …Score = probability × consequence on a 1-5 scale. Anything above 12 should have an active action with a deadline, not just monitoring.
How to Conduct a Risk Analysis in Six Steps
1. Start with the Goals
For each strategic goal, ask: what could cause this to fail? This makes the analysis relevant instead of generic.
2. Identify Risks in All Categories
Go through the category list with the management team. Describe the event concretely: “key employee at plant B resigns”, not “personnel risk”.
3. Assess Probability and Consequence
Use a 1-5 scale and assess independently of how easy the risk is to manage. Consequence can be measured in currency, days, or lost customers.
4. Choose Management Strategy
Avoid, reduce, transfer (insurance, contract), or accept. An accepted risk is a decision — write it down.
5. Assign Owner and Deadline
Every risk above your tolerance threshold gets an owner and a date. Actions should be tasks or projects, not just notes.
6. Revisit Quarterly
Include the top 10 risks in the strategy review. Update scores, close what's gone, and add new items.
Five Mistakes in Risk Management
- The list is so long that no risks are truly prioritized.
- Risks are formulated as topics (“IT”, “market”) instead of events with consequences.
- Probability and consequence are assessed based on how uncomfortable they are to discuss.
- The management strategy is “we'll keep an eye on it” for everything — even the most serious risks.
- The analysis is done for the board meeting and not updated again until next year.
Spreadsheet vs. Plandura for Risk Management
| Area | Spreadsheet | Plandura |
|---|---|---|
| Link to Strategy | Standalone file with no connection to goals and projects. | Risks are linked to strategic goals and projects, making the consequence visible. |
| Prioritization | Sorting must be done manually every time. | Score and status are calculated, and the most important risks are shown at the top. |
| Follow-up | No deadline, no reminder. | Owner, deadline, and automatic placement on the agenda for the next review. |
| History | Changes are overwritten. | Development in the risk landscape can be tracked over time with archive and undo. |
Frequently asked questions
What is a risk analysis?
+
A risk analysis is a systematic mapping of events that could prevent the company from achieving its goals. Each risk is assessed for probability and consequence and assigned a management strategy, an owner, and a deadline.
How do you create a risk matrix?
+
Assess each risk for probability and consequence, typically on a scale from 1 to 5, and multiply the two numbers. Place the risk in the matrix, where probability is one axis and consequence is the other. Risks in the upper right quadrant require immediate action, while the lowest ones can be consciously accepted.
How many risks should an SME track?
+
10-15 active risks at the management level are sufficient. More makes prioritization impossible. Smaller risks can be managed within departments without cluttering the management overview.
What is the difference between risk analysis and SWOT?
+
SWOT provides an overall picture of strengths, weaknesses, opportunities, and threats. Risk analysis takes the threats further and makes them operational with probability, consequence, management, owner, and deadline. SWOT is analysis, risk analysis is management.
How often should the risk analysis be updated?
+
Quarterly as part of the strategy review, and additionally when something significant changes: a major customer, a supplier, a legal requirement, a major investment, or a security incident.
Can risk analysis be done in Plandura?
+
Yes. Plandura has a built-in risk analysis tool under Strategic Analyses, where risks are assessed for probability and consequence, linked to strategic goals and projects, and assigned an owner and deadline. The most important risks are automatically included on the agenda for the next strategy review.
Related guides
These guides are closely connected to risk analysis and are natural next steps in your strategy work.
- PESTEL analysis: model and templateSix external factors that shape your market, with practical examples.
- SWOT analysis: guide and templateStrengths, weaknesses, opportunities and threats — with TOWS to turn insight into action.
- Strategy review: agenda and cadenceA fixed rhythm that keeps decisions and progress visible.
- Strategy implementation in practiceHow strategy gets executed instead of archived.
More strategy guides
Analysis and environment
Goals, KPIs and performance
Strategy process and planning
Execution and follow-up
Keep the Risk Landscape Updated with Your Strategy
Create a free account and get risk analysis, goals, KPIs, projects, and reviews in one tool.