Every business faces more risks than it can manage at once: fires and floods, cyberattacks, supplier failures, lawsuits, key-person loss, regulatory changes. Risk mapping is a simple, structured way to decide which risks deserve attention first and how each one should be handled, including which ones should be insured.
What a risk map is
A risk map usually has two parts. The risk register is a table that lists each risk with its causes, consequences, owner, existing controls and planned actions. The heat map is a grid that plots each risk by likelihood and impact so the most serious ones stand out visually. Together they support the risk assessment step described in ISO 31000:2018, which breaks assessment into identification, analysis and evaluation.
Step 1: Set the scope and criteria
Decide what you are mapping (the whole company, one site, one project) and over what time horizon. Then define scoring scales in plain terms. A common approach uses five levels for likelihood (rare to almost certain) and five for impact (minor to severe). Describe impact in units your managers understand: dollars of loss, days of downtime, number of injured people, regulatory consequences, reputational harm.
Step 2: Identify risks
Use several sources so that blind spots are less likely:
- interviews and workshops with department heads and frontline staff;
- your own loss history and insurance claims;
- contracts, leases and customer requirements;
- industry incident reports and regulator guidance;
- checklists by category: property, liability, people, operations, technology, financial, strategic, legal and compliance.
Write each risk as cause, event and consequence, for example "Lack of offline backups (cause) leads to ransomware encrypting the order system (event), stopping shipments for a week (consequence)." Precise wording makes risks easier to score and treat.
Step 3: Analyze and score
For each risk, estimate likelihood and impact considering the controls that already exist. Many companies record both inherent risk (before controls) and residual risk (after controls), which shows how much the business relies on each control. Multiply or combine the scores to get a rating, but treat it as a guide, not a precise measurement.
Step 4: Draw the heat map
Place each risk on the grid. Risks in the high-likelihood, high-impact corner are top priorities. Low-likelihood, high-impact risks, such as a major fire, a hurricane or a large liability verdict, often sit in a separate zone that deserves attention even though they rarely happen; these are typically the risks best suited to insurance.
Step 5: Decide on treatment
| Option | What it means | Example |
|---|---|---|
| Avoid | Stop the activity that creates the risk | Decline a contract with uncapped liability |
| Reduce | Lower likelihood or impact with controls | Sprinklers, driver training, multi-factor authentication |
| Transfer or share | Shift the financial impact to another party | Insurance, indemnity clauses, outsourcing |
| Retain | Accept the risk knowingly and budget for it | Deductibles, self-insured small losses |
Each risk needs a named owner and a deadline for actions. Without ownership, a register becomes a document no one reads.
Step 6: Connect the map to insurance
Compare the register with your current policies. Typical findings include property values that have not been updated, business income limits that do not match realistic downtime, missing cyber coverage, contracts that require higher liability limits, or cargo in transit that is not covered by any policy. A well-prepared risk map also helps underwriters understand your business, which can support better terms.
Limits of heat maps
Heat maps are easy to read but have weaknesses. Scores are subjective, ordinal scales can hide large differences between risks in the same cell, and related risks can combine into a much larger event than the grid suggests. Supplement the map with scenario analysis for the biggest exposures, and use loss data or models where they exist.
Keep it alive
Review the register at least annually and after major changes: a new location, product, acquisition or serious incident. For a broader governance approach, see our overview of risk management standards such as ISO 31000 and COSO ERM. When you are ready to insure the risks you decided to transfer, request a quote through Polis Re.