A risk score, in this document’s own terms, is nothing more than two numbers multiplied together. That simplicity is the entire point. Published in 2008 by the National Patient Safety Agency, a special health authority of the NHS in England that no longer exists, A Risk Matrix for Risk Managers set out to give every NHS trust in the country the same basic tool for comparing wildly different kinds of risk: a clinical incident, a budget overrun, a staffing shortage, a damaging news story, all scored on the same one-to-twenty-five scale.
Why the NHS needed one matrix, not many
Before this document, individual NHS organizations were, by its own account, using a variety of homegrown risk matrices, making it hard to compare a risk logged in one trust against a risk logged in another. The NPSA’s goal was not to invent a wholly new concept: consequence-times-likelihood risk matrices were already standard practice well beyond healthcare. The goal was to give the NHS a single, common version of it, simple enough to use consistently and flexible enough that individual trusts could still tailor it to local needs.
The two axes, in detail
The matrix scores every risk on two independent one-to-five scales, one for consequence and one for likelihood, and multiplies them together.
Consequence runs from negligible at 1 to catastrophic at 5. For patient safety specifically, catastrophic is defined precisely: death or permanent serious incapacity. Below that, major (4) covers injury leading to long-term incapacity or disability, requiring more than fourteen days off work, or an increase in hospital stay of more than fifteen days. Moderate (3) covers an injury requiring professional intervention and four to fourteen days off work. The same five-point scale is applied not just to physical harm but to several other domains at once: quality and complaints, staffing and competence, statutory duty and inspections, adverse publicity and reputation, business objectives, finance, and service or business interruption. A trust can score a data breach, a budget overrun or a damaging local news story on exactly the same one-to-five axis as a clinical incident, which is the entire mechanism that lets these otherwise incomparable risks sit on one shared register.
That cross-domain design is easy to underrate, so it is worth showing rather than just describing. A moderate score of 3 on the finance domain means a loss of a quarter to half a percent of budget, or a claim worth between ten thousand and one hundred thousand pounds. A moderate score of 3 on the reputation domain means local media coverage causing a long-term reduction in public confidence. Neither of those has anything to do with a patient’s physical safety, and neither is measured in the same units, yet both land at the identical severity score, ready to sit next to each other on the same risk register and compete for the same limited attention from a trust board.
Likelihood also runs one to five, and each level is anchored to a rough real-world frequency rather than left to guesswork: rare (1) means something that will probably never happen, roughly once in a hundred years; unlikely (2) is roughly once in ten years; possible (3) roughly once a year; likely (4) roughly once a month; and almost certain (5) means something that will undoubtedly happen, possibly frequently, roughly once every four days.
The grid itself
| Consequence ↓ / Likelihood → | 1 Rare | 2 Unlikely | 3 Possible | 4 Likely | 5 Almost certain |
|---|---|---|---|---|---|
| 5 Catastrophic | 5 | 10 | 15 | 20 | 25 |
| 4 Major | 4 | 8 | 12 | 16 | 20 |
| 3 Moderate | 3 | 6 | 9 | 12 | 15 |
| 2 Minor | 2 | 4 | 6 | 8 | 10 |
| 1 Negligible | 1 | 2 | 3 | 4 | 5 |
Scores toward the bottom-left of that grid land in green, the low-risk band. Scores toward the top-right land in red. The banding gives any member of staff, not just a trained risk manager, a fast visual read: a catastrophic-but-rare risk, scoring 5, is treated very differently from a moderate-but-almost-certain one, scoring 15, even though intuition might rate the first as scarier.
“The risk scores are not intended to be a precise mathematical measure of risk.”
That line appears printed directly under one NHS trust’s version of the grid, a reminder guarding against exactly the false precision a multiplication table invites. A score of 15 is not really three-fifths as bad as a score of 25; it is a rough prioritization tool, not a measurement.
An agency that closed, a tool that did not
The National Patient Safety Agency itself closed in 2012, its patient-safety functions absorbed into NHS England. The original document has not survived on an official NHS domain: the agency’s own website is gone, and no direct successor page hosts the exact 2008 text. What has survived, in a genuinely striking way, is the model itself. East London NHS Foundation Trust’s own risk grading matrix, still in use, explicitly labels its scoring tables as “based on NPSA risk matrix model,” reproducing the same five consequence categories, the same five likelihood bands, and the same one-to-twenty-five multiplication grid, more than a decade after the agency that designed it stopped existing. If you work in NHS risk management today and have never heard of the NPSA, there is a fair chance you are still using its matrix without knowing where it came from.