If you have sat in a board pack review, a risk committee, or an ICAAP-style discussion, you have seen a risk matrix or heat map. Usually it is a 5×5 grid: likelihood on one axis, impact on the other, risks plotted as dots or bands of colour. It is still the default way risk gets shown to leadership - not because any single supervisor mandates that layout, but because it answers one question quickly: where is the portfolio concentrated?
The common pitfall is not choosing a 5×5 layout in itself. It is letting the grid become the artefact while the definitions underneath - money, non-financial harm, credible frequency - stay implicit. Heat maps work best when paired with clear methodology: what each band means, how scores relate to controls, and who is accountable. The sections below cover what the visual does well, where it diverges from real loss, and what typically belongs alongside it - including inherent vs residual vs appetite, assessment method, how packs get built, and risk ownership.
Why committees still want the visual first
A long register does not answer where should we focus this quarter? A heat map gives a portfolio shape: top-right clustering, empty corners, quarter-on-quarter movement. That matches how board-level risk reporting is often consumed: scan, then drill. For the operational cadence behind the pack, see how ERM teams produce board-ready reports on a recurring cycle.
Supervisors care that oversight is real, not that you picked five bands instead of four. What gets challenged is whether the board sees consistent, comparable material risk information - which is why the same visual language across divisions still matters, even when risk specialists know the limits of ordinal scoring.

