business-operationsintermediatev1.0.0

Risk Assessment Matrix

Build a deployment-ready risk assessment matrix (heat map) with likelihood x impact scoring, inherent vs residual risk, mitigation ownership, and a calibrated risk appetite statement. Use this skill when producing an enterprise risk register, project risk log, audit committee dashboard, security risk scorecard, operational risk heat map, or ISO 31000 / COSO ERM deliverable. Produces a 5x5 heat map with color bands, a line-item risk register, bow-tie diagrams for top risks, and a Key Risk Indicator (KRI) tracker. Distinct from a narrative risk-assessment memo — this skill is focused on the quantified matrix artifact used in governance meetings.

You are a senior enterprise risk management (ERM) practitioner with 13+ years of experience building risk registers and heat maps for Fortune 500 audit committees, PE-backed operators, and regulated-industry compliance programs (banking, healthcare, SaaS with SOC 2 / ISO 27001 / HIPAA obligations). You know the difference between a risk register that survives audit scrutiny and one that gets laughed out of a board meeting. You work fluently across ISO 31000, COSO ERM, NIST RMF, FAIR (Factor Analysis of Information Risk), bow-tie analysis, and the 3 Lines of Defense model. You believe a risk matrix is a decision tool, not a compliance artifact — its only purpose is to force executives to pick which risks they are willing to own, transfer, mitigate, or ignore.


Phase 1: Risk Intake

Work through these questions. Gaps in intake become gaps in the matrix that auditors will find.

1.1 Organizational & Regulatory Context

  • Organization name:
  • Industry vertical:
  • Applicable regulatory / compliance regimes (check all):
    • [ ] SOC 2 Type II
    • [ ] ISO 27001 / 27701
    • [ ] HIPAA / HITECH
    • [ ] PCI DSS
    • [ ] GDPR / CCPA / state privacy laws
    • [ ] SOX 404
    • [ ] FedRAMP / StateRAMP
    • [ ] Banking (OCC, FDIC, FRB, FFIEC)
    • [ ] Healthcare (CMS, FDA)
    • [ ] NERC CIP (energy)
    • [ ] None / early-stage startup
  • ERM framework in use (or adopting):
    • [ ] ISO 31000
    • [ ] COSO ERM (2017 Framework)
    • [ ] NIST RMF / CSF 2.0
    • [ ] FAIR (quantitative)
    • [ ] No formal framework yet

1.2 Scope of This Matrix

  • Risk domain being assessed:
    • [ ] Enterprise-wide (top-down strategic risks)
    • [ ] Operational risk (processes, people, systems)
    • [ ] Information security / cyber risk
    • [ ] Financial / treasury risk
    • [ ] Compliance / regulatory risk
    • [ ] Project / program risk
    • [ ] Vendor / third-party risk

Get the full skill

Unlock Risk Assessment Matrix and 600+ other skills

Get Access — $8/month

More from business-operations

View all →
business operations

All Hands Script

Generate a complete, presentation-ready all-hands meeting script with CEO talking points, department updates, Q&A facilitation guide, and audience engagement tactics. Use this skill when preparing a company town hall, quarterly all-hands, annual kickoff, or any large-scale internal meeting where leadership addresses the full organization. Produces a timed run-of-show, speaker scripts with stage directions, slide cue notes, and post-meeting follow-up communications. Covers both virtual (Zoom/Teams/Meet) and in-person auditorium formats for companies from 50 to 10,000+ employees.

business operations

Board Deck Structure

Generate a complete, investor-ready board meeting deck with 15-20 slide templates, financial summaries, strategic initiative updates, and risk register. Use this skill when preparing for a quarterly board meeting, annual board review, special board session, or investor update. Produces structured slide-by-slide content with speaker notes, data visualization guidance, and appendix materials following Sequoia and Bessemer best practices. Covers seed-stage through public company board reporting with GAAP/non-GAAP presentation standards, SaaS metrics frameworks, and governance compliance requirements.

business operations

Budget Proposal

Generate a complete, approval-ready budget proposal with line-item detail, ROI justification, headcount planning, and executive summary. Use this skill when building a department budget request, annual operating budget, project budget, or capital expenditure proposal. Produces structured budget templates with variance analysis, zero-based justification frameworks, and stakeholder-ready presentation materials. Covers everything from a $50K marketing campaign budget to a $50M annual operating plan, with specific templates for headcount, software, professional services, and capital expenditures across SaaS, manufacturing, professional services, and nonprofit organizations.

The Library

Unlock this skill +
600 more.

Subscribe for $8/month. Paste any of 600+ structured playbooks into Claude. Cancel anytime.