6 Myths About Risk Matrices That Plant Managers Still Believe
A risk matrix is a decision aid, not a substitute for field evidence, control ownership, or leadership judgment. These six myths explain why a neat risk score can still leave a plant exposed.

Key takeaways
- 01A risk matrix organizes a decision, but it does not measure exposure by itself.
- 02A low score can be misleading when consequence severity, exposure assumptions, or control reliability are weak.
- 03A high score should trigger a decision about controls and authority, not only a request for another signature.
- 04Residual risk is credible only when the stated controls exist, work as intended, and have an owner.
- 05Plant managers improve risk decisions when they test assumptions at the point of work and define escalation thresholds.
- 06The best matrix is the one that changes an operational decision before people inherit an unmanaged exposure.
A risk matrix can help a plant manager compare hazards and choose a proportionate response, but it cannot turn incomplete evidence into a safe decision. The score is only as credible as the consequence definition, exposure assumption, control verification, and authority behind it.
That distinction matters because a matrix produces a number at the moment when leaders want clarity. A red square appears to demand action, while a green square seems to permit routine work. Both reactions can be wrong when the score hides a fragile assumption.
In Safety Culture: From Theory to Practice, Andreza Araujo connects safety maturity with the choices leaders make visible in everyday operations. A risk matrix becomes useful only when it changes what the organization accepts, verifies, escalates, and owns.
Why risk-matrix myths cost plants more than they expect
Risk matrices are attractive because they create a common language for hazards that otherwise feel difficult to compare. ISO 31000:2018 supports structured risk criteria, context, and treatment, yet it does not give a plant permission to treat a score as a measurement of reality.
The danger starts when the tool becomes more authoritative than the evidence behind it. A team may debate whether a task is a six or an eight while nobody confirms whether isolation holds, whether the rescue route is usable, or whether the contractor can execute the control under actual conditions.
The six myths below survive because each one contains a partial truth. Plant managers need the full decision, not the convenient half.
Myth 1: The matrix measures risk objectively
A matrix organizes judgment. It does not observe the hazard, calculate exposure, or verify that a barrier is available. Those tasks depend on the quality of the information that enters the assessment.
Two teams can use the same grid and reach different results because they describe exposure differently. One team may assess a planned task with trained workers and stable conditions. Another may be assessing the same equipment during a rushed breakdown with missing supervision and restricted access.
The matrix makes the difference visible only when the context is written clearly. Otherwise, the score gives subjective assumptions the appearance of precision.
Plant managers should ask what observation, record, or field test supports each major input. If the answer is only that the team has always used that rating, the number is a habit, not evidence.
Myth 2: Green means safe
A green result usually means the assessed condition falls within a defined tolerance. It does not mean that harm is impossible or that the controls deserve no further attention.
The color can also conceal an exposure that the assessment did not include. A lifting task may have acceptable conditions for the load but unacceptable conditions for nearby pedestrians, changing weather, or a worker who has not received the required briefing.
Green becomes dangerous when it ends the conversation. The team stops asking what could change, who owns the control, and what signal would move the task into a different decision state.
Use the green result as a starting point for control verification. The practical question is whether the conditions that produced the rating are still present at the point of work.
Myth 3: Red means stop, so no other decision is needed
A high score should prompt a strong response, but the color alone does not define who must act or what must change. Without a decision rule, red becomes a dramatic label attached to an unresolved problem.
The plant may stop the task, add a temporary measure, redesign the method, or escalate the decision to a leader with control over staffing, engineering, procurement, or production priorities. Those actions are not interchangeable, and each requires a different owner.
A stop that has no restart condition can create pressure to resume work through informal approval. The score remains red on paper while the real decision moves into a hallway conversation.
Define the response beside the criterion. State the authority, the required evidence, the control standard, and the condition that allows work to restart.
Myth 4: The highest score always deserves the most attention
Prioritization is necessary, but a ranking can mislead when consequence, frequency, exposure duration, and control dependency are represented poorly. The largest score is not automatically the most urgent operational problem.
A lower-rated task may occur hundreds of times under changing conditions, while a higher-rated task may be rare and tightly controlled. Another task may have a moderate score but depend on one barrier whose failure would create a severe outcome.
This is why plant managers should distinguish the score from the decision priority. The priority must reflect what can change, how quickly the exposure can worsen, and whether the organization has reliable control over the conditions.
Review the top risks with a second question. Which exposure can move outside its assumptions before the next management meeting?
Myth 5: Residual risk is whatever remains after controls are listed
Listing controls does not prove that the risk has been reduced. A control becomes part of residual-risk reasoning only when the organization knows who owns it, how it operates, and how its reliability will be checked.
A procedure may exist while the required equipment is unavailable. A permit may be signed while the isolation is not independently verified. A training record may be complete while the worker has never practiced the critical response under realistic conditions.
These gaps do not mean the controls have no value. They mean the assessment must not treat intended protection as dependable protection.
Before accepting residual risk, ask what evidence would show that the control is working today. Then name the person who will respond if the evidence is absent or the condition changes.
Myth 6: Updating the matrix is the same as improving the decision
Changing a rating can correct an assessment, but it does not necessarily change the exposure. A revised number without a revised work method, resource decision, escalation path, or verification routine is administrative movement.
This myth is common after an incident, audit finding, or management review. The organization updates the likelihood description, adds a control to the template, and reports that the risk register is current. The field may look exactly as it did before.
James Reason’s work on latent failures helps explain why this response is incomplete. The visible error is often connected to decisions about design, planning, supervision, maintenance, and priorities. A better score does not remove those conditions.
Close the loop by asking what will be different at the point of work. If the answer cannot be observed, the matrix has been edited, not the risk.
What plant managers should do now
Start with one high-consequence activity whose matrix rating is widely trusted. Read the assumptions aloud with a supervisor, an operator, and the person who owns the critical control. Gaps usually appear when the same word means different things to each role.
- Separate the score from the evidence that supports it.
- Write the decision authority and escalation threshold next to each critical criterion.
- Verify the most important control where the work occurs, not only in the risk register.
- Define the restart condition whenever a task is stopped or a temporary control is used.
- Review whether the assessment changed the work, the resource allocation, or the ownership of the exposure.
A matrix is valuable when it helps people make a better decision before exposure becomes harm. It is a weak substitute for leadership when its colors settle the discussion while the operating conditions remain untested.
For a broader approach to diagnosing the habits behind risk decisions, explore Andreza Araujo’s safety culture resources.
Frequently asked questions
What is the main purpose of a risk matrix?
Can a low risk score still represent a serious safety concern?
Should a high risk score always stop the work?
What makes residual risk credible?
How should plant managers improve risk-matrix decisions?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.