Sheet MER-20 — Audit & Compliance Manual
Risk Heatmap
Concentration of exposure, prioritization signals, and the visual model teams use to discuss risk with leadership.
Scope
Heatmaps only help when they drive prioritization instead of becoming a decorative board artifact. This guide keeps the public-safe operating interpretation and excludes private rendering or export detail.
Audience: System operators, IT administrators, L1/L2 support staff Last Updated: 2026-07-09
Overview
The Risk Heat Map visualizes a program’s risks on a 5x5 grid with likelihood on the Y-axis and impact on the X-axis. Each cell is color-coded by risk level (low, medium, high, critical) and shows the count of risks in that position. A sidebar lists the top 10 highest-scoring risks. You can toggle between inherent and residual risk views.
Getting Started
Prerequisites
Meridian.viewpermission.- At least one risk in the program’s risk register.
Using the Heat Map
Viewing the Heat Map
Steps:
- Navigate to a program’s Risk Register page.
- Click the Heat Map link (or navigate directly to the relevant workflow).
Result: A 5x5 grid appears with risks placed by their likelihood (rows) and impact (columns). Each cell shows:
- The risk count in that cell.
- Color coding: green (low), yellow (medium), red (high), dark red (critical).
- Click a cell to see the list of risks at that position.
Toggling Inherent vs. Residual View
Steps:
- Use the Inherent / Residual toggle at the top of the page.
Result:
- Inherent: Shows risks positioned by their raw likelihood and impact scores.
- Residual: Shows risks that have an effective residual score. Manual-mode risks are positioned by residual likelihood and residual impact. Computed-mode risks still contribute to the residual top-risk ranking, but they are reported separately as unpositioned because computed residual is a scalar score and does not provide grid coordinates.
Drilling Into a Cell
Steps:
- Click any cell in the grid.
Result: A panel shows the risks in that cell with their ID, reference, title, and score. Each risk links to the risk detail page.
Top Risks Sidebar
The sidebar lists the top 10 risks by score (descending). In inherent view, this uses inherent scores. In residual view, this uses the effective residual score:
- Manual mode:
residual_score - Computed mode:
computed_residual_score
If a computed-mode residual risk has a score but no manual residual likelihood/impact, it still appears in the top-risk ranking and in the page warning/list, but not in a heat-map cell.
Understanding the Grid
The grid is 5x5:
- Y-axis (rows): Likelihood, from 1 (bottom) to 5 (top).
- X-axis (columns): Impact, from 1 (left) to 5 (right).
- Score: Likelihood x Impact. Ranges from 1 to 25.
- Risk Level: Derived from the score. Color-coded on the grid.
| Score Range | Level | Color |
|---|---|---|
| Low | low | Green |
| Medium | medium | Yellow |
| High | high | Red |
| Critical | critical | Dark red |
Permissions Reference
| Permission | Grants |
|---|---|
Meridian.view |
View the heat map for any accessible program |