Scoring Model
Two-Axis Evaluation Grid
Every legal risk is measured across two independent axes:
Impact Magnitude (consequences if the risk becomes reality):
| Rating |
Descriptor |
Meaning |
| 1 |
Trivial |
Minimal disruption; no meaningful financial, operational, or reputational consequence. Absorbed within day-to-day operations. |
| 2 |
Minor |
Contained impact; financial exposure under 1% of the relevant contract or transaction value; brief operational hiccup; no public visibility. |
| 3 |
Substantial |
Tangible impact; financial exposure in the 1-5% range of relevant value; noticeable operational interference; possibility of limited external attention. |
| 4 |
Serious |
Major impact; financial exposure between 5-25% of relevant value; significant operational disruption; probable public scrutiny; potential for regulatory interest. |
| 5 |
Severe |
Existential-level impact; financial exposure exceeding 25% of relevant value; core business operations threatened; material reputational harm; regulatory action anticipated; potential personal exposure for directors and officers. |
Occurrence Probability (how likely the risk is to materialize):
| Rating |
Descriptor |
Meaning |
| 1 |
Negligible |
Essentially theoretical; no known precedent in comparable situations; would demand extraordinary circumstances. |
| 2 |
Low |
Conceivable but not anticipated; sparse precedent; requires specific precipitating events. |
| 3 |
Moderate |
Plausible; some analogous situations have materialized; precipitating conditions are foreseeable. |
| 4 |
Elevated |
Expected to happen; clear precedent exists; precipitating conditions are commonplace in analogous contexts. |
| 5 |
Near Certain |
Virtually guaranteed; strong historical pattern; precipitating conditions are already present or imminent. |
Computing the Score
Risk Score = Impact Magnitude x Occurrence Probability
| Score Band |
Category |
Indicator |
| 1-4 |
Baseline Risk |
GREEN |
| 5-9 |
Intermediate Risk |
YELLOW |
| 10-15 |
Elevated Risk |
ORANGE |
| 16-25 |
Acute Risk |
RED |
Visual Grid
OCCURRENCE PROBABILITY
Negligible Low Moderate Elevated Near Certain
(1) (2) (3) (4) (5)
IMPACT
Severe (5) | 5 | 10 | 15 | 20 | 25 |
Serious (4) | 4 | 8 | 12 | 16 | 20 |
Substantial(3)| 3 | 6 | 9 | 12 | 15 |
Minor (2) | 2 | 4 | 6 | 8 | 10 |
Trivial (1) | 1 | 2 | 3 | 4 | 5 |
Category Profiles and Response Protocols
GREEN -- Baseline Risk (Score 1-4)
Profile:
- Low-consequence issues with negligible probability
- Routine operational risks with well-established controls already in place
- Familiar risk patterns that the organization regularly manages
Protocol:
- Accept: Proceed with existing controls in place
- Log: Enter into the risk register for ongoing visibility
- Periodic check: Revisit during quarterly or annual review cycles
- No escalation: The responsible team member manages independently
Typical scenarios:
- Vendor agreement with a small deviation from preferred terms in a non-material area
- Standard confidentiality agreement with a reputable counterparty in a familiar jurisdiction
- Routine administrative compliance task with a clear owner and deadline
YELLOW -- Intermediate Risk (Score 5-9)
Profile:
- Issues of moderate consequence that could arise under realistic conditions
- Risks deserving active attention without requiring emergency response
- Situations where precedent provides a management roadmap
Protocol:
- Reduce exposure: Deploy targeted controls or negotiate improved terms
- Active surveillance: Review monthly or upon occurrence of defined trigger events
- Thorough documentation: Capture the risk, all mitigation steps, and decision rationale in the register
- Designated owner: A specific individual holds accountability for tracking and mitigation
- Stakeholder communication: Relevant business contacts are informed of the risk and the mitigation approach
- Escalation triggers: Define specific conditions that would push this risk to a higher category
Typical scenarios:
- Agreement with a liability ceiling below the preferred level but within a negotiable range
- Vendor processing personal data in a territory with uncertain adequacy status
- Regulatory development that may affect a business line over the medium term
- IP provision that is broader than optimal but consistent with market practice
ORANGE -- Elevated Risk (Score 10-15)
Profile:
- Weighty issues with a realistic chance of materializing
- Risks capable of producing significant financial, operational, or public-facing harm
- Situations demanding senior-level attention and structured mitigation
Protocol:
- Senior counsel involvement: Brief the head of legal or designated senior attorney
- Structured mitigation plan: Build a concrete, time-bound plan to reduce the risk
- Leadership awareness: Ensure relevant business leaders understand the risk and the recommended path
- Frequent review: Weekly check-ins or milestone-based reassessment
- External counsel assessment: Engage outside specialists for domain-specific guidance as warranted
- Detailed written analysis: Produce a full risk memorandum covering analysis, alternatives, and recommendations
- Contingency planning: Define the response playbook if the risk materializes
Typical scenarios:
- Agreement containing uncapped indemnification in a material obligation area
- Data processing operation that may violate regulatory requirements without restructuring
- Credible litigation threat from a significant counterparty
- Intellectual property infringement allegation with a plausible basis
- Formal regulatory inquiry or audit notification
RED -- Acute Risk (Score 16-25)
Profile:
- The most consequential issues, with high or near-certain probability of materializing
- Risks that threaten fundamental business viability, expose officers and directors, or endanger key stakeholders
- Demands immediate executive engagement and rapid mobilization
Protocol:
- Immediate executive briefing: Notify General Counsel, C-suite, and Board as the situation warrants
- Outside counsel retention: Engage specialized external lawyers without delay
- Dedicated response team: Stand up a cross-functional team with clearly defined roles and authority
- Insurance notification: Alert carriers where coverage may apply
- Crisis protocols: Activate crisis management procedures when reputational exposure exists
- Evidence preservation: Institute a litigation hold if legal proceedings are a possibility
- Continuous monitoring: Daily or more frequent status reviews until resolved or downgraded
- Board-level reporting: Include in governance risk reporting as appropriate
- Regulatory communication: File any mandatory regulatory notifications
Typical scenarios:
- Pending litigation with substantial financial exposure
- Personal data breach affecting regulated information
- Active regulatory enforcement proceeding
- Material breach of or against the organization under a significant contract
- Government investigation
- Infringement claim targeting a core product or revenue-generating service
Formal Documentation Standards
Risk Assessment Memorandum
Every formal evaluation should follow this structure:
## Legal Risk Evaluation
**Prepared**: [date]
**Analyst**: [name of person conducting the evaluation]
**Subject**: [description of the matter under review]
**Privilege designation**: [Yes/No -- mark as attorney-client privileged where applicable]
### 1. Risk Statement
[Precise, concise articulation of the legal risk]
### 2. Factual Background
[Relevant facts, chronology, and business context]
### 3. Scoring Analysis
#### Impact Magnitude: [1-5] - [Descriptor]
[Supporting rationale including potential financial exposure, operational consequences, and reputational dimensions]
#### Occurrence Probability: [1-5] - [Descriptor]
[Supporting rationale including precedent, triggering conditions, and current circumstances]
#### Composite Score: [Number] - [GREEN/YELLOW/ORANGE/RED]
### 4. Aggravating Factors
[Elements that amplify the risk]
### 5. Countervailing Factors
[Elements that dampen the risk or contain exposure]
### 6. Mitigation Alternatives
| Alternative | Effectiveness | Resource Demand | Recommended? |
|---|---|---|---|
| [Option A] | [High/Med/Low] | [High/Med/Low] | [Yes/No] |
| [Option B] | [High/Med/Low] | [High/Med/Low] | [Yes/No] |
### 7. Recommended Course of Action
[Specific recommendation with supporting rationale]
### 8. Post-Mitigation Risk Level
[Projected risk category after implementing recommended measures]
### 9. Ongoing Monitoring Plan
[Frequency and method of review; conditions that would trigger reassessment]
### 10. Immediate Next Steps
1. [Task - Responsible party - Due date]
2. [Task - Responsible party - Due date]
Risk Register Format
For entry into the team's centralized risk tracker:
| Field |
Content |
| Identifier |
Unique tracking code |
| Discovery Date |
When the risk first came to light |
| Summary |
Brief characterization |
| Domain |
Contract / Regulatory / Litigation / IP / Data Privacy / Employment / Corporate / Other |
| Impact Rating |
1-5 with descriptor |
| Probability Rating |
1-5 with descriptor |
| Composite Score |
Calculated value |
| Category |
GREEN / YELLOW / ORANGE / RED |
| Accountable Person |
Individual responsible for monitoring |
| Active Controls |
Mitigations currently deployed |
| Disposition |
Open / Mitigated / Accepted / Closed |
| Next Review |
Scheduled reassessment date |
| Remarks |
Supplementary context |
Criteria for Engaging Outside Counsel
Situations Requiring External Representation
- Filed litigation: Any lawsuit brought by or against the organization
- Government proceedings: Any inquiry from a regulatory agency, government body, or law enforcement
- Criminal risk: Any scenario involving potential criminal liability for the entity or its people
- Capital markets implications: Any matter that could affect securities disclosures or regulatory filings
- Governance-level matters: Any issue necessitating board notification or board-level approval
Situations Strongly Favoring External Engagement
- Uncharted legal territory: Questions lacking settled authority where the organization's position could establish precedent
- Multi-jurisdictional complexity: Matters spanning unfamiliar or conflicting legal regimes
- Outsized financial stakes: Exposure exceeding the organization's defined risk appetite thresholds
- Specialist knowledge gaps: Subject areas not covered by in-house expertise (antitrust, anti-corruption, patent prosecution, etc.)
- Major regulatory shifts: New legal frameworks that require compliance program construction or significant adaptation
- Strategic transactions: Mergers, acquisitions, or major deals requiring diligence, structuring, and regulatory clearance
Situations Worth Evaluating for External Support
- Significant contractual disputes: Substantial disagreements over interpretation with important business partners
- Workforce claims: Actual or threatened claims involving discrimination, harassment, wrongful termination, or retaliation
- Data security events: Incidents that may trigger mandatory notification duties
- IP conflicts: Infringement allegations (inbound or outbound) involving material products or services
- Coverage disagreements: Disputes with insurance carriers over claim coverage
Selecting the Right Firm
When recommending outside engagement, prompt the user to weigh:
- Subject matter depth and track record
- Familiarity with the relevant jurisdiction
- Industry sector experience
- Conflict clearance status
- Fee structure expectations (hourly, flat, blended, contingency)
- Firm diversity commitments
- Pre-existing relationships (panel membership, prior engagements)
1---2name: legal-risk-scoring3description: Score legal risks by severity and likelihood, assign ratings, and document escalation paths.4---5
6## Scoring Model
7
8### Two-Axis Evaluation Grid
9
10Every legal risk is measured across two independent axes:
11
12**Impact Magnitude** (consequences if the risk becomes reality):
13
14| Rating | Descriptor | Meaning |
15|---|---|---|
16| 1 | **Trivial** | Minimal disruption; no meaningful financial, operational, or reputational consequence. Absorbed within day-to-day operations. |
17| 2 | **Minor** | Contained impact; financial exposure under 1% of the relevant contract or transaction value; brief operational hiccup; no public visibility. |
18| 3 | **Substantial** | Tangible impact; financial exposure in the 1-5% range of relevant value; noticeable operational interference; possibility of limited external attention. |
19| 4 | **Serious** | Major impact; financial exposure between 5-25% of relevant value; significant operational disruption; probable public scrutiny; potential for regulatory interest. |
20| 5 | **Severe** | Existential-level impact; financial exposure exceeding 25% of relevant value; core business operations threatened; material reputational harm; regulatory action anticipated; potential personal exposure for directors and officers. |
21
22**Occurrence Probability** (how likely the risk is to materialize):
23
24| Rating | Descriptor | Meaning |
25|---|---|---|
26| 1 | **Negligible** | Essentially theoretical; no known precedent in comparable situations; would demand extraordinary circumstances. |
27| 2 | **Low** | Conceivable but not anticipated; sparse precedent; requires specific precipitating events. |
28| 3 | **Moderate** | Plausible; some analogous situations have materialized; precipitating conditions are foreseeable. |
29| 4 | **Elevated** | Expected to happen; clear precedent exists; precipitating conditions are commonplace in analogous contexts. |
30| 5 | **Near Certain** | Virtually guaranteed; strong historical pattern; precipitating conditions are already present or imminent. |
31
32### Computing the Score
33
34**Risk Score = Impact Magnitude x Occurrence Probability**
35
36| Score Band | Category | Indicator |
37|---|---|---|
38| 1-4 | **Baseline Risk** | GREEN |
39| 5-9 | **Intermediate Risk** | YELLOW |
40| 10-15 | **Elevated Risk** | ORANGE |
41| 16-25 | **Acute Risk** | RED |
42
43### Visual Grid
44
45```
46 OCCURRENCE PROBABILITY
47 Negligible Low Moderate Elevated Near Certain
48 (1) (2) (3) (4) (5)
49IMPACT
50Severe (5) | 5 | 10 | 15 | 20 | 25 |
51Serious (4) | 4 | 8 | 12 | 16 | 20 |
52Substantial(3)| 3 | 6 | 9 | 12 | 15 |
53Minor (2) | 2 | 4 | 6 | 8 | 10 |
54Trivial (1) | 1 | 2 | 3 | 4 | 5 |
55```
56
57## Category Profiles and Response Protocols
58
59### GREEN -- Baseline Risk (Score 1-4)
60
61**Profile**:
62- Low-consequence issues with negligible probability
63- Routine operational risks with well-established controls already in place
64- Familiar risk patterns that the organization regularly manages
65
66**Protocol**:
67- **Accept**: Proceed with existing controls in place
68- **Log**: Enter into the risk register for ongoing visibility
69- **Periodic check**: Revisit during quarterly or annual review cycles
70- **No escalation**: The responsible team member manages independently
71
72**Typical scenarios**:
73- Vendor agreement with a small deviation from preferred terms in a non-material area
74- Standard confidentiality agreement with a reputable counterparty in a familiar jurisdiction
75- Routine administrative compliance task with a clear owner and deadline
76
77### YELLOW -- Intermediate Risk (Score 5-9)
78
79**Profile**:
80- Issues of moderate consequence that could arise under realistic conditions
81- Risks deserving active attention without requiring emergency response
82- Situations where precedent provides a management roadmap
83
84**Protocol**:
85- **Reduce exposure**: Deploy targeted controls or negotiate improved terms
86- **Active surveillance**: Review monthly or upon occurrence of defined trigger events
87- **Thorough documentation**: Capture the risk, all mitigation steps, and decision rationale in the register
88- **Designated owner**: A specific individual holds accountability for tracking and mitigation
89- **Stakeholder communication**: Relevant business contacts are informed of the risk and the mitigation approach
90- **Escalation triggers**: Define specific conditions that would push this risk to a higher category
91
92**Typical scenarios**:
93- Agreement with a liability ceiling below the preferred level but within a negotiable range
94- Vendor processing personal data in a territory with uncertain adequacy status
95- Regulatory development that may affect a business line over the medium term
96- IP provision that is broader than optimal but consistent with market practice
97
98### ORANGE -- Elevated Risk (Score 10-15)
99
100**Profile**:
101- Weighty issues with a realistic chance of materializing
102- Risks capable of producing significant financial, operational, or public-facing harm
103- Situations demanding senior-level attention and structured mitigation
104
105**Protocol**:
106- **Senior counsel involvement**: Brief the head of legal or designated senior attorney
107- **Structured mitigation plan**: Build a concrete, time-bound plan to reduce the risk
108- **Leadership awareness**: Ensure relevant business leaders understand the risk and the recommended path
109- **Frequent review**: Weekly check-ins or milestone-based reassessment
110- **External counsel assessment**: Engage outside specialists for domain-specific guidance as warranted
111- **Detailed written analysis**: Produce a full risk memorandum covering analysis, alternatives, and recommendations
112- **Contingency planning**: Define the response playbook if the risk materializes
113
114**Typical scenarios**:
115- Agreement containing uncapped indemnification in a material obligation area
116- Data processing operation that may violate regulatory requirements without restructuring
117- Credible litigation threat from a significant counterparty
118- Intellectual property infringement allegation with a plausible basis
119- Formal regulatory inquiry or audit notification
120
121### RED -- Acute Risk (Score 16-25)
122
123**Profile**:
124- The most consequential issues, with high or near-certain probability of materializing
125- Risks that threaten fundamental business viability, expose officers and directors, or endanger key stakeholders
126- Demands immediate executive engagement and rapid mobilization
127
128**Protocol**:
129- **Immediate executive briefing**: Notify General Counsel, C-suite, and Board as the situation warrants
130- **Outside counsel retention**: Engage specialized external lawyers without delay
131- **Dedicated response team**: Stand up a cross-functional team with clearly defined roles and authority
132- **Insurance notification**: Alert carriers where coverage may apply
133- **Crisis protocols**: Activate crisis management procedures when reputational exposure exists
134- **Evidence preservation**: Institute a litigation hold if legal proceedings are a possibility
135- **Continuous monitoring**: Daily or more frequent status reviews until resolved or downgraded
136- **Board-level reporting**: Include in governance risk reporting as appropriate
137- **Regulatory communication**: File any mandatory regulatory notifications
138
139**Typical scenarios**:
140- Pending litigation with substantial financial exposure
141- Personal data breach affecting regulated information
142- Active regulatory enforcement proceeding
143- Material breach of or against the organization under a significant contract
144- Government investigation
145- Infringement claim targeting a core product or revenue-generating service
146
147## Formal Documentation Standards
148
149### Risk Assessment Memorandum
150
151Every formal evaluation should follow this structure:
152
153```
154
155## Legal Risk Evaluation
156
157**Prepared**: [date]
158**Analyst**: [name of person conducting the evaluation]
159**Subject**: [description of the matter under review]
160**Privilege designation**: [Yes/No -- mark as attorney-client privileged where applicable]
161
162### 1. Risk Statement
163[Precise, concise articulation of the legal risk]
164
165### 2. Factual Background
166[Relevant facts, chronology, and business context]
167
168### 3. Scoring Analysis
169
170#### Impact Magnitude: [1-5] - [Descriptor]
171[Supporting rationale including potential financial exposure, operational consequences, and reputational dimensions]
172
173#### Occurrence Probability: [1-5] - [Descriptor]
174[Supporting rationale including precedent, triggering conditions, and current circumstances]
175
176#### Composite Score: [Number] - [GREEN/YELLOW/ORANGE/RED]
177
178### 4. Aggravating Factors
179[Elements that amplify the risk]
180
181### 5. Countervailing Factors
182[Elements that dampen the risk or contain exposure]
183
184### 6. Mitigation Alternatives
185
186| Alternative | Effectiveness | Resource Demand | Recommended? |
187|---|---|---|---|
188| [Option A] | [High/Med/Low] | [High/Med/Low] | [Yes/No] |
189| [Option B] | [High/Med/Low] | [High/Med/Low] | [Yes/No] |
190
191### 7. Recommended Course of Action
192[Specific recommendation with supporting rationale]
193
194### 8. Post-Mitigation Risk Level
195[Projected risk category after implementing recommended measures]
196
197### 9. Ongoing Monitoring Plan
198[Frequency and method of review; conditions that would trigger reassessment]
199
200### 10. Immediate Next Steps
2011. [Task - Responsible party - Due date]
2022. [Task - Responsible party - Due date]
203```
204
205### Risk Register Format
206
207For entry into the team's centralized risk tracker:
208
209| Field | Content |
210|---|---|
211| Identifier | Unique tracking code |
212| Discovery Date | When the risk first came to light |
213| Summary | Brief characterization |
214| Domain | Contract / Regulatory / Litigation / IP / Data Privacy / Employment / Corporate / Other |
215| Impact Rating | 1-5 with descriptor |
216| Probability Rating | 1-5 with descriptor |
217| Composite Score | Calculated value |
218| Category | GREEN / YELLOW / ORANGE / RED |
219| Accountable Person | Individual responsible for monitoring |
220| Active Controls | Mitigations currently deployed |
221| Disposition | Open / Mitigated / Accepted / Closed |
222| Next Review | Scheduled reassessment date |
223| Remarks | Supplementary context |
224
225## Criteria for Engaging Outside Counsel
226
227### Situations Requiring External Representation
228
229- **Filed litigation**: Any lawsuit brought by or against the organization
230- **Government proceedings**: Any inquiry from a regulatory agency, government body, or law enforcement
231- **Criminal risk**: Any scenario involving potential criminal liability for the entity or its people
232- **Capital markets implications**: Any matter that could affect securities disclosures or regulatory filings
233- **Governance-level matters**: Any issue necessitating board notification or board-level approval
234
235### Situations Strongly Favoring External Engagement
236
237- **Uncharted legal territory**: Questions lacking settled authority where the organization's position could establish precedent
238- **Multi-jurisdictional complexity**: Matters spanning unfamiliar or conflicting legal regimes
239- **Outsized financial stakes**: Exposure exceeding the organization's defined risk appetite thresholds
240- **Specialist knowledge gaps**: Subject areas not covered by in-house expertise (antitrust, anti-corruption, patent prosecution, etc.)
241- **Major regulatory shifts**: New legal frameworks that require compliance program construction or significant adaptation
242- **Strategic transactions**: Mergers, acquisitions, or major deals requiring diligence, structuring, and regulatory clearance
243
244### Situations Worth Evaluating for External Support
245
246- **Significant contractual disputes**: Substantial disagreements over interpretation with important business partners
247- **Workforce claims**: Actual or threatened claims involving discrimination, harassment, wrongful termination, or retaliation
248- **Data security events**: Incidents that may trigger mandatory notification duties
249- **IP conflicts**: Infringement allegations (inbound or outbound) involving material products or services
250- **Coverage disagreements**: Disputes with insurance carriers over claim coverage
251
252### Selecting the Right Firm
253
254When recommending outside engagement, prompt the user to weigh:
255- Subject matter depth and track record
256- Familiarity with the relevant jurisdiction
257- Industry sector experience
258- Conflict clearance status
259- Fee structure expectations (hourly, flat, blended, contingency)
260- Firm diversity commitments
261- Pre-existing relationships (panel membership, prior engagements)