Editorial Governance and Strategy
Publishing Risk Tier Matrix
Classify planned content by factual, legal, privacy, safety, brand, and user-harm exposure so review effort and approval authority match the consequences.
Free editable Markdown · Editorial leaders, compliance teams, and risk owners ·
Accessible HTML preview
Blank template
The downloaded file contains the same fields in editable Markdown.
Assessment context
- Content title
- [Working title]
- Owner
- [Accountable editor]
- Format and channel
- [Where and how it will appear]
- Intended audience
- [Include vulnerable or restricted groups]
- Expected reach
- [Internal, limited, public, or estimated scale]
- Decision supported
- [What may a reader do because of it?]
- Assessment date
- [YYYY-MM-DD]
- Assessor
- [Name and role]
Risk factors
- Factual consequence
- [Low / Moderate / High / Critical, with reason]
- Safety or wellbeing
- [Rating and reason]
- Legal or regulatory
- [Rating and required owner]
- Privacy or confidentiality
- [Rating and data involved]
- Reputation or fairness
- [Rating and affected people]
- Security or misuse
- [Rating and misuse scenario]
- Audience vulnerability
- [Rating and reason]
- Reversibility
- [Easy correction / Persistent effect / Irreversible]
- Uncertainty
- [What is not yet known?]
Automatic gates
- Triggered minimum tier
- [Tier or None]
- Includes unnecessary or unapproved personal information.
- Could materially affect health, safety, legal, financial, or civic decisions.
- Makes a consequential claim about an identifiable person or organization.
- Reveals confidential, restricted, or security-sensitive details.
- Provides instructions that could be repurposed for harmful activity.
- Uses evidence whose authenticity or context is unresolved.
Tier and required controls
- Assigned tier
- [Tier 1 / Tier 2 / Tier 3 / Tier 4]
- Evidence requirement
- [Sources and verification depth]
- Required reviewers
- [Editorial and specialist roles]
- Approval authority
- [Named role]
- Distribution control
- [Public, limited, delayed, or restricted]
- Monitoring plan
- [Feedback, correction, or removal owner]
- Reassessment trigger
- [Claim, audience, source, channel, or context change]
- Residual risk accepted by
- [Authorized decision maker]
How to use this template
- Agree on material risk factors, automatic escalation gates, and concrete examples relevant to the publication.
- Define three or four tiers with observable descriptions rather than relying on an unexplained numeric total.
- Attach required evidence, reviewers, approval authority, distribution controls, and monitoring to each tier.
- Classify a planned item using documented facts, then have the designated owner confirm any gated or high-risk result.
- Reassess after material content changes and use incidents or false alarms to improve the matrix at its scheduled review.
Define risk as consequence and exposure
Risk is not the same as controversy or editing difficulty. Assess what could happen if the content is wrong, misunderstood, disclosed improperly, manipulated, or used outside its intended context. Consider the severity of harm, how many people may encounter it, the vulnerability of the audience, and whether the effect can be reversed. A typo in an internal event recap differs from an incorrect dosage, financial deadline, security procedure, or allegation. Record the evidence for each factor instead of assigning a number from instinct. Where uncertainty is material, classify conservatively until a qualified owner resolves it.
Use gates as well as scores
Simple totals can hide a catastrophic factor among several low ones. Define automatic gates for cases such as personal data, instructions with physical safety consequences, claims about identifiable people, regulated advice, confidential material, or unverified breaking information. A gate sets the minimum tier and required reviewer regardless of the total. For remaining work, use a small descriptive scale with observable anchors. Avoid pretending that “3” means the same thing across privacy and brand impact. The matrix should make reasoning consistent enough to route work, not manufacture scientific precision.
Connect every tier to controls
A tier has value only when it changes the workflow. Specify evidence requirements, independence of review, approval authority, test or preview needs, access restrictions, correction monitoring, and review times for each level. Ensure the organization can actually supply those controls; a mandatory reviewer with no capacity creates pressure to misclassify work. Reassess when the headline, claims, audience, distribution, source quality, or publication context changes. After incidents and near misses, compare the initial classification with the observed problem and update factor definitions without rewriting the historic record.
See the fields in context
Fictional example: storm shelter directions
Fairhaven Council and its storm notice are invented for this workbook.
- Planned content: A public map and directions to temporary storm shelters.
- Gate: Incorrect instructions could affect physical safety, so the item enters the highest local review tier regardless of its short length.
- Controls: Emergency coordinator confirms locations; accessibility lead checks route information; editor timestamps the notice and links the official alert.
- Distribution: Public only after approvals, with an owner monitoring changes throughout the event.
- Reassessment: Any shelter closure or transport change requires immediate reclassification and republication.
Frequently asked questions
Does high risk mean the content should not be published?
Not automatically. It means the consequences require stronger evidence, qualified review, explicit authority, and monitoring. Some content is both high risk and essential. The matrix helps the team distinguish responsible publication from an avoidable shortcut.
Should risk tiers be calculated with a formula?
A formula can support consistency, but automatic gates and written reasoning remain important. Do not average away one severe issue. Test any scoring rule against past examples and allow an authorized reviewer to raise, never casually lower, a tier.
Can AI detection determine a risk tier?
No. A detector score does not establish factual accuracy, authorship, privacy, or harm. Assess the content, sources, audience, and intended use. If AI assisted the work, document that workflow and apply human review suited to the actual consequences.
Who can lower a classification?
Name the role in advance. A reduction should cite new evidence or a changed scope, retain the earlier assessment, and confirm that no mandatory gate still applies. The content owner should not lower a tier merely to meet a deadline.