# Publishing Risk Tier Matrix

Classify planned content by factual, legal, privacy, safety, brand, and user-harm exposure so review effort and approval authority match the consequences.

## Usage note

Configure this matrix with qualified editorial, privacy, legal, safety, security, and subject-matter owners before applying it. It is a triage tool, not professional advice or permission to publish. A low score never overrides a mandatory rule, and one severe factor should be able to raise the tier without being averaged away.

## How to use this template

1. Agree on material risk factors, automatic escalation gates, and concrete examples relevant to the publication.
2. Define three or four tiers with observable descriptions rather than relying on an unexplained numeric total.
3. Attach required evidence, reviewers, approval authority, distribution controls, and monitoring to each tier.
4. Classify a planned item using documented facts, then have the designated owner confirm any gated or high-risk result.
5. Reassess after material content changes and use incidents or false alarms to improve the matrix at its scheduled review.

## Blank template

### Assessment context

- **Content title:** [Working title]
- **Owner:** [Accountable editor]
- **Format and channel:** [Where and how it will appear]
- **Intended audience:** [Include vulnerable or restricted groups]
- **Expected reach:** [Internal, limited, public, or estimated scale]
- **Decision supported:** [What may a reader do because of it?]
- **Assessment date:** [YYYY-MM-DD]
- **Assessor:** [Name and role]

### Risk factors

- **Factual consequence:** [Low / Moderate / High / Critical, with reason]
- **Safety or wellbeing:** [Rating and reason]
- **Legal or regulatory:** [Rating and required owner]
- **Privacy or confidentiality:** [Rating and data involved]
- **Reputation or fairness:** [Rating and affected people]
- **Security or misuse:** [Rating and misuse scenario]
- **Audience vulnerability:** [Rating and reason]
- **Reversibility:** [Easy correction / Persistent effect / Irreversible]
- **Uncertainty:** [What is not yet known?]

### Automatic gates

- [ ] Includes unnecessary or unapproved personal information.
- [ ] Could materially affect health, safety, legal, financial, or civic decisions.
- [ ] Makes a consequential claim about an identifiable person or organization.
- [ ] Reveals confidential, restricted, or security-sensitive details.
- [ ] Provides instructions that could be repurposed for harmful activity.
- [ ] Uses evidence whose authenticity or context is unresolved.
- **Triggered minimum tier:** [Tier or None]

### Tier and required controls

- **Assigned tier:** [Tier 1 / Tier 2 / Tier 3 / Tier 4]
- **Evidence requirement:** [Sources and verification depth]
- **Required reviewers:** [Editorial and specialist roles]
- **Approval authority:** [Named role]
- **Distribution control:** [Public, limited, delayed, or restricted]
- **Monitoring plan:** [Feedback, correction, or removal owner]
- **Reassessment trigger:** [Claim, audience, source, channel, or context change]
- **Residual risk accepted by:** [Authorized decision maker]
