A transportation risk matrix is the systematic cross of probability (P) and impact (I) for events that can break a shipment: theft, cargo damage or loss, vehicle failure, people accidents, and environmental events (spills). The product P×I decides where to invest controls before the problem reaches AP, the customer, or insurance.
In Mexico 2026, running without a matrix is flying blind: cargo theft remains the risk most cited in sector reports and ANTP coverage, fatigue under Hours of Service raises accident probability, and documentation (including Carta Porte) is both compliance and post-incident control. This guide gives you the structure, a working example, and the cycle to keep it alive.
What is a transportation risk matrix?
Operating definition for shippers and 3PLs: a list of trip risks (by lane, mode, or network) with owner, P×I score, heat level, active controls, and monitoring evidence. It is not a “security policy” PDF. It is the decision queue for which risk to close this week.
It differs from a simple anti-theft checklist: the matrix forces you to compare theft vs mechanical failure vs spill under the same rule, so you do not spend the whole budget on escorts while ignoring maintenance or fatigue.
If your OTIF drops and you cannot tell security from capacity from dock delay, the matrix forces cause separation.
Without a matrix
- Priority = last incident or loudest chat
- Generic controls (“add GPS”) with no owner or KPI
- Yearly review or never; lanes change, the spreadsheet does not
With a P×I matrix
- Priority = documented, reviewable score
- Every risk has a control, evidence, and owner
- Short cycle: monitor and review after incidents or new lanes
How to score P×I (1–5 scale)
Use a written scale. Without criteria, two coordinators invent two matrices. Usable Mexico example (tune numbers to your internal data):
1
Probability (P): Rare in 12 months; stable lane, clean history
Impact (I): Minor delay; no cargo loss or injury
2
Probability (P): Occasional; 1–2 events/year on similar network
Impact (I): Accessorial cost / minor documented claim
3
Probability (P): Possible each quarter on the lane or fleet
Impact (I): Partial loss, broken OTIF, or insurance hit
4
Probability (P): Frequent on known corridors/hotspots
Impact (I): High material loss or injury; long dispute
5
Probability (P): Very likely without reinforced control
Impact (I): Total loss, fatality, or severe environmental harm
Score = P × I (range 1–25 on a 5×5 scale). Absolute values matter less than consistency across lanes and month-to-month comparability.
Heat map: Extreme, High, Medium, Low
Extreme
P×I range: 20–25
Typical action: Immediate control, named owner, weekly review, possible do-not-operate on the lane
High
P×I range: 12–19
Typical action: 30-day mitigation plan, weekly KPIs, control budget
Medium
P×I range: 6–11
Typical action: Standard controls + monitoring; improve in quarterly backlog
Low
P×I range: 1–5
Typical action: Conscious residual acceptance; revisit if context changes
Mexico example matrix: 5 categories
Illustrative example for a shipper/3PL with domestic high-value lanes and a carrier mix.
Scores are not an official ranking: they mirror the pattern in operations that already measure theft, warranties, and claims. Use it as a template, not a verdict on your network.
Security
Theft / assault
Cargo
Damage / loss
Vehicle
Mechanical failure
People
Accidents / fatigue
Environmental
Spills / leaks
Security
Primary risk: Cargo theft on hotspot corridor
P: 5
I: 5
P×I: 25
Level: Extreme
Cargo
Primary risk: Damage from poor stow / missing POD
P: 4
I: 4
P×I: 16
Level: High
People
Primary risk: Fatigue-driven accident (HOS)
P: 3
I: 5
P×I: 15
Level: High
Vehicle
Primary risk: Breakdown en route (maintenance)
P: 3
I: 4
P×I: 12
Level: High
Environmental
Primary risk: Spill / leak of regulated product
P: 2
I: 4
P×I: 8
Level: Medium
On public figures: exact theft volumes vary by source and year.
What stays stable in 2024–2026 industry discourse and in our cargo security guide is that theft concentrates attention and material loss, and that GPS + protocol + safer lanes are the minimum package.
Do not invent a viral number for your committee: cite the month’s source (SESNSP, ANTP, insurer) or stay qualitative plus your internal history.
Controls and recommendations by category
1. Security (theft)
Controls:
- GPS with geofencing and deviation alerts
- Transit windows (avoid overnight stays in hotspots)
- Escort or convoy when value justifies it
- Seals and dock verification
- Emergency protocol (who calls whom in the first minutes)
- Carriers with a security scorecard
Mexico recommendation: treat monitoring as 24/7 operations, not an app someone opens the next morning. Track without actionable alerts is theater.
Pair the matrix with the security guide and with GPS in transport governed from the TMS / control tower.
2. Cargo (damage / loss)
Controls:
- Stow instructions
- Load/unload photos
- Structured POD (not just an “ok” in chat)
- Proper packaging
- Cargo insurance aligned to real value
- Remittance vs delivered cross-check
Recommendation: if status only lives in WhatsApp logistics, the claim is born lost.
Require timestamped evidence; the WhatsApp script helps adoption, but the system of record must be the shipment file.
3. Vehicle (failure)
Controls:
- Preventive maintenance
- Pre-trip checklist
- Fleet age
- Backup unit plan on critical lanes
- Sensors/telematics when the product requires it
Recommendation: put “breakdown en route” on the carrier scorecard. Cheap freight that fails every other week is High risk dressed as savings.
4. People (accidents)
Controls:
- Hours and rest limits (Hours of Service)
- Realistic appointments
- Routes that do not force clock-racing
- Defensive driving training
- Alcohol/drug testing per policy and applicable law
Recommendation: fatigue is not fixed with a cab sticker. If commercial promises assume impossible transit times, you are manufacturing high P in People and Cargo at once.
5. Environmental (spills)
Controls:
- Correct dangerous-goods classification when applicable
- Containment kits
- Response training
- Routes and permits
- Documentation and authority notification per material
Recommendation: even when P is Medium on general networks, I can be extreme (fines, remediation, reputation). Do not average hazmat risk with dry retail pallets.
Carta Porte and CFDI as control (not superstition): a correct Carta Porte reduces regulatory risk (SAT fines) and speeds traceability in claims. It does not replace GPS or escort; it completes the file with POD and GPS logs.
A matrix without a cycle is decoration
Identify, assess, control, monitor, and review: the short, repeatable process is what separates ops that cut claims from ops that only “have a risk spreadsheet.”
Identify
List risks by lane/mode: theft, damage, failure, accident, spill, plus cargo-specific ones (cold chain, high value, hazmat). Sources: internal incidents, insurer, industry reports, driver feedback.
Assess
Assign P and I with the written scale. Compute P×I and heat level. Do not negotiate the score so it “looks fine” for leadership: the committee needs operating truth.
Control
For Extreme/High: owner, concrete control, date, and budget. Write “how we know it works” (KPI): % units with live GPS, time-to-alert, % POD with photo, HOS compliance, etc.
Monitor
Tower / track & trace with actionable alerts. Cross operational exceptions against the shipment file. If the notice arrives at 10 a.m. next day, you are not monitoring: you are archiving.
Review
After a material incident, a new lane, or each quarter: Did P fall? Did I rise with cargo value? Was the control adopted or skipped? Update the matrix and close findings.
Mexico 2026 context: what raises the score
- Theft on known corridors. State of Mexico, Puebla, Veracruz, and segments of El Bajío recur in industry security analyses. Combine sector and ANTP dashboards with your history; do not copy a generic internet map.
- Tight insurance and capacity. In the cost frame we describe in the 2026 transport squeeze, a claim does not only lose goods: it strains the policy and the carrier relationship.
- Fatigue and transit promises. Without Hours of Service governance, People risk rises quietly while sales sells an impossible SLA.
- Chat-only operations. When status lives only in WhatsApp, there is no monitoring or post-event audit. The matrix asks for evidence; chat does not produce it alone.
OCL fits the Monitor phase (and evidence for Review): track & trace and audit agents keep visibility and a shipment file (GPS, POD, Carta Porte) so matrix controls do not die in a PDF.
They do not replace your P×I analysis; they stop it from depending on group-chat memory. To report progress to leadership, pair this matrix with security KPIs, KRIs, and AI.
7-day checklist to build your matrix
- 1
Days 1–2: risk inventory
Five base categories + lanes in the top 20% of spend or cargo value.
- 2
Day 3: freeze P and I scale
One page, signed by Ops and Insurance/Compliance. No scale, no matrix.
- 3
Day 4: scoring workshop
Ops + Security + AP + one key carrier. Document assumptions, not only the number.
- 4
Day 5: Extreme/High controls
Owner, date, KPI. If everything is Extreme, you are over-scoring: recalibrate I.
- 5
Day 6: wire monitoring
GPS alerts, geofence, POD with evidence, HOS in appointments. Pilot one lane.
- 6
Day 7: review ritual
Quarterly calendar + post-incident trigger. Publish the matrix where Ops actually looks.
Does your matrix exist… or only the exception chat?
In a demo we walk through how track, alerts, and the shipment file (GPS / POD / Carta Porte) sustain Monitor to Review on your real lanes.
Book a demoSources and further reading
Key takeaways5 points
- A transportation risk matrix prioritizes with a P×I score (probability × impact), not Slack/WhatsApp intuition.
- In Mexico, Security (theft) often lands Extreme/High: GPS, geofencing, protocols, and safer lanes cut real exposure.
- Five minimum categories: Security, Cargo, Vehicle, People, Environmental; each with owner, control, and KPI.
- Identify, Assess, and Control, Monitor, and Review turns the matrix into a system, not a yearly spreadsheet.
- Visibility, track, and audit with evidence (POD/Carta Porte/GPS) close the gap between written control and live ops.
Frequently asked questions
A tool that crosses probability (P) and impact (I) for events that break freight outcomes (theft, cargo damage/loss, vehicle failure, accidents, spills) so you prioritize controls. The P×I score places each risk on a heat map: Extreme, High, Medium, or Low.
Assign probability and impact on a written 1–5 scale for your operation, then multiply. Example: theft on a high-risk corridor with P=5 and I=5 scores 25 (Extreme). Document the scale so two analysts reach the same score.
High probability on high-risk corridors plus high impact (lost goods, insurance, OTIF, reputation). Controls are not escort-only: live GPS, geofencing, emergency protocol, and cross-checked documentation reduce exposure. See the cargo security guide.
Yes, under People (accidents) and often reinforcing Vehicle and Cargo. Fatigue raises crash, damage, and delay probability. Governing driver hours and realistic appointments lowers your team-risk score.
Yes as documentary and traceability control: goods, origin/destination, operator, and insurance sit in the file. It does not stop theft by itself, but it speeds claims, SAT compliance, and post-incident audit. An incoherent CFDI/Carta Porte is a separate regulatory risk.
After a material incident, when you open a new lane, or at least quarterly. The cycle is Identify, Assess, and Control, Monitor, and Review. If you build it once a year, corridors and carriers already moved.
Near-real-time visibility and track, exception alerts, and a shipment file (GPS, POD, Carta Porte) so Monitor and Review do not depend on WhatsApp alone. The matrix sets priorities; evidence keeps controls alive.
