Skip to main content
The state of ai impact assessment
Category: Risk Assessment & Analysis

Likelihood and Consequence

Also known as: Consequence and Likelihood, Likelihood and Impact, Probability and Impact
Simply put

Likelihood and consequence are the two basic factors used to judge how serious a risk is. Likelihood describes how probable it is that a harmful event will happen, while consequence describes how bad the outcome would be if it did. Combining the two helps decision-makers rank risks and decide which ones need the most attention.

Formal definition

In many risk assessment methodologies, likelihood and consequence are the paired dimensions used to characterize and rate a risk. Likelihood refers to the chance or probability that a specified risk event will occur, often expressed through qualitative descriptors (for example, almost certain, likely, possible) or quantitative measures. Consequence refers to the effect or outcome of that event on objectives, typically graded by severity. These two dimensions are commonly plotted on a consequence/likelihood matrix (also called a risk matrix), a widely used technique that defines a level of risk by mapping a likelihood category against a consequence category. Practitioners should note that likelihood/consequence ratings are estimates whose reliability depends on the quality of underlying data and judgment, and that the specific scales, descriptors, and matrix design vary by framework and organization. Matrix-based rating does not itself treat or eliminate risk; it supports prioritization and reporting.

Why it matters

Likelihood and consequence together form the conceptual foundation of most risk assessment methodologies. Without a structured way to weigh how probable an event is against how damaging it would be, organizations struggle to compare risks that differ in nature, for example, a frequent but minor operational disruption against a rare but potentially catastrophic one. Pairing these two dimensions gives decision-makers a common language for prioritization, so that limited time, attention, and resources can be directed toward the risks that matter most rather than distributed evenly across every identified concern.

The consequence/likelihood matrix that operationalizes these factors is one of the most widely used risk analysis and reporting techniques, and it is frequently built into risk and safety management software. Its popularity stems from its accessibility: stakeholders across governance, risk, and compliance functions can understand a colored grid more readily than a statistical model. This same accessibility, however, carries a limitation practitioners should keep in mind. Ratings are estimates, and their reliability depends heavily on the quality of the underlying data and the judgment of those doing the rating. A well-presented matrix can lend an unwarranted sense of precision to what are, in many cases, informed approximations.

It is also important to recognize what likelihood and consequence rating does not do. Mapping a risk on a matrix supports prioritization and reporting, but it does not by itself treat, reduce, or eliminate the risk. The scales, descriptors, and matrix design vary across frameworks and organizations, so a rating produced under one scheme may not be directly comparable to one produced under another. Treating the matrix as the end of the risk process, rather than an input to decisions about controls and treatment, is a common pitfall.

Who it's relevant to

Risk managers
Risk managers use likelihood and consequence as the core dimensions for characterizing, rating, and reporting risks. The consequence/likelihood matrix gives them a consistent method to compare disparate risks and to communicate priorities to decision-makers, while remaining mindful that ratings are estimates dependent on data quality and judgment.
Governance and decision-makers
Boards, executives, and other decision-makers rely on likelihood and consequence ratings to understand where attention and resources should be focused. The matrix supports their prioritization decisions, but they should recognize it does not itself treat or eliminate risk and that its output reflects the assumptions built into the chosen scales.
Compliance and safety personnel
Those managing compliance and operational or safety risks apply likelihood and consequence to assess hazardous events, often within risk and safety management software that incorporates the matrix technique. Descriptors such as "almost certain," "likely," and "possible" help them frame how probable an event is against how severe its outcome would be.
Internal auditors
Internal auditors examining risk assessment processes should understand how likelihood and consequence ratings are derived, since the reliability of a risk matrix depends on the underlying data and judgment. Auditors can evaluate whether matrix design, scales, and descriptors are applied consistently and whether ratings appropriately inform treatment decisions rather than substituting for them.

Inside Likelihood and Consequence

Likelihood
The chance that a given risk event will occur, often expressed qualitatively (e.g., rare, possible, likely), semi-quantitatively (rating scales), or quantitatively (probabilities or frequencies over a defined time horizon). In many risk frameworks, likelihood is one of two primary dimensions used to characterize a risk.
Consequence
The effect or impact on objectives should the risk event occur, which may be positive or negative and can span financial, operational, reputational, regulatory, safety, or other categories. Consequence is typically assessed against defined criteria or severity scales relevant to the organization's objectives.
Risk criteria
The reference terms of reference against which the significance of a risk is evaluated, including the scales, thresholds, and definitions used to rate likelihood and consequence consistently across an organization. These criteria are typically set in line with an organization's objectives, context, and appetite.
Time horizon
The period over which likelihood is estimated, since the probability of an event often depends on the window considered. Making the horizon explicit helps ensure ratings are comparable across risks.
Combined assessment (risk level)
The result of considering likelihood together with consequence, often visualized on a risk matrix or heat map, to derive an overall level of risk that supports prioritization and treatment decisions. The method of combination varies by framework and should be defined in advance.
Inherent vs. residual perspective
Likelihood and consequence may be assessed before controls (inherent) or after accounting for existing controls (residual). Distinguishing which perspective is being rated is important, since controls are intended to modify likelihood, consequence, or both.

Common questions

Answers to the questions practitioners most commonly ask about Likelihood and Consequence.

Does a high likelihood rating mean a risk is more important than one with a lower likelihood?
Not necessarily. Likelihood is only one dimension of a risk assessment; consequence (the severity of the effect on objectives) is the other. A risk with lower likelihood but severe consequence may warrant greater attention than a frequent but low-impact event. Most frameworks combine the two dimensions, often through a risk matrix or scoring approach, rather than prioritizing on likelihood alone. How the two are weighted is typically an organizational judgment reflecting risk appetite and context.
Are likelihood and probability the same thing?
They are related but not always interchangeable. In many frameworks, including ISO 31000, likelihood is used as a broad term for the chance of something happening, whether described qualitatively or quantitatively, precisely because reliable statistical probability data is often unavailable. Probability more strictly implies a mathematically derived measure. Using 'likelihood' signals that an estimate may be based on judgment, expert input, or qualitative scales rather than a calculated frequency. Organizations should be clear about which they mean and avoid implying statistical precision that the underlying data does not support.
How should we define the scales we use to rate likelihood and consequence?
Scales are typically defined by the organization to suit its context, and both qualitative (for example, rare to almost certain) and quantitative (for example, frequency ranges or monetary bands) approaches are common. Leading practice generally favors describing each scale point with clear, consistent criteria so that different assessors interpret ratings similarly. Consequence scales are often split by category, such as financial, operational, reputational, or safety, since a single event may affect objectives differently across dimensions. The choice of scale should be documented and applied consistently to support comparability.
Should likelihood and consequence be assessed on an inherent or residual basis?
This depends on the organization's methodology, and many frameworks support assessing both. Inherent assessment considers the risk before accounting for controls, while residual assessment reflects the risk after existing controls are applied. Some organizations assess inherent risk to understand exposure and the value controls provide, then focus decision-making on residual risk. It is important to state explicitly which basis a given rating reflects, since combining inherent and residual assessments inconsistently can distort comparisons and prioritization.
How can we make likelihood and consequence ratings more consistent across assessors?
Consistency is commonly supported by well-defined scale descriptors, calibration discussions among assessors, worked examples, and documented rationale for each rating. Involving people with relevant expertise and, where available, drawing on historical data or loss records can reduce individual bias. Some organizations use facilitated workshops or peer review to challenge estimates. Because these assessments often rest on judgment, transparency about the assumptions and evidence behind a rating is generally more valuable than an appearance of precision.
How do likelihood and consequence ratings feed into risk prioritization and treatment decisions?
The two dimensions are typically combined, often via a risk matrix, heat map, or scoring formula, to produce an overall risk level that supports prioritization. Risks may then be compared against risk appetite and tolerance to determine whether treatment is required. It is worth noting that combining qualitative ratings arithmetically can introduce distortions, so the resulting scores are generally treated as an aid to judgment rather than a definitive ranking. Treatment decisions usually also weigh factors such as cost, feasibility, and interdependencies that a likelihood-consequence score alone does not capture.

Common misconceptions

A high likelihood rating always means a high-priority risk.
Likelihood is only one dimension. A frequent event with negligible consequence may rank lower than a rare event with severe consequence. Prioritization in many frameworks depends on the combination of both dimensions against defined risk criteria, not likelihood alone.
Likelihood and consequence ratings are objective, precise measurements.
Ratings are typically estimates shaped by available data, assumptions, and judgment, and are only as reliable as the criteria and inputs behind them. Qualitative scales in particular can vary in interpretation between assessors, which is why consistent, documented criteria are important.
The likelihood and consequence assessed are fixed once controls are applied.
Assessments reflect a point in time and a stated perspective (inherent or residual). Because context, threats, and control effectiveness change, ratings can shift and generally warrant periodic reassessment rather than being treated as static.

Best practices

Define clear, documented criteria and scales for both likelihood and consequence before assessing risks, so ratings are applied consistently across the organization.
State the time horizon used for likelihood explicitly to keep estimates comparable across different risks.
Specify whether each assessment reflects an inherent or residual perspective, and note the controls assumed when rating residual risk.
Use both dimensions together, rather than likelihood or consequence in isolation, to derive an overall risk level and support prioritization.
Draw on relevant data, historical experience, and informed judgment where quantitative data is limited, and document the assumptions behind each rating.
Reassess likelihood and consequence periodically and when context, threats, or control effectiveness change, treating ratings as point-in-time estimates rather than permanent.
Promotional banner for the Pentest Readiness checklist download