Likelihood Assessment
A likelihood assessment estimates how probable it is that a given risk event will actually occur. It is one of the two core dimensions of risk evaluation, the other being impact, which measures how severe the consequences would be if the event happened. Together, likelihood and impact are typically combined to help prioritize which risks warrant the most attention.
Likelihood assessment is the component of a risk assessment that evaluates the probability that a specified risk event or effect will occur, expressed either qualitatively or, where sufficient data exists, quantitatively. In many programs it is scored on an ordinal scale (for example a five-level scale ranging from very low to very high) and paired with a separately assessed impact rating within a risk matrix to derive an overall risk level. It is important to distinguish likelihood from impact: likelihood addresses how probable an event is, not how damaging it would be. Qualitative likelihood assessments are frequently based on expert judgment and opinion rather than empirical frequency data, which introduces subjectivity and makes consistent scale definitions and calibration important; results can also become stale as conditions change. In third-party and supply chain contexts, likelihood assessment informs risk tiering and prioritization but does not by itself quantify exposure, verify controls, or account for the severity of consequences, all of which require complementary analysis.
Why it matters
Likelihood assessment gives risk, procurement, and compliance teams a structured way to separate risks that are merely conceivable from those that are genuinely probable. Without an explicit likelihood dimension, programs tend to treat every plausible failure scenario as equally pressing, which dilutes attention and resources. By pairing likelihood with a separately assessed impact rating, teams can prioritize the risks that combine high probability with serious consequences, which is the foundation of risk tiering across a third-party or supply chain portfolio.
The practical value of a likelihood assessment depends heavily on how honestly its limitations are recognized. Qualitative likelihood ratings are frequently based on expert judgment and opinion rather than empirical frequency data, which introduces subjectivity and makes consistent scale definitions and calibration important. Two assessors can rate the same event very differently unless the scale levels are defined clearly and applied uniformly. Ratings can also become stale as conditions change, so a likelihood score captured at onboarding may no longer reflect a supplier's current exposure without periodic reassessment.
It is also important not to overload likelihood with work it cannot do. Likelihood addresses how probable an event is, not how damaging it would be, and by itself it does not quantify financial exposure, verify that controls are in place, or account for the severity of consequences. Treating a low likelihood score as a substitute for these complementary analyses can leave high-impact, low-probability dependencies dangerously under-managed.
Who it's relevant to
Inside Likelihood Assessment
Common questions
Answers to the questions practitioners most commonly ask about Likelihood Assessment.
