Skip to main content
Category: Assessment and Due Diligence

Likelihood Assessment

Also known as: Probability Assessment, Likelihood Rating, Likelihood Estimation
Simply put

A likelihood assessment estimates how probable it is that a given risk event will actually occur. It is one of the two core dimensions of risk evaluation, the other being impact, which measures how severe the consequences would be if the event happened. Together, likelihood and impact are typically combined to help prioritize which risks warrant the most attention.

Formal definition

Likelihood assessment is the component of a risk assessment that evaluates the probability that a specified risk event or effect will occur, expressed either qualitatively or, where sufficient data exists, quantitatively. In many programs it is scored on an ordinal scale (for example a five-level scale ranging from very low to very high) and paired with a separately assessed impact rating within a risk matrix to derive an overall risk level. It is important to distinguish likelihood from impact: likelihood addresses how probable an event is, not how damaging it would be. Qualitative likelihood assessments are frequently based on expert judgment and opinion rather than empirical frequency data, which introduces subjectivity and makes consistent scale definitions and calibration important; results can also become stale as conditions change. In third-party and supply chain contexts, likelihood assessment informs risk tiering and prioritization but does not by itself quantify exposure, verify controls, or account for the severity of consequences, all of which require complementary analysis.

Why it matters

Likelihood assessment gives risk, procurement, and compliance teams a structured way to separate risks that are merely conceivable from those that are genuinely probable. Without an explicit likelihood dimension, programs tend to treat every plausible failure scenario as equally pressing, which dilutes attention and resources. By pairing likelihood with a separately assessed impact rating, teams can prioritize the risks that combine high probability with serious consequences, which is the foundation of risk tiering across a third-party or supply chain portfolio.

The practical value of a likelihood assessment depends heavily on how honestly its limitations are recognized. Qualitative likelihood ratings are frequently based on expert judgment and opinion rather than empirical frequency data, which introduces subjectivity and makes consistent scale definitions and calibration important. Two assessors can rate the same event very differently unless the scale levels are defined clearly and applied uniformly. Ratings can also become stale as conditions change, so a likelihood score captured at onboarding may no longer reflect a supplier's current exposure without periodic reassessment.

It is also important not to overload likelihood with work it cannot do. Likelihood addresses how probable an event is, not how damaging it would be, and by itself it does not quantify financial exposure, verify that controls are in place, or account for the severity of consequences. Treating a low likelihood score as a substitute for these complementary analyses can leave high-impact, low-probability dependencies dangerously under-managed.

Who it's relevant to

Third-party risk managers
Use likelihood assessment as one of the two core inputs, alongside impact, to tier suppliers and allocate assessment and monitoring effort. They should define consistent likelihood scales and schedule reassessments, since qualitative ratings can become stale as conditions change.
Procurement and vendor onboarding teams
Apply likelihood ratings during onboarding to help prioritize which relationships need more scrutiny, while recognizing that a likelihood score reflects probability alone and does not verify controls or quantify potential exposure.
Compliance and risk governance functions
Rely on documented likelihood scales and calibration practices to demonstrate a defensible, repeatable basis for risk prioritization, and to make clear where ratings depend on expert judgment rather than empirical frequency data.
Business continuity and resilience planners
Consult likelihood assessments to distinguish probable disruptions from rare but severe scenarios, understanding that a low likelihood rating does not diminish the need to plan for high-impact events that fall outside what likelihood alone captures.

Inside Likelihood Assessment

Threat or Event Identification
The set of adverse events being evaluated for their probability of occurrence, such as a supplier's financial failure, a data breach at a service provider, a service outage, or a geopolitical disruption. Likelihood assessment scores the probability of these defined events, not their consequences, which fall under impact assessment.
Probability Estimation Basis
The evidence and inputs used to estimate how likely an event is, which may include historical incident data, threat intelligence, financial indicators, questionnaire responses, or expert judgment. In many programs these inputs are partly qualitative and self-reported, which constrains the reliability of the resulting estimate.
Scoring or Rating Scale
The scale used to express likelihood, whether qualitative (for example, rare, possible, likely) or quantitative (for example, a percentage or frequency over a defined period). The scale's meaning depends on the time horizon and definitions adopted by the program, so scores are typically not comparable across differing methodologies.
Time Horizon
The defined window over which the probability is assessed, since an event's likelihood over one year differs from its likelihood over a longer period. Likelihood estimates are generally point-in-time and can become stale as a third party's circumstances or the threat environment change.
Relationship to Inherent and Residual Risk
Likelihood can be assessed before controls are applied (contributing to inherent risk) or after controls are considered (contributing to residual risk). Distinguishing which is being measured is essential, as conflating the two misrepresents the risk position.

Common questions

Answers to the questions practitioners most commonly ask about Likelihood Assessment.

Is likelihood assessment the same as measuring the probability of a specific incident occurring?
No. Likelihood assessment estimates the relative chance that a risk event materializes over a defined period, but in most third-party risk programs it does not produce a precise statistical probability. Data on external suppliers is often incomplete, self-reported, or point-in-time, so likelihood is typically expressed on qualitative or ordinal scales (for example, low/medium/high or a 1-5 rating) rather than as a calculated numeric probability. Treating an ordinal rating as a true probability overstates the precision the underlying inputs can support.
Does a high likelihood rating mean the third party poses a high overall risk?
Not by itself. Likelihood is only one component of risk; it must be combined with impact (the consequence or severity if the event occurs) to characterize risk. A high-likelihood event with negligible impact may rank lower than a low-likelihood event with severe impact. Likelihood assessment also typically informs inherent risk before controls are considered, and does not on its own reflect residual risk after mitigations. Conflating a likelihood score with an overall risk conclusion skips the impact and control dimensions.
What inputs typically feed a likelihood assessment for a third party?
Depending on the risk domain and tier, inputs may include due diligence findings, questionnaire responses, external threat intelligence, historical incident or performance data, geographic and geopolitical factors, financial indicators, and the nature and criticality of the service provided. Because many of these sources are self-reported or point-in-time, programs often weight or corroborate them differently, and note where independent validation is absent.
How often should likelihood ratings be refreshed?
Because likelihood can shift as conditions change, a point-in-time rating can become stale. Many programs refresh ratings on a cadence tied to the risk tier, more frequently for critical or higher-risk relationships, and also on a trigger basis when events such as an incident, ownership change, or adverse news occur. The appropriate frequency depends on the volatility of the underlying risk and available monitoring data rather than a single universal interval.
Should the same likelihood scale be applied across all risk domains?
Not necessarily. Likelihood drivers differ by domain, information security, financial, operational, geopolitical, and ESG risks each have distinct indicators. Using a single generic scale can obscure these differences. Many programs define domain-specific criteria or anchor descriptions for each rating level so that assessors apply consistent, comparable judgments within a domain, while recognizing that scores across domains are not always directly interchangeable.
How can programs reduce subjectivity in likelihood ratings?
Subjectivity is a known limitation of qualitative likelihood scales. Programs can improve consistency by defining explicit criteria or descriptors for each rating level, documenting the rationale and evidence behind a rating, involving more than one assessor or a review step for higher-tier relationships, and corroborating self-reported inputs with independent sources where feasible. These measures reduce but do not eliminate the judgment inherent in likelihood assessment.

Common misconceptions

Likelihood assessment measures how bad an event would be for the organization.
Likelihood assessment estimates the probability that an event occurs; the severity of its consequences is addressed separately through impact assessment. Risk is typically derived by combining the two, and neither substitutes for the other.
A likelihood score based on a supplier questionnaire reflects an independently verified probability.
Many likelihood inputs are self-reported and reflect a point-in-time snapshot. Unless corroborated through independent verification or monitoring, such scores carry the limitations of unvalidated attestation and can become outdated as conditions change.
A likelihood rating applies uniformly across all risk domains for a given third party.
Likelihood is generally domain-specific. The probability of an information security incident differs from that of financial distress, an operational outage, or a geopolitical disruption, and a single blended score can obscure these distinct probabilities.

Best practices

State explicitly whether a likelihood estimate reflects inherent risk (before controls) or residual risk (after controls), and avoid mixing the two within the same score.
Define the time horizon and the meaning of each point on the likelihood scale so that ratings are interpretable and, where possible, comparable within your program.
Assess likelihood separately by risk domain (for example, information security, financial, operational, geopolitical, ESG) rather than assigning a single blended probability to a third party.
Corroborate self-reported inputs with independent evidence or ongoing monitoring where the risk tier warrants it, and record which inputs are unvalidated attestations.
Refresh likelihood estimates on a cadence tied to risk tier, recognizing that point-in-time assessments can become stale as the third party or the threat environment changes.
Combine likelihood with a separate impact assessment to derive risk, and document the assumptions and evidence behind each probability estimate to support review and challenge.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.