Skip to main content
Category: Risk Analysis and Quantification

Frequency

Simply put

In risk management, frequency refers to how often a particular event or loss is expected to occur over a given period. It is one of the two basic dimensions used to describe risk, the other being the impact or severity of the event. Estimating frequency helps organizations understand how likely they are to face a given risk within a defined timeframe.

Formal definition

Frequency denotes the number of times a defined event, loss, or occurrence takes place per unit of time or per unit of exposure. In risk assessment it is commonly paired with severity (magnitude of consequence) to characterize a risk, and it may be expressed qualitatively (for example, rare, occasional, frequent) or quantitatively (for example, expected events per year). Frequency is conceptually related to, but not identical with, likelihood or probability: frequency typically describes an expected rate of recurrence over time or exposure, whereas probability expresses the chance of occurrence, often for a single event or interval. The appropriate measurement basis, time horizon, and exposure unit vary by framework, sector, and the nature of the risk being assessed. This entry does not cover specific quantification methodologies, tooling, or the general (non-GRC) scientific meanings of frequency.

Why it matters

Frequency is one of the two foundational dimensions used to characterize risk, working alongside impact or severity to give organizations a structured way to understand the risks they face. Without an estimate of how often an event is expected to occur, an assessment of severity alone gives an incomplete picture: a catastrophic event that is highly unlikely and a minor event that recurs constantly may warrant very different treatment. Pairing frequency with severity allows risk managers to prioritize attention and resources toward the risks that matter most over a defined timeframe.

Because frequency describes an expected rate of recurrence over time or exposure, it directly informs how organizations plan for and respond to recurring exposures. Estimating how likely a risk is to materialize within a given period supports decisions about which controls to strengthen, which risks to accept, and how to allocate limited resources. The appropriate measurement basis, time horizon, and exposure unit differ by framework, sector, and the nature of the risk, so frequency estimates should be interpreted in light of the context and assumptions underlying them.

Frequency is conceptually related to, but not identical with, likelihood or probability, and conflating the two can distort a risk assessment. Frequency typically expresses an expected rate of recurrence over time or exposure, whereas probability expresses the chance of occurrence, often for a single event or interval. Keeping this distinction clear helps ensure that risk descriptions and any downstream calculations rest on a consistent basis.

Who it's relevant to

Risk Managers
Risk managers use frequency alongside severity to characterize and prioritize risks, deciding how often a defined event or loss is expected to occur within a given timeframe and what treatment is warranted. Selecting an appropriate measurement basis, time horizon, and exposure unit is central to producing consistent and defensible risk assessments.
Internal Auditors
When evaluating the design and operation of an organization's risk assessment processes, auditors may examine whether frequency has been estimated on a sound and consistent basis and whether it has been kept distinct from probability. This supports an objective assessment of how reliably risks have been characterized, without engaging in the management activity of setting the estimates themselves.
Governance and Board-Level Stakeholders
Those responsible for oversight rely on frequency, combined with severity, to understand how likely the organization is to face particular risks over a defined period. Clear frequency estimates help inform decisions about resource allocation and risk prioritization, provided the underlying assumptions and time horizons are made transparent.

Inside Frequency

Likelihood dimension of risk
Frequency expresses how often a risk event is expected to occur over a defined period, forming one of the two principal dimensions of risk assessment alongside impact or consequence. It answers the question of how often rather than how severe.
Reference period
A frequency estimate is meaningful only against a stated time horizon, such as per year, per transaction, or per operating cycle. Without an explicit period, a frequency value cannot be interpreted or compared consistently.
Qualitative frequency scales
Many frameworks use descriptive bands such as rare, unlikely, possible, likely, and almost certain, mapped to broad occurrence ranges. These scales support judgement-based assessment where precise data is unavailable, and the band definitions typically vary by organization and framework.
Quantitative frequency measures
Where sufficient data exists, frequency may be expressed numerically, for example as an expected number of events per period or an annualized rate. The reliability of such measures depends on the quality and relevance of the underlying historical or modeled data.
Relationship to probability
Frequency and probability are related but distinct: frequency counts occurrences over a period, whereas probability expresses the chance of an event within a defined exposure. The two are commonly conflated but should be defined explicitly in an assessment methodology.

Common questions

Answers to the questions practitioners most commonly ask about Frequency.

Does a higher frequency rating mean an event will definitely occur more often?
No. Frequency in risk assessment expresses how often an event is expected or estimated to occur over a defined period, typically as a likelihood measure rather than a guarantee. A higher frequency rating reflects a greater estimated rate of occurrence, but it remains an assessment of probability over time, not a certainty. Actual outcomes may differ from the estimate, and frequency ratings should be treated as informed judgments subject to uncertainty and periodic review.
Is frequency the same as impact or severity when scoring a risk?
No. Frequency and impact are distinct dimensions of risk assessment and should not be conflated. Frequency addresses how often an event is expected to occur, while impact (or severity) addresses the magnitude of consequences if it does occur. Many risk methodologies combine the two dimensions to derive a risk rating, but they are assessed separately. Treating a frequent, low-consequence event the same as a rare, high-consequence event would obscure meaningful differences relevant to prioritization and treatment.
How is frequency typically expressed on a risk assessment scale?
Frequency is commonly expressed using a defined scale that may be qualitative (for example, rare, occasional, frequent), semi-quantitative (banded ranges of occurrences per period), or quantitative (an estimated number of events over a stated time horizon). The scale and its definitions vary by organization, framework, and risk domain. To support consistent application, the categories are usually documented with clear thresholds and a stated time period so that assessors interpret them the same way.
What time period should be used when estimating frequency?
The time period should be defined explicitly and suited to the risk being assessed, because a frequency estimate is meaningless without a stated reference interval. Some organizations standardize on an annual basis for comparability across a risk register, while others select intervals appropriate to the process cycle or exposure. The key practice is to state the period consistently within a given assessment context so that ratings remain comparable.
What sources of information can inform a frequency estimate?
Frequency estimates may draw on historical incident and loss data, near-miss records, industry or peer data where available, expert judgment, and the outputs of control performance monitoring. The reliability of the estimate depends on the quality and relevance of the underlying data. Where data is sparse, structured expert elicitation is often used, and the resulting estimate should be documented as a judgment with its assumptions noted so it can be reviewed and challenged.
How does the effectiveness of controls relate to frequency in an assessment?
Frequency can be assessed on an inherent basis, before considering the effect of controls, or on a residual basis, reflecting the influence of controls that reduce how often an event occurs. It is important to state which basis is being used, since preventive controls may lower assessed frequency while some controls act on impact rather than frequency. Confusing the two bases can distort a risk rating, so the assumptions about control performance behind a frequency estimate should be made explicit and revisited as control effectiveness changes.

Common misconceptions

Frequency and probability mean the same thing and can be used interchangeably.
Frequency typically refers to how often an event occurs over a reference period, while probability expresses the chance of occurrence within a defined exposure. Conflating them can distort risk ratings; a methodology should define which measure it uses and how any conversion between them is made.
A frequency estimate is objective and precise because it is expressed as a number.
Numerical frequency values are only as reliable as the data and assumptions behind them. Where historical data is sparse or the environment is changing, quantitative frequencies may carry significant uncertainty and are often better supported by qualitative judgement bands.
Frequency alone determines how serious a risk is.
Frequency addresses only the likelihood dimension. A meaningful risk assessment combines frequency with impact or consequence; a high-frequency, low-impact event may warrant different treatment than a rare, high-impact one.

Best practices

Always state the reference period for any frequency estimate so that values can be interpreted and compared consistently across risks.
Define within the risk assessment methodology whether frequency or probability is being used, and document any basis for converting between them.
Where descriptive bands such as rare or likely are used, document the occurrence ranges each band represents so that ratings are applied consistently by different assessors.
Assess frequency alongside impact rather than in isolation, and avoid treating a numerical frequency as inherently more reliable than a well-reasoned qualitative estimate.
Ground quantitative frequency measures in relevant, quality-checked data, and note the uncertainty or limitations where data is sparse or the operating environment is changing.
Review frequency estimates periodically, as changes in the environment, controls, or exposure can alter how often a risk event is expected to occur.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide