Skip to main content
Category: Risk Analysis and Quantification

Impact

Also known as: Consequence, Severity
Simply put

Impact is the effect or influence something has on an entity or its environment. In a risk context, it refers to how significantly an event or outcome affects an organization's objectives, operations, or resources. The provided evidence describes impact only in general terms as a 'marked effect or influence' and does not supply a risk-management-specific definition.

Formal definition

Impact generally denotes the degree of effect or influence that an event, condition, or action exerts on a defined entity or environment. In risk practice, impact is commonly one dimension of risk assessment, often paired with likelihood, used to characterize the consequence of a risk event on objectives; however, the evidence packet supplied here defines impact only in a broad, non-technical sense as a 'marked effect or influence' and does not include framework-specific criteria, scoring methods, or standards references. Practitioners should note that precise impact definitions, scales, and categories typically vary by framework, jurisdiction, sector, and organizational context.

Why it matters

Impact is one of the fundamental dimensions used to characterize risk. Understanding how significantly an event or outcome could affect an organization's objectives, operations, or resources allows decision-makers to distinguish between risks that warrant substantial attention and those that do not. Without an assessment of impact, an organization has an incomplete picture of the risks it faces and may misallocate limited resources toward events that are unlikely to cause meaningful harm while neglecting those that could.

Because impact is commonly paired with likelihood in risk assessment, it directly informs prioritization and treatment decisions. Two risk events may share a similar probability of occurring, yet differ greatly in the severity of their consequences; the impact dimension is what surfaces that difference. It is important to note, however, that the evidence available here describes impact only in a broad, general sense as a 'marked effect or influence,' and does not supply a risk-management-specific definition, scale, or scoring method.

Practitioners should therefore treat impact as a concept whose precise definition, measurement scales, and categories vary by framework, jurisdiction, sector, and organizational context. Applying a generic understanding of impact without reference to the applicable framework or organizational criteria may produce inconsistent or misleading assessments.

Who it's relevant to

Risk Managers
Risk managers use impact, typically alongside likelihood, to characterize and prioritize risks against organizational objectives. The specific impact scales and categories they apply generally depend on the frameworks and criteria adopted by their organization.
Internal Auditors
Internal auditors may consider the potential impact of risks and control failures when planning and scoping assurance work. As an assurance function, their role is to evaluate how impact has been assessed by management rather than to own that assessment.
Governance Professionals
Those responsible for directing the organization rely on an understanding of impact to inform decision rights and resource allocation, ensuring that events with more significant potential consequences receive appropriate attention.
Compliance Officers
Compliance officers may weigh the potential impact of non-adherence to applicable laws, regulations, and internal policies, recognizing that the relevant consequences vary by jurisdiction, sector, and organizational context.

Inside Impact

Impact (consequence)
The effect on objectives should a risk event occur, commonly expressed in terms of magnitude or severity. In many risk frameworks, such as ISO 31000, impact (often termed consequence) is one of two primary dimensions of risk, paired with likelihood.
Impact scale
A defined set of ordered levels (for example, low through severe) used to rate consequences consistently. Organizations typically calibrate these scales to their own context, objectives, and risk criteria rather than adopting a universal standard.
Impact categories
The distinct types of effect a risk may produce, which commonly include financial, operational, reputational, legal or regulatory, health and safety, and strategic consequences. A single event may register across more than one category.
Quantitative versus qualitative impact
Impact may be estimated numerically (for example, in monetary or time-based terms) or described qualitatively against defined descriptors. The choice typically depends on data availability, the nature of the risk, and the assessment methodology in use.
Inherent versus residual impact
Impact may be considered before controls are applied (contributing to inherent risk) or after treatment and controls are accounted for (contributing to residual risk). Stating which basis is used is important to avoid ambiguity.
Time horizon and velocity
Impact assessment often considers not only magnitude but when and how quickly consequences may materialize, which can affect prioritization and treatment decisions.

Common questions

Answers to the questions practitioners most commonly ask about Impact.

Is impact the same as the likelihood of a risk occurring?
No. Impact and likelihood are distinct dimensions of a risk. Impact describes the magnitude of consequence should a risk event materialize, whereas likelihood describes the probability or frequency of that event occurring. In many risk assessment methodologies these two dimensions are estimated separately and then combined to inform a risk rating. Treating them as interchangeable can distort prioritization, since a high-impact but low-likelihood risk and a low-impact but high-likelihood risk may warrant very different treatment decisions.
Does impact only refer to financial loss?
No. While financial consequence is a common way to express impact, it is typically only one of several dimensions. Depending on the framework and the organization's objectives, impact may also be characterized in terms of operational disruption, reputational harm, legal or regulatory consequences, health and safety effects, or other non-financial outcomes. Reducing impact to a purely monetary figure can understate consequences that are difficult to quantify, so many organizations assess impact across multiple categories.
How can an organization define impact criteria consistently across different risks?
Organizations commonly establish predefined impact scales or criteria, often expressed as descriptive bands or levels, so that assessors apply comparable definitions. These criteria may span multiple categories such as financial, operational, reputational, and regulatory consequences, with descriptions calibrated to the organization's size and context. Documenting the criteria and providing examples for each level helps reduce subjectivity, though judgment is still required and the criteria should be reviewed periodically to remain relevant to objectives.
Should impact be assessed before or after considering existing controls?
It depends on what the assessment is measuring. Impact may be considered in the context of inherent risk, before the effect of controls, or in the context of residual risk, after controls are taken into account. Some methodologies assess both to understand how controls affect consequence and likelihood. It is important to state explicitly which basis is being used, because conflating inherent and residual perspectives can lead to inconsistent ratings and unclear treatment decisions.
Who should be involved in estimating impact?
Estimating impact typically involves those with relevant knowledge of the affected objectives, processes, or assets, often risk owners or subject matter experts within the first line, supported by risk management functions in the second line. Involving individuals close to the operation can improve the realism of consequence estimates, while a supporting risk function can promote consistency in how the impact criteria are applied. Assurance functions such as internal audit generally evaluate the process rather than perform the management assessment themselves, preserving their independence.
How should impact be documented in a risk register?
Impact is commonly recorded in a risk register alongside likelihood and the resulting risk rating, with a reference to the impact category or categories assessed and the basis used (for example, inherent or residual). Recording the rationale or key assumptions behind an impact estimate can improve transparency and support later review. Because impact estimates rely on judgment and may change as circumstances evolve, many organizations revisit and update these entries as part of periodic risk review cycles.

Common misconceptions

Impact and likelihood are the same thing, or impact alone measures risk.
Impact describes the magnitude of consequence if an event occurs, while likelihood describes the probability of occurrence. In many frameworks, risk is characterized by considering both together; impact in isolation does not represent the level of risk.
Impact is always financial or can be reduced to a single number.
Impact commonly spans multiple categories, including operational, reputational, legal or regulatory, and safety effects, some of which resist reliable monetization. A single quantitative figure may understate the full range of consequences.
A stated impact rating is an objective, precise prediction.
Impact ratings are typically estimates informed by judgment, assumptions, and available data, and they carry uncertainty. They should be treated as reasoned assessments rather than guarantees of outcome.

Best practices

Define and document clear impact scales and category descriptors, calibrated to the organization's objectives and risk criteria, so that ratings are applied consistently across assessments.
State explicitly whether an impact estimate reflects an inherent or residual basis, and record the assumptions and controls considered.
Assess impact across multiple relevant categories rather than defaulting to financial consequences alone, and note where an event may register in more than one category.
Where data supports it, combine quantitative and qualitative techniques, and be transparent about the uncertainty and limitations of any estimate.
Consider time horizon and how quickly consequences may materialize when using impact to prioritize risks and inform treatment decisions.
Periodically review and recalibrate impact scales and ratings as objectives, context, and available information change.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps