Skip to main content
Category: Risk Analysis and Quantification

Level of Risk

Also known as: Risk Level
Simply put

Level of risk is a measure of how significant a particular risk is, based on how likely the event is to occur and how serious its consequences would be. It helps organizations understand and compare risks so they can decide which ones need the most attention. Risks are often described using ordered categories, such as minimal, low, or moderate.

Formal definition

In risk management, the level of risk is the magnitude of a risk expressed as a combination of the likelihood of an event occurring and the impact (consequences) of that event. It provides a snapshot used to prioritise risks, with higher-level risks typically ranked ahead of lower-level ones for treatment or control. The level may be represented qualitatively through ordered rating categories (for example, minimal, low, moderate) or through a scoring approach that combines likelihood and impact assessments; the specific scales, thresholds, and rating labels vary by organization and framework. This entry addresses the concept only and does not prescribe particular scoring methods, tooling, or implementation specifics.

Why it matters

Level of risk is the mechanism by which organizations translate a broad universe of identified risks into a prioritized order of attention. Without a consistent measure that combines how likely an event is with how serious its consequences would be, risks tend to be treated on the basis of intuition or recency rather than significance. By assigning a level, an organization can compare dissimilar risks against a common scale and direct limited resources toward those that matter most.

The practical value lies in prioritisation. As reflected in guidance from bodies such as the European Court of Auditors, risks are commonly ranked according to their level, obtained by assessing both the likelihood of an event occurring and the impact should it occur. Higher-level risks are typically addressed ahead of lower-level ones for treatment or control, which supports defensible, evidence-based decisions about where to focus mitigation effort.

It is important to treat level of risk as a snapshot rather than a guarantee. The rating reflects an assessment at a point in time and depends on the scales, thresholds, and labels an organization adopts; these vary between organizations and frameworks. A level rating supports judgement but does not, on its own, ensure a risk is adequately controlled, and it should be revisited as circumstances change.

Who it's relevant to

Risk managers
Risk managers use level of risk to compare and prioritise the risks they identify, focusing treatment and control efforts on those assessed as most significant. They are also typically responsible for defining the likelihood and impact scales and rating categories used, and for ensuring levels are reassessed as conditions change.
Governance professionals and decision-makers
Those with oversight and decision rights rely on risk levels to make defensible, evidence-based choices about where to direct limited resources. A consistent level rating gives them a common basis on which to weigh dissimilar risks against one another.
Internal auditors and assurance functions
Internal auditors may use assessed risk levels to inform where assurance effort is directed and may evaluate whether the organization's approach to determining levels is applied consistently. Their role is to assess the process objectively rather than to own the risk assessments themselves.
Control owners
Because a risk's level can inform which controls are required to mitigate it, those responsible for designing and operating controls use level ratings to understand the significance of the risks their controls address and the relative priority attached to them.

Inside Level of Risk

Likelihood
The probability or frequency with which a risk event may occur, commonly expressed on a qualitative scale (e.g., rare to almost certain), a quantitative probability, or a frequency over a defined time horizon.
Consequence (Impact)
The severity of the effect on objectives should the risk event materialize, which may be assessed across multiple dimensions such as financial, operational, reputational, legal, or safety impacts.
Combination of Likelihood and Consequence
In many frameworks, including ISO 31000 (issued by the International Organization for Standardization), the level of risk is characterized as the magnitude expressed as the combination of consequences and their likelihood, rather than either element alone.
Measurement Scale
The basis used to express the level of risk, which may be qualitative (descriptive categories), semi-quantitative (rating scales or scores), or quantitative (numeric values), each with differing precision and comparability.
Inherent versus Residual Perspective
The level of risk may be assessed before the effect of controls (inherent) or after controls are applied (residual). Stating which perspective is used is important, as the two typically differ.
Reference Point for Evaluation
The estimated level of risk is commonly compared against risk criteria, appetite, or tolerance to support risk evaluation and decisions on whether treatment is required. The level itself is a measure, not a decision.

Common questions

Answers to the questions practitioners most commonly ask about Level of Risk.

Is the level of risk the same as the likelihood of an event occurring?
No. In many risk management frameworks, the level of risk is a combined expression of the consequence (impact) of an event and the likelihood of its occurrence, not likelihood alone. Treating it as a probability measure only omits the consequence dimension and can understate or overstate the significance of a risk. Likelihood is typically one input to determining the level of risk rather than a synonym for it.
Does a determined level of risk tell you whether the risk is acceptable?
Not by itself. The level of risk is a magnitude estimate produced through risk analysis; whether that magnitude is acceptable is a separate judgement made during risk evaluation, typically by comparing the level against risk criteria such as risk appetite or risk tolerance. A high level of risk is not automatically unacceptable, and a low level is not automatically acceptable, until it is assessed against defined criteria.
How is the level of risk typically expressed in practice?
It may be expressed qualitatively (for example, low, medium, high), semi-quantitatively (using ordinal scales or scores), or quantitatively (for example, in monetary or numeric terms), depending on the framework, data availability, and organizational context. The chosen method should be documented so that ratings are consistent and comparable across assessments.
Should the level of risk be assessed before or after controls are considered?
This depends on whether inherent or residual risk is being represented. The level of inherent risk is commonly assessed before accounting for existing controls, while the level of residual risk reflects the effect of controls in place. Practitioners should state explicitly which basis a given rating represents, since conflating the two can misinform treatment decisions.
How can consistency in rating the level of risk be maintained across an organization?
Consistency is commonly supported by documented and shared criteria, such as defined consequence and likelihood scales, worked examples, and calibration or review by a second-line function. Because scoring often involves judgement, periodic review of how ratings are applied can help reduce divergence between assessors and business units.
How often should the level of risk be reassessed?
Reassessment frequency varies by organization, risk type, and framework. It is commonly reviewed on a defined cycle and also when circumstances change materially, such as changes in the operating environment, controls, objectives, or emerging threats. The appropriate cadence should align with the organization's monitoring and review arrangements.

Common misconceptions

Level of risk is the same as likelihood, so a low-probability event is automatically a low-level risk.
In many frameworks the level of risk reflects the combination of likelihood and consequence. A low-probability event with severe consequences may still represent a significant level of risk, so likelihood alone is insufficient to characterize it.
A quantified level of risk (for example, a numeric score) is objective and precise.
Level of risk often relies on estimates and judgment, particularly where qualitative or semi-quantitative scales are used. Numeric scores can convey false precision; they typically depend on the underlying assumptions, scale design, and data quality, which should be documented and understood.
Determining the level of risk tells you whether the risk is acceptable.
Estimating the level of risk is an analysis step. Acceptability is a separate evaluation reached by comparing the estimated level against risk criteria, appetite, or tolerance. The level of risk informs, but does not by itself constitute, that decision.

Best practices

State explicitly whether the level of risk is being assessed on an inherent or residual basis, since the two commonly differ and mixing them can distort comparisons.
Define the likelihood and consequence scales, including any time horizon and the dimensions of impact considered, so that ratings are applied consistently across risks and assessors.
Choose a measurement approach (qualitative, semi-quantitative, or quantitative) appropriate to the available data and decision needs, and avoid implying more precision than the underlying information supports.
Document the assumptions, data sources, and judgments behind each estimate so the level of risk is transparent, reviewable, and reproducible.
Keep the estimation of the level of risk distinct from the evaluation of acceptability, comparing the estimated level against defined risk criteria, appetite, or tolerance as a separate step.
Periodically revisit and recalibrate scales and estimates as conditions, controls, and information change, since the level of risk is not static.
Application Security Isn’t Optional Anymore.