Skip to main content
Category: Risk Analysis and Quantification

Likelihood

Also known as: Probability of occurrence, Chance
Simply put

Likelihood is the chance that a particular event or outcome will happen. In risk management, it is commonly used to describe how probable it is that a given risk will actually occur, often expressed on a scale or as a rating.

Formal definition

In a risk management context, likelihood refers to a measure of the chance that a specified event, condition, or outcome will occur, typically assessed alongside impact when evaluating risk. It may be expressed qualitatively (for example, rare, possible, likely) or quantitatively (for example, as a probability or frequency), depending on the assessment methodology in use. Likelihood is closely related to the general concept of probability; in formal statistics, however, the term 'likelihood' has a more specialized meaning as a function of parameter values given observed data, which differs from its everyday and risk-assessment usage. This entry addresses the risk-management sense and does not cover the statistical likelihood function or specific scoring scales, which vary by framework and organization.

Why it matters

Likelihood is one of the two primary dimensions, alongside impact, used to evaluate and prioritize risks in most risk management methodologies. Without a considered view of how probable an event is, organizations cannot meaningfully rank risks or allocate limited resources to those that warrant attention. Treating a remote possibility and a near-certainty as equivalent tends to produce either wasted effort on improbable events or inadequate preparation for probable ones.

The usefulness of a likelihood assessment depends heavily on the rigor and consistency with which it is applied. Likelihood ratings are inherently judgmental, particularly where historical data is sparse, and they can be subject to bias, over-optimism, or inconsistent interpretation of qualitative scales across assessors. Because scales and definitions vary by framework and organization, a rating of 'possible' in one register may not mean the same thing as in another, which complicates comparison and aggregation.

A further point of care is terminology: in everyday and risk-assessment usage, likelihood is broadly synonymous with the chance or probability that something will occur, but in formal statistics the term 'likelihood' has a distinct technical meaning as a function of parameter values given observed data. Professionals should be alert to this difference to avoid conflating the two senses when moving between qualitative risk registers and quantitative or statistical analysis.

Who it's relevant to

Risk managers
Those responsible for maintaining risk registers and assessments rely on likelihood, together with impact, to rate and prioritize risks and to inform decisions about which exposures to treat. They also set and apply the definitions behind the likelihood scale so that ratings remain consistent across assessors and over time.
Risk and control owners in the business
Managers who own specific risks contribute the operational knowledge needed to judge how probable an event is, drawing on experience and any available data. Their input shapes the likelihood ratings that feed prioritization decisions.
Internal auditors and assurance functions
Assurance providers may review how likelihood is assessed, examining whether definitions are applied consistently and whether ratings are adequately supported, as part of evaluating the reliability of the organization's risk assessment process. This is an independent review of the assessment, distinct from performing the risk assessment itself.
Analysts working with quantitative or statistical methods
Those who bridge qualitative risk registers and quantitative analysis need to be mindful that 'likelihood' in the risk-assessment sense refers to the chance of an event occurring, whereas in formal statistics the term denotes a function of parameter values given observed data. Keeping the two senses distinct avoids misinterpretation when translating between approaches.

Inside Likelihood

Probability of occurrence
The core element of likelihood is an estimate of how probable it is that a given risk event or scenario will occur within a defined period or set of conditions. It answers the question of chance rather than impact.
Time horizon or reference period
Likelihood is typically assessed against a specified window, such as within a year or over the life of a project. The same event may carry different likelihoods depending on the period considered.
Qualitative expression
In many risk assessment approaches, likelihood is expressed on an ordinal scale using descriptive bands such as rare, unlikely, possible, likely, or almost certain. These categories support consistent rating but do not by themselves provide numerical precision.
Quantitative expression
Where sufficient data exist, likelihood may be expressed as a probability, a frequency, or an expected number of occurrences. The choice between qualitative and quantitative expression commonly depends on data availability and the maturity of the assessment.
Relationship to impact within risk assessment
Likelihood is one of two dimensions commonly combined with impact (or consequence) to derive a risk rating. It does not describe the severity of an outcome, only its chance of occurring.
Inherent versus residual perspective
Likelihood can be assessed before controls are considered (inherent) or after accounting for the effect of controls (residual). Stating which perspective applies is important to avoid misinterpretation of the rating.

Common questions

Answers to the questions practitioners most commonly ask about Likelihood.

Is likelihood the same as probability?
Not exactly. While the terms are often used interchangeably, likelihood in risk management commonly refers to a broader qualitative or semi-quantitative expression of how possible it is that a risk event will occur, whereas probability typically denotes a precise mathematical value between 0 and 1. Many frameworks use likelihood scales (for example, rare to almost certain) that do not require statistical calculation. Treating the two as identical can imply a level of quantitative rigor that a qualitative likelihood rating does not provide.
Does a high likelihood rating mean a risk is high priority?
Not on its own. Likelihood is only one dimension of risk assessment; it is commonly combined with impact (or consequence) to derive an overall risk level. A risk with high likelihood but negligible impact may rank lower than a low-likelihood, severe-impact risk. Prioritization typically depends on the combination of both factors as evaluated against the organization's risk criteria, so likelihood should not be read as a standalone measure of significance.
How can likelihood be estimated when historical data is limited?
In the absence of robust historical data, organizations commonly rely on qualitative scales informed by expert judgment, structured workshops, or comparison with analogous events. Where such estimates are used, it is good practice to document the basis and assumptions and to note the associated uncertainty. This entry does not prescribe a specific estimation methodology, as appropriate approaches vary by context, sector, and available information.
Should likelihood be assessed on an inherent or residual basis?
Many frameworks support assessing likelihood at both stages: inherent likelihood before considering the effect of controls, and residual likelihood after accounting for controls in place. The choice depends on the organization's methodology and the purpose of the assessment. Being explicit about which basis is being used helps avoid confusion, particularly when comparing risks or reporting to governance bodies.
How can likelihood ratings be kept consistent across different assessors?
Consistency is commonly supported by defining clear, calibrated likelihood scales with descriptive anchors (for example, associating each rating with a frequency band or a qualitative descriptor) and by providing guidance so that assessors interpret the levels similarly. Some organizations use facilitation, peer review, or calibration sessions. The aim is comparability across risks; the specific calibration approach is an implementation matter beyond the scope of this entry.
How often should likelihood assessments be reviewed?
Review frequency typically depends on the volatility of the risk, changes in the operating environment, and the organization's risk management cadence. Likelihood estimates may need updating when new information emerges, when controls change, or when triggering events occur, rather than solely on a fixed schedule. This entry does not specify a required interval, as appropriate timing varies by organization and risk type.

Common misconceptions

Likelihood and impact are the same thing or can be treated interchangeably.
Likelihood addresses the chance that an event occurs, while impact addresses the magnitude of its consequences. They are distinct dimensions that are typically assessed separately and then combined to inform a risk rating.
A qualitative likelihood band such as 'possible' or 'likely' carries a precise, universally agreed probability.
Qualitative bands are ordinal descriptors whose meaning depends on the scale and definitions adopted by a given organization or framework. Without documented criteria, the same label may represent different probabilities to different assessors.
A stated likelihood is a fixed prediction of what will happen.
Likelihood is an estimate of chance under stated assumptions and over a defined period, not a guarantee. It can change as conditions, data, and controls change, and it does not assure any particular outcome.

Best practices

Define and document the likelihood scale, including the meaning of each band and any associated probability or frequency ranges, so ratings are applied consistently across assessors.
State the time horizon or reference period against which likelihood is assessed, since the same event may warrant different ratings over different periods.
Specify whether the likelihood being recorded is inherent (before controls) or residual (after controls) to prevent misinterpretation.
Assess likelihood separately from impact and combine them only through a defined method, rather than blending the two dimensions into a single intuitive judgment.
Use quantitative expressions where reliable data support them and qualitative expressions where they do not, being transparent about the basis and limitations of the estimate.
Periodically revisit likelihood estimates as new data, changing conditions, or control changes emerge, and treat them as revisable rather than fixed.
Application Security Isn’t Optional Anymore.