Skip to main content
Category: Risk Analysis and Quantification

Probability

Also known as: Likelihood
Simply put

Probability is a way of expressing how likely an event is to happen, using a number between 0 and 1, where 0 means the event will not occur and 1 means it is certain to occur. Because many events cannot be predicted with total certainty, probability lets us describe the chance of something happening rather than guaranteeing an outcome. In risk management, it is commonly used alongside impact to characterize the likelihood component of a risk.

Formal definition

Probability is a numerical measure of the likelihood that a given event will occur, expressed on a scale from 0 to 1, where larger values indicate greater likelihood. In its classical formulation it can be computed as the ratio of favorable outcomes to the total number of equally likely outcomes, while probability theory more broadly provides a mathematical framework for analyzing chance events in a logically consistent manner. Within risk assessment, probability (sometimes termed likelihood) typically represents one dimension of risk that is evaluated together with the magnitude of consequence or impact; note that some risk frameworks use qualitative likelihood scales rather than precise numerical probabilities, and the two should not be conflated.

Why it matters

Probability underpins the way risk is characterized in most risk management frameworks. Because many events cannot be predicted with total certainty, probability provides a disciplined way to express how likely an event is to occur rather than asserting that it will or will not happen. This matters because risk decisions are made under uncertainty, and a consistent measure of likelihood allows organizations to compare, prioritize, and treat risks in a logically sound manner rather than relying on intuition alone.

In risk assessment, probability is typically evaluated together with the magnitude of consequence or impact, so that neither dimension is considered in isolation. A high-likelihood event with negligible consequence and a low-likelihood event with severe consequence may warrant very different responses, and separating the likelihood component from the impact component helps make that distinction explicit. Conflating the two, or treating a likelihood estimate as a guarantee of outcome, tends to distort prioritization.

A practical caution accompanies the use of probability in this setting. Some risk frameworks express likelihood using qualitative scales, such as ordered bands, rather than precise numerical probabilities between 0 and 1. These two approaches should not be conflated, because a qualitative rating does not carry the same mathematical meaning as a computed probability, and reading precision into a qualitative label can mislead decision-makers.

Who it's relevant to

Risk managers
Risk managers use probability to express the likelihood component of a risk and to pair it with impact when assessing and prioritizing risks. Being explicit about whether likelihood is expressed numerically or on a qualitative scale helps keep assessments consistent and comparable.
Internal auditors and assurance professionals
Those providing assurance may examine how likelihood is estimated and applied within a risk assessment, including whether numerical probabilities and qualitative scales are used consistently and not conflated. Their focus is on evaluating the approach rather than performing the underlying risk management activity.
Governance and decision-makers
Those directing an organization rely on likelihood estimates, combined with impact, to inform decisions made under uncertainty. Understanding that probability describes a chance rather than guarantees an outcome supports more measured interpretation of risk information.

Inside Probability

Likelihood expression
Probability, in a risk management context, expresses the likelihood that a given event or condition will occur, often over a defined time horizon. In many frameworks it is expressed either quantitatively (as a numerical value or range) or qualitatively (through ordinal categories such as rare, possible, or likely).
Reference period and conditions
A probability figure typically depends on a stated time frame and set of assumed conditions. The same event may carry different probabilities depending on the horizon considered and the controls or circumstances assumed to be in place.
Relationship to impact
In risk assessment, probability is commonly combined with a measure of impact or consequence to characterize a risk. Probability alone does not describe the significance of a risk; it is one of the dimensions used to prioritize and treat risks.
Basis of estimation
Probability estimates may be derived from historical data, statistical modeling, or expert judgment. The reliability of an estimate depends on the quality and relevance of the underlying data and the assumptions applied.
Qualitative versus quantitative treatment
Some methodologies use qualitative probability scales suited to limited data, while others use quantitative probabilities where sufficient data supports numerical estimation. The choice typically reflects data availability, the nature of the risk, and organizational practice.

Common questions

Answers to the questions practitioners most commonly ask about Probability.

Is probability the same as the likelihood ratings used on a risk matrix?
Not exactly. Probability in its formal sense is a measure of the chance of an event, conventionally expressed on a scale from 0 to 1 (or as a percentage). The likelihood ratings on many qualitative risk matrices, such as rare, possible, or almost certain, are ordinal categories that approximate probability but are not true numerical probabilities. Treating an ordinal band as if it were a precise probability can create false precision, and the categories often vary between organizations and frameworks.
Does a low probability mean a risk can be ignored?
No. Probability is only one dimension of risk; the potential impact or consequence is the other. A low-probability event with severe consequences may warrant significant attention, treatment, or contingency planning, depending on the organization's risk appetite and tolerance. Assessing probability in isolation, without reference to impact and to the objectives at stake, can lead to under-treating high-consequence exposures.
How should probability be estimated when historical data is limited?
Where relevant historical data is sparse, organizations commonly rely on expert judgment, structured elicitation, analogous events, or qualitative bands rather than precise numerical estimates. Such estimates are inherently uncertain and should be documented with their assumptions and limitations. Many practitioners note the source and confidence of an estimate so that reviewers understand its basis and can update it as more information becomes available.
How is probability typically combined with impact in a risk assessment?
In many risk assessment methods, probability and impact are assessed separately and then combined, often multiplicatively in quantitative approaches or via a matrix in qualitative approaches, to derive a risk rating or ranking. The specific combination method varies by framework and organization. Users should be aware that combining ordinal bands into a single score can obscure the underlying values, so the method and its assumptions are typically documented.
Should the same probability scale be used across an entire organization?
Using a consistent, clearly defined probability scale across an organization commonly supports comparability and aggregation of risks. However, the appropriate time horizon and reference basis may differ between contexts, for example strategic versus operational risks, so definitions should specify what the probability refers to and over what period. Consistency in definitions matters more than forcing a single scale onto contexts where it does not fit.
How often should probability estimates be reviewed and updated?
Probability estimates are point-in-time judgments that can change as conditions, controls, or external factors evolve. Many organizations review them on a defined cycle and also upon trigger events such as significant changes in the operating environment or new information. The appropriate frequency depends on the volatility of the risk and the organization's monitoring practices; this entry does not prescribe a specific interval.

Common misconceptions

Probability and risk are the same thing.
Probability is generally one component of risk, not risk itself. In many frameworks, risk is characterized by combining the probability of an event with its potential impact and, in some approaches, the associated uncertainty. Treating probability as equivalent to risk omits the consequence dimension.
A probability value is an objective, precise fact.
Probability estimates are frequently based on historical data, models, or expert judgment and carry uncertainty. A stated figure reflects the assumptions, data quality, and time horizon behind it, and may vary as those inputs change. It should not be read as a guaranteed rate of occurrence.
Qualitative probability ratings can be treated as exact numbers.
Ordinal categories such as low, medium, or high indicate relative likelihood rather than measured numerical probability. Converting such labels into arithmetic values or averaging them can be misleading unless the methodology explicitly supports that treatment.

Best practices

State the time horizon and the assumed conditions to which a probability estimate applies, since the same event may carry different likelihoods over different periods.
Document the basis of each estimate, distinguishing values derived from historical data or modeling from those based on expert judgment, and note the associated uncertainty.
Assess probability alongside impact rather than in isolation, so that risks are prioritized on both likelihood and consequence.
Choose qualitative or quantitative approaches according to data availability and the nature of the risk, and avoid applying arithmetic to ordinal scales unless the methodology supports it.
Revisit probability estimates periodically as new data, changes in conditions, or changes in controls emerge, treating estimates as subject to revision rather than fixed.
Use consistent, clearly defined probability scales and definitions across assessments to support comparability, and record any assumptions that could affect interpretation.
Application Security Isn’t Optional Anymore.