Answers to the questions practitioners most commonly ask about Severity.
Is severity the same as the risk rating or overall risk level of an event?
No. Severity typically refers to the magnitude of impact or consequence of an event or issue, considered on its own. A risk rating or overall risk level commonly combines impact with likelihood, and in some frameworks with other factors such as velocity or detectability. Treating severity as equivalent to the full risk rating can lead to mislabeled prioritization, because a high-severity event may carry a low probability of occurrence, and vice versa.
Does a high severity assessment mean the same thing as a high priority for action?
Not necessarily. Severity describes how significant the consequences would be, whereas prioritization for treatment or response usually weighs severity alongside likelihood, existing controls, and organizational context. An issue may be assessed as high severity yet be deprioritized if it is already well controlled or unlikely to materialize, while a lower-severity but frequent or imminent issue may warrant earlier attention. Conflating the two can distort resource allocation.
How is a severity scale typically defined so that ratings are applied consistently?
Organizations commonly define severity using a rating scale with documented criteria for each level, often expressed across multiple impact dimensions such as financial, operational, legal or regulatory, safety, and reputational consequences. Providing descriptive anchors or thresholds for each level, rather than labels alone, supports more consistent application across assessors. The specific scale and thresholds vary by organization, sector, and the framework in use.
How should severity be documented for an identified issue or event?
Severity is generally recorded alongside the rationale for the rating, including which impact dimensions were considered and the assumptions made. Capturing the basis for the assessment supports traceability, review, and comparison over time. Documentation practices differ by organization, and this entry does not prescribe particular tooling or register formats.
Who is typically responsible for assigning a severity rating?
Assigning severity is commonly a management or first-line responsibility for the risk or issue owner, often with support or challenge from a second-line function that maintains the assessment methodology. Independent assurance functions such as internal audit generally evaluate whether severity is being assessed appropriately rather than setting the ratings themselves, preserving their independence and objectivity.
How can severity ratings be kept comparable across different parts of an organization?
Comparability is commonly supported by using a shared, documented severity scale with defined criteria, calibrating assessors against worked examples, and periodically reviewing ratings for consistency. Where different units apply different scales or thresholds, mapping or normalization may be needed before aggregating results. The effectiveness of these practices depends on how clearly the criteria are defined and how consistently they are applied.