Skip to main content
Category: Risk Analysis and Quantification

Severity

Also known as: Impact severity, Degree of severity
Simply put

Severity refers to how serious or harmful the effects of an incident or event can be. In a risk context, it describes the degree of harm or negative consequence that could result, with higher severity indicating more serious effects.

Formal definition

In risk management, severity denotes the degree of harm, loss, or adverse consequence associated with an incident, event, or realized risk, typically assessed as one component of risk alongside likelihood. It measures how bad the outcome would be rather than how probable it is; the two are commonly combined to characterize the overall level of a risk. The specific scales, categories, and criteria used to rate severity vary by framework, organization, sector, and jurisdiction, and this entry does not prescribe any particular rating method or threshold.

Why it matters

Severity is one of the two dimensions, alongside likelihood, that organizations commonly use to characterize the overall level of a risk. Understanding how serious the consequences of an event could be, independent of how probable it is, allows risk and compliance professionals to distinguish between events that are frequent but minor and those that are rare but potentially catastrophic. Without a clear view of severity, prioritization efforts can misallocate attention and resources, treating high-impact exposures with the same urgency as trivial ones.

Who it's relevant to

Risk managers
Risk managers use severity as a core component of risk assessment, pairing it with likelihood to characterize and prioritize exposures. Judging how serious the consequences of an event could be helps them focus treatment on the risks that matter most, though the specific scales and criteria they apply will depend on their framework and organizational context.
Compliance officers
Compliance officers may draw on severity when evaluating the potential consequences of non-adherence to laws, regulations, or internal policies. A view of how harmful a given breach could be supports proportionate responses, but severity here informs judgment rather than substituting for jurisdiction- and sector-specific requirements.
Internal auditors
As an independent assurance function, internal auditors may consider the severity of potential consequences when scoping and prioritizing their work and when communicating findings. Severity informs where assurance attention is directed; it does not change the auditor's role, which remains distinct from the management activities that identify and treat the underlying risks.

Inside Severity

Impact dimension
The magnitude of consequence associated with a risk event or issue should it occur, often expressed across categories such as financial, operational, reputational, legal, or safety-related. Severity in most risk and incident contexts refers primarily to this impact component rather than to how frequently the event may occur.
Severity scale or rating criteria
A defined set of levels (for example, low, moderate, high, critical) with descriptive anchors that allow consistent classification. The specific thresholds and definitions vary by organization, framework, and sector and are typically documented in a risk assessment methodology or incident management policy.
Distinction from likelihood
Severity addresses the size of the consequence, while likelihood addresses the probability of occurrence. In many risk assessment approaches the two are assessed separately and then combined to derive an overall risk rating; conflating them can distort prioritization.
Contextual application
Severity is applied differently across domains, such as incident severity in operational and IT contexts, breach severity in data protection contexts, and consequence rating within enterprise or operational risk assessments. The defining criteria depend on the objectives against which impact is measured.
Relationship to prioritization and escalation
Severity commonly informs escalation paths, response timelines, and resource allocation. Higher-severity items are typically routed to more senior decision-makers, though escalation thresholds are set by organizational policy and may differ across jurisdictions and sectors.

Common questions

Answers to the questions practitioners most commonly ask about Severity.

Is severity the same as the risk rating or overall risk level of an event?
No. Severity typically refers to the magnitude of impact or consequence of an event or issue, considered on its own. A risk rating or overall risk level commonly combines impact with likelihood, and in some frameworks with other factors such as velocity or detectability. Treating severity as equivalent to the full risk rating can lead to mislabeled prioritization, because a high-severity event may carry a low probability of occurrence, and vice versa.
Does a high severity assessment mean the same thing as a high priority for action?
Not necessarily. Severity describes how significant the consequences would be, whereas prioritization for treatment or response usually weighs severity alongside likelihood, existing controls, and organizational context. An issue may be assessed as high severity yet be deprioritized if it is already well controlled or unlikely to materialize, while a lower-severity but frequent or imminent issue may warrant earlier attention. Conflating the two can distort resource allocation.
How is a severity scale typically defined so that ratings are applied consistently?
Organizations commonly define severity using a rating scale with documented criteria for each level, often expressed across multiple impact dimensions such as financial, operational, legal or regulatory, safety, and reputational consequences. Providing descriptive anchors or thresholds for each level, rather than labels alone, supports more consistent application across assessors. The specific scale and thresholds vary by organization, sector, and the framework in use.
How should severity be documented for an identified issue or event?
Severity is generally recorded alongside the rationale for the rating, including which impact dimensions were considered and the assumptions made. Capturing the basis for the assessment supports traceability, review, and comparison over time. Documentation practices differ by organization, and this entry does not prescribe particular tooling or register formats.
Who is typically responsible for assigning a severity rating?
Assigning severity is commonly a management or first-line responsibility for the risk or issue owner, often with support or challenge from a second-line function that maintains the assessment methodology. Independent assurance functions such as internal audit generally evaluate whether severity is being assessed appropriately rather than setting the ratings themselves, preserving their independence and objectivity.
How can severity ratings be kept comparable across different parts of an organization?
Comparability is commonly supported by using a shared, documented severity scale with defined criteria, calibrating assessors against worked examples, and periodically reviewing ratings for consistency. Where different units apply different scales or thresholds, mapping or normalization may be needed before aggregating results. The effectiveness of these practices depends on how clearly the criteria are defined and how consistently they are applied.

Common misconceptions

Severity and overall risk are the same thing.
Severity typically captures only the impact dimension. In many frameworks overall risk is derived by considering severity together with likelihood; treating severity alone as the risk rating can lead to misprioritization.
Severity is an objective, fixed value.
Severity is assigned against defined criteria that reflect organizational context, objectives, and appetite. Ratings can vary between organizations and change as circumstances change, and they commonly involve judgment rather than a single universal measure.
A high-severity rating means the event is imminent or probable.
Severity describes the size of potential consequence, not the probability of occurrence. A high-severity event may be unlikely, which is why likelihood is generally assessed alongside severity.

Best practices

Define severity levels with explicit, documented anchors for each category of impact (such as financial, operational, reputational, legal, or safety) so that ratings are applied consistently across the organization.
Keep severity and likelihood as separate assessment inputs, and be transparent about how they are combined to produce any overall risk or priority rating.
Align severity criteria with the organization's stated objectives, risk appetite, and any applicable jurisdictional or sector-specific obligations, rather than applying a single generic scale.
Tie severity ratings to defined escalation paths and response expectations set out in policy, so that higher-severity items receive appropriate visibility and decision authority.
Periodically review and calibrate severity criteria and past ratings to reduce inconsistency and to reflect changes in context, objectives, or the external environment.
Document the rationale behind severity assignments to support auditability and to preserve the distinction between management's assessment and any independent assurance review of it.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.