Skip to main content
Category: Risk Assessment & Analysis

Likelihood and Severity of Harm

Also known as: Probability and Severity of Harm, Likelihood and Impact, Probability of Occurrence and Severity
Simply put

Likelihood and severity of harm are the two basic ingredients used to size up a risk: how probable it is that something bad happens, and how serious the damage would be if it did. Combining these two dimensions helps organizations decide which risks matter most and where to focus attention. A low-probability event with catastrophic consequences may warrant as much concern as a frequent but minor one.

Formal definition

In many risk assessment frameworks, risk is characterized as a function of two distinct components: the likelihood (probability) that a hazard results in harm, and the severity (magnitude or consequence) of that harm if it occurs. Severity is typically defined as a measure of the possible effects or consequences of a hazard, and is often ranked on ordinal scales (for example, catastrophic, critical, marginal, negligible), while likelihood is often ranked on scales such as frequent to improbable. These two dimensions are commonly plotted together in a risk matrix to derive an estimated risk level. Note that specific scale definitions, terminology, and combination methods vary by framework and sector; the evidence here draws primarily on safety and product-risk contexts (such as ISO 14971 for medical devices) rather than establishing a single authoritative definition applicable to all AI governance or model risk settings.

Why it matters

Likelihood and severity of harm are the foundational inputs for prioritizing risk, and treating them as a single undifferentiated notion of "how bad is this" is one of the most common errors in risk assessment. Because the two dimensions are distinct, they can point in different directions: a hazard that occurs frequently but causes only minor harm may demand a very different response than one that is highly improbable but potentially catastrophic. Organizations that collapse these dimensions into a vague sense of severity risk misallocating attention and resources, either over-investing in nuisance-level issues or under-preparing for rare but devastating outcomes.

Who it's relevant to

Risk assessors and safety engineers
Those who build and populate risk matrices rely on the likelihood-severity distinction to rate individual hazards consistently. The primary pitfall to guard against is conflating the two dimensions into one score, which obscures the difference between frequent-but-minor and rare-but-catastrophic risks and undermines defensible prioritization.
Model risk and AI governance practitioners
Professionals adapting harm-based risk assessment to AI systems may draw on the likelihood-severity structure familiar from safety and product-risk contexts. They should note that the scale definitions, terminology, and combination methods in those contexts (such as ISO 14971 for medical devices) are not automatically authoritative for AI governance or model risk settings, and should confirm how their own framework defines and combines these dimensions.
Compliance officers and auditors
Reviewers checking that a risk assessment is methodologically sound benefit from verifying that likelihood and severity have been evaluated and documented as separate components, rather than merged. This separation makes the reasoning behind a given risk rating traceable and easier to challenge or defend.
Product and safety teams in regulated sectors
Teams working under safety-oriented frameworks, such as medical device risk management, use severity as a measure of the possible effects or consequences of a hazard and likelihood as its probability of occurrence. These teams should apply the scale definitions specified by their applicable framework rather than importing scales from an unrelated sector.

Inside Likelihood and Severity of Harm

Likelihood of harm
The estimated probability that a given harm or adverse outcome will actually occur from the use or misuse of an AI system. It is typically assessed qualitatively or quantitatively and is often one axis of a risk matrix used to prioritize risks. Likelihood estimates are inherently uncertain and depend on assumptions about deployment context, usage patterns, and controls in place.
Severity of harm
The magnitude or seriousness of the adverse impact should the harm materialize, often considering factors such as the reversibility of the harm, the number of affected individuals, and whether the impact affects fundamental rights, safety, financial position, or dignity. Severity is commonly treated as a separate axis from likelihood so that low-probability but high-consequence harms are not overlooked.
Risk as a function of both dimensions
In many risk frameworks, risk is characterized as a combination of likelihood and severity rather than either factor alone. This pairing supports prioritization, but the two dimensions are conceptually distinct and should be evaluated separately before being combined, since combining them prematurely can mask high-severity, low-likelihood scenarios.
Affected population and scope
Considerations of who or what may be harmed, how many are affected, and whether affected parties are vulnerable groups. Scope influences severity assessments and, in some regulatory framings, whether a use case is treated as higher risk. The relevant population and thresholds vary by framework and jurisdiction.
Reversibility and duration
Whether a harm can be undone or remediated and how long its effects persist. Harms that are permanent or difficult to reverse are typically weighted as more severe, independent of how likely they are to occur.
Contextual and temporal dependence
Both likelihood and severity depend on deployment context, and they can change over time as data, usage, models, or controls change. Estimates made at design time may not hold in production, which is why these dimensions are commonly re-assessed rather than fixed once.

Common questions

Answers to the questions practitioners most commonly ask about Likelihood and Severity of Harm.

Is a harm with high severity but low likelihood automatically a low-priority risk?
No. Treating likelihood and severity as if one can simply cancel out the other is a common error. A low-probability, high-severity harm (for example, a catastrophic or irreversible outcome affecting many individuals) may warrant significant controls even when its estimated likelihood is small. Many risk frameworks treat likelihood and severity as distinct dimensions that are assessed together rather than collapsed into a single number, and some place particular weight on severity where harms are irreversible or affect fundamental rights. The appropriate treatment typically depends on the framework, the risk appetite of the organization, and the sector in which the model operates.
Does a low likelihood-and-severity rating mean the underlying risk has been eliminated?
No. Rating a harm as low in likelihood and severity is an assessment of estimated risk, not a statement that the risk no longer exists. Controls and mitigations reduce or manage risk rather than remove it, and residual risk typically remains after mitigation. Estimates of likelihood and severity are also uncertain and can change as data, usage context, or the model itself evolves, which is why ongoing monitoring is generally treated as part of managing these harms rather than a one-time determination.
How can likelihood and severity be estimated when there is little historical data on a harm?
Where empirical data is sparse, practitioners commonly combine what quantitative evidence exists with structured qualitative judgment, such as expert elicitation, scenario analysis, and analogies to comparable systems or incidents. In many approaches, these estimates are documented with their assumptions and uncertainty explicitly noted, and treated as provisional pending further data. The suitability of any particular estimation method depends on the context and the framework being applied; this entry does not endorse a single technique as universally correct.
Who within an organization is typically responsible for assessing likelihood and severity of harm?
Responsibility is often distributed across roles rather than held by a single function. In organizations that use a lines-of-defense model, the first line (those who build or operate the model) frequently produces initial assessments, while the second line (independent risk or validation functions) may challenge or review those assessments, and the third line (internal audit) may evaluate whether the process was followed. The specific allocation varies by organization, sector, and applicable framework, and this entry does not assert a mandatory structure.
How should likelihood and severity assessments be documented?
Assessments are commonly documented in a way that records the identified harms, the basis for the likelihood and severity estimates, the assumptions and data relied upon, the uncertainty involved, and any controls applied. Clear documentation supports later review, independent challenge, and updates as conditions change. The required form and detail of such documentation depend on the organization's policies and any applicable regulatory or standards expectations, which differ across jurisdictions and sectors.
When should likelihood and severity assessments be revisited?
Because these estimates are context-dependent and uncertain, they are typically revisited when relevant conditions change, such as shifts in the model's use case, changes in input data or population, model retraining or updates, observed incidents, or new information about potential harms. Many programs also schedule periodic reassessment independent of any triggering event. The specific triggers and cadence depend on the organization's monitoring approach and the requirements of the framework it applies.

Common misconceptions

Likelihood and severity can be collapsed into a single risk score without loss of meaning.
Combining the two into one number can obscure important distinctions, particularly low-likelihood, high-severity scenarios. Many frameworks recommend assessing each dimension separately before any aggregation so that catastrophic-but-rare harms remain visible in prioritization.
A low likelihood of harm means the risk can be deprioritized or accepted.
Low likelihood does not by itself justify acceptance when severity is high or the harm is irreversible or affects vulnerable groups. Severity considerations can warrant controls even where the probability of occurrence is assessed as low.
Likelihood and severity estimates, once documented, remain valid throughout the model's life.
Both dimensions are context- and time-dependent and can shift as data, usage patterns, model behavior, or surrounding controls change. They are typically treated as estimates subject to periodic re-assessment rather than one-time determinations.

Best practices

Assess likelihood and severity as distinct dimensions before combining them, so that high-severity, low-likelihood harms are not masked in an aggregated score.
Document the assumptions, deployment context, and evidence underlying each likelihood and severity estimate, and flag the degree of uncertainty rather than presenting estimates as precise.
Explicitly account for reversibility, duration, affected population size, and impacts on vulnerable groups when characterizing severity.
Re-assess likelihood and severity periodically and after material changes to data, usage, the model, or surrounding controls, since both dimensions are context- and time-dependent.
Use severity considerations to justify controls for high-consequence harms even when likelihood is assessed as low, and record the rationale for any risk acceptance decisions.
Where thresholds or risk-tiering are involved, tie them to the specific framework or jurisdiction being applied and avoid treating a single definition of likelihood or severity as authoritative across all contexts.