Determining Risk Likelihood

About the Author
Michael Is a professionally qualified risk management expert and has many years’ experience supporting, developing and improving effective risk management systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five star rated risks management course.

________________________________________________________________________________________________

When you’ve identified a risk, one of the most important next steps is evaluating risk likelihood – the probability that the risk event will actually occur. This isn’t just a guess; it requires structured techniques, combining data, expert judgment, and context. Here are the main approaches and techniques you can use:

1. Qualitative Techniques

These methods rely on descriptive, relative scales rather than precise numbers. They’re common in risk registers and early-stage assessments.

  • Risk Matrices / Heat Maps
    Plot likelihood against impact using a simple scale (e.g., Rare, Unlikely, Possible, Likely, Almost Certain). Helps visualise and prioritise risks.
  • Ordinal Scales
    Assign scores (1–5, or 1–10) to likelihood. For example, “1 = <5% chance, 5 = >80% chance.”
  • Expert Judgment / Workshops
    Gather input from subject matter experts, frontline staff, or management to calibrate likelihood ratings. Delphi technique (structured expert consensus) is often used to reduce bias.
  • Historical Analogy
    Use past incidents (internal or industry-wide) as indicators of how often similar risks have materialised.

 

 

2. Quantitative Techniques

These approaches use data, statistics, or models to express likelihood as a probability or frequency.

  • Statistical Analysis of Past Data
    Analyse frequency and trends of previous occurrences (e.g., equipment failure rates, past breaches, market fluctuations).
  • Probability Distributions
    Model uncertainty using probability distributions (normal, Poisson, exponential) to represent frequency of risk events.
  • Monte Carlo Simulation
    Run thousands of simulations using probability inputs to estimate the likelihood of different outcomes.
  • Bayesian Analysis
    Update probability estimates as new information emerges (e.g., conditional likelihood if other events happen first).

3. Scenario-Based Techniques

Explore likelihood in the context of specific situations.

  • What-if and Sensitivity Analysis
    Test assumptions about likelihood under different conditions (e.g., what if supply chain disruption doubles?).
  • Fault Tree / Event Tree Analysis
    Break down causes (fault tree) or outcomes (event tree) to quantify probability pathways leading to the risk event.
  • Stress Testing
    Examine how systems or processes respond under extreme but plausible conditions, revealing hidden likelihoods.

________________________________________________________________________________________________

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won’t use your data for anything else.

Sign Up Here:

 

________________________________________________________________________________________________

4. Hybrid and Organisational Techniques

Practical approaches that combine data, judgement, and governance.

  • Likelihood Scoring with Defined Criteria
    Predefine what “rare,” “possible,” or “likely” mean numerically (e.g., Rare = <1 event in 10 years; Likely = >1 event per year). This ensures consistency across the organisation.
  • Risk Indicators / Early Warning Signals
    Use key risk indicators (KRIs) – such as staff turnover, near-miss frequency, or system downtime – to infer rising likelihood before the risk fully materialises.
  • Benchmarking
    Compare risk frequencies with similar organisations or industry standards.

Good practice tip:
Likelihood evaluation should never be a one-off. It’s dynamic — update assessments regularly as new data, incidents, or environmental changes occur. Combining multiple techniques (e.g., expert judgment + historical data + probability modelling) gives a much more reliable estimate than relying on just one.

________________________________________________________________________________________________

Framework for Evaluating Risk Likelihood

Here’s a step-by-step framework you can use (or adapt) for systematically evaluating the likelihood element of an identified risk. It blends qualitative and quantitative methods so it works whether you have rich data or limited information.

Step 1. Define Risk Likelihood Scales

  • Decide whether you’ll use:
    • Qualitative descriptors (e.g., Rare, Unlikely, Possible, Likely, Almost Certain), or
    • Quantitative measures (e.g., % chance, frequency per year).
  • Where possible, give clear definitions for each level. Example:
    • Rare = <1% chance in 10 years
    • Possible = once every 3–5 years
    • Likely = once per year

This avoids inconsistent scoring across different risks or teams.


Step 2. Collect Evidence

Gather all available information about the risk and its drivers:

  • Historical data (internal records, industry reports, regulators, insurers).
  • Expert judgment (workshops, Delphi technique, interviews).
  • Indicators (trends, near misses, precursor events, audit findings).
  • External intelligence (competitor failures, market conditions, geopolitical trends).

Step 3. Analyse Probability

Choose the technique appropriate for the data quality and context:

  • If limited data:
    • Expert judgment with a qualitative scale.
    • Benchmarking against similar risks/events.
  • If moderate data:
    • Frequency analysis (number of past events per time period).
    • Fault Tree or Event Tree mapping to break down causal pathways.
  • If rich data:
    • Probability distributions and Monte Carlo simulation.
    • Bayesian analysis to update likelihood as new information emerges.

Step 4. Assign a Likelihood Rating

  • Map the analysis back to the agreed scale (qualitative or quantitative).
  • Document why you scored it that way (assumptions, data sources, uncertainties).
  • If uncertainty is high, capture a range instead of a single number.

Step 5. Validate the Assessment

  • Cross-check with:
    • Other experts or teams (to avoid bias).
    • Historical incidents (does the rating make sense?).
    • Organisational risk appetite and tolerance levels.

Step 6. Link to Risk Register / Heat Map

  • Record the likelihood score alongside impact in your risk register.
  • Plot on a risk matrix/heat map to visualise and prioritise.

Step 7. Monitor and Review

  • Set review frequency (e.g., quarterly, annually, or after major changes).
  • Track Key Risk Indicators (KRIs) that signal increasing or decreasing likelihood.
  • Update likelihood ratings as new data or incidents emerge.

Quick Example in Practice

  • Risk: Cyberattack disrupting services.
  1. Scale: risk likelihood rated on 1–5 scale (Rare to Almost Certain).
  2. Evidence: Industry shows 30% of peers had incidents in last 12 months; 5 attempted attacks blocked monthly.
  3. Analysis: Based on frequency, “Likely.”
  4. Rating: 4 out of 5 (Likely).
  5. Validation: Confirmed with IT Security lead.
  6. Register: Plotted as High likelihood, High impact.
  7. Review: Quarterly based on attack trends and control upgrades.

________________________________________________________________________________________________

 

Learn About Risk Management

Gain the practical skills you need to identify and manage risk with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

 

 

Five star training testimonial

 

[/su_column][/su_row]

________________________________________________________________________________________________