________________________________________________________________________________________________
When you’ve identified a risk, one of the most important next steps is evaluating risk likelihood – the probability that the risk event will actually occur. This isn’t just a guess; it requires structured techniques, combining data, expert judgment, and context. Here are the main approaches and techniques you can use:
1. Qualitative Techniques
These methods rely on descriptive, relative scales rather than precise numbers. They’re common in risk registers and early-stage assessments.
- Risk Matrices / Heat Maps
Plot likelihood against impact using a simple scale (e.g., Rare, Unlikely, Possible, Likely, Almost Certain). Helps visualise and prioritise risks. - Ordinal Scales
Assign scores (1–5, or 1–10) to likelihood. For example, “1 = <5% chance, 5 = >80% chance.” - Expert Judgment / Workshops
Gather input from subject matter experts, frontline staff, or management to calibrate likelihood ratings. Delphi technique (structured expert consensus) is often used to reduce bias. - Historical Analogy
Use past incidents (internal or industry-wide) as indicators of how often similar risks have materialised.

2. Quantitative Techniques
These approaches use data, statistics, or models to express likelihood as a probability or frequency.
- Statistical Analysis of Past Data
Analyse frequency and trends of previous occurrences (e.g., equipment failure rates, past breaches, market fluctuations). - Probability Distributions
Model uncertainty using probability distributions (normal, Poisson, exponential) to represent frequency of risk events. - Monte Carlo Simulation
Run thousands of simulations using probability inputs to estimate the likelihood of different outcomes. - Bayesian Analysis
Update probability estimates as new information emerges (e.g., conditional likelihood if other events happen first).
3. Scenario-Based Techniques
Explore likelihood in the context of specific situations.
- What-if and Sensitivity Analysis
Test assumptions about likelihood under different conditions (e.g., what if supply chain disruption doubles?). - Fault Tree / Event Tree Analysis
Break down causes (fault tree) or outcomes (event tree) to quantify probability pathways leading to the risk event. - Stress Testing
Examine how systems or processes respond under extreme but plausible conditions, revealing hidden likelihoods.
________________________________________________________________________________________________
Sign Up Here:
________________________________________________________________________________________________
4. Hybrid and Organisational Techniques
Practical approaches that combine data, judgement, and governance.
- Likelihood Scoring with Defined Criteria
Predefine what “rare,” “possible,” or “likely” mean numerically (e.g., Rare = <1 event in 10 years; Likely = >1 event per year). This ensures consistency across the organisation. - Risk Indicators / Early Warning Signals
Use key risk indicators (KRIs) – such as staff turnover, near-miss frequency, or system downtime – to infer rising likelihood before the risk fully materialises. - Benchmarking
Compare risk frequencies with similar organisations or industry standards.
✅ Good practice tip:
Likelihood evaluation should never be a one-off. It’s dynamic — update assessments regularly as new data, incidents, or environmental changes occur. Combining multiple techniques (e.g., expert judgment + historical data + probability modelling) gives a much more reliable estimate than relying on just one.
________________________________________________________________________________________________
Framework for Evaluating Risk Likelihood
Here’s a step-by-step framework you can use (or adapt) for systematically evaluating the likelihood element of an identified risk. It blends qualitative and quantitative methods so it works whether you have rich data or limited information.
Step 1. Define Risk Likelihood Scales
- Decide whether you’ll use:
- Qualitative descriptors (e.g., Rare, Unlikely, Possible, Likely, Almost Certain), or
- Quantitative measures (e.g., % chance, frequency per year).
- Where possible, give clear definitions for each level. Example:
- Rare = <1% chance in 10 years
- Possible = once every 3–5 years
- Likely = once per year
This avoids inconsistent scoring across different risks or teams.
Step 2. Collect Evidence
Gather all available information about the risk and its drivers:
- Historical data (internal records, industry reports, regulators, insurers).
- Expert judgment (workshops, Delphi technique, interviews).
- Indicators (trends, near misses, precursor events, audit findings).
- External intelligence (competitor failures, market conditions, geopolitical trends).
Step 3. Analyse Probability
Choose the technique appropriate for the data quality and context:
- If limited data:
- Expert judgment with a qualitative scale.
- Benchmarking against similar risks/events.
- If moderate data:
- Frequency analysis (number of past events per time period).
- Fault Tree or Event Tree mapping to break down causal pathways.
- If rich data:
- Probability distributions and Monte Carlo simulation.
- Bayesian analysis to update likelihood as new information emerges.
Step 4. Assign a Likelihood Rating
- Map the analysis back to the agreed scale (qualitative or quantitative).
- Document why you scored it that way (assumptions, data sources, uncertainties).
- If uncertainty is high, capture a range instead of a single number.
Step 5. Validate the Assessment
- Cross-check with:
- Other experts or teams (to avoid bias).
- Historical incidents (does the rating make sense?).
- Organisational risk appetite and tolerance levels.
Step 6. Link to Risk Register / Heat Map
- Record the likelihood score alongside impact in your risk register.
- Plot on a risk matrix/heat map to visualise and prioritise.
Step 7. Monitor and Review
- Set review frequency (e.g., quarterly, annually, or after major changes).
- Track Key Risk Indicators (KRIs) that signal increasing or decreasing likelihood.
- Update likelihood ratings as new data or incidents emerge.
✅ Quick Example in Practice
- Risk: Cyberattack disrupting services.
- Scale: risk likelihood rated on 1–5 scale (Rare to Almost Certain).
- Evidence: Industry shows 30% of peers had incidents in last 12 months; 5 attempted attacks blocked monthly.
- Analysis: Based on frequency, “Likely.”
- Rating: 4 out of 5 (Likely).
- Validation: Confirmed with IT Security lead.
- Register: Plotted as High likelihood, High impact.
- Review: Quarterly based on attack trends and control upgrades.
________________________________________________________________________________________________
Gain the practical skills you need to identify and manage risk with this five-star rated training course.
Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.


Rated 4.8 out of 5 on Trustpilot
________________________________________________________________________________________________
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: