Ratings and severity
Inherent and residual ratings, the five-level severity scale, and how to apply them consistently.
RiskCurb rates every risk twice: inherent and residual. Both use the same five-level severity scale, so the two ratings sit side by side and stay comparable.
The five-level severity scale
Likelihood and impact are each scored on a five-level scale, from Low through Critical. The combined score produces the risk's severity. Each level carries a dedicated accessible color, and severity language always pairs the level name, such as High or Critical, with its color. Color never carries the meaning alone.
| Level | Typical frequency | Typical impact | Chip reads |
|---|---|---|---|
| 1. Low | Rare. Not expected inside a normal review cycle. | Negligible. Absorbed in day-to-day operations. | Low, Green |
| 2. Moderate | Unlikely. Could appear over several review cycles. | Minor. Handled with local resources. | Moderate, Yellow |
| 3. High | Possible. Expected within the annual cycle. | Significant. Needs a named owner and planned treatment. | High, Amber |
| 4. Very High | Likely. Expected to recur without intervention. | Major. Escalated to leadership with a treatment deadline. | Very High, Red |
| 5. Critical | Almost certain. Occurring or imminent without intervention. | Severe. Threatens the objective or the service itself. | Critical, Deep red |
Using one scale across the register is what makes exposure comparable. A High in parks and a High in IT mean the same thing to the board.
Inherent rating
Inherent rating describes the exposure before controls are considered: if nothing were done about this risk, how likely is it and how bad is the outcome. Rate inherent first, and rate it honestly. It is the baseline every treatment is measured against.
Residual rating
Residual rating describes the exposure with current controls and treatments in place. Owners update it as treatment work completes, so the register reflects the work actually done, not the work promised.
The gap between inherent and residual is the value of your control environment. When leadership asks what the risk function delivers, that gap is part of the answer.
Review discipline
Ratings drift when they are only revisited at annual review. Two habits keep them honest:
- Update residual rating when a treatment closes, not at the next cycle.
- Re-rate inherent exposure when the environment changes, for example after a major incident or an organizational shift.
If a risk's residual rating has not moved in several cycles while its treatments sit overdue, treat that as a review flag in itself.