Risk Assessment: Likelihood, Impact & Detectability
The biggest misconception about risk assessment is that the most likely risk is automatically the most dangerous. In real operations, the risk that hurts you is often the one that is severe and invisible until it is too late - a compliance lapse, a quality defect, a cyber breach, or a single-source supplier failure.
- Risk assessment ranks uncertainty so managers can decide what to prevent, monitor, transfer or accept.
- The three interview-critical dimensions are likelihood - will it happen, impact - how badly will it hurt, and detectability - how early can we spot it.
- A useful shortcut is RPN = Likelihood × Impact × Detectability. Higher RPN means higher priority, but never ignore a high-impact risk just because likelihood is low.
- Detectability is the forgotten dimension. A moderate-likelihood risk with poor detection can be more dangerous than a frequent but visible risk.
- Good assessment separates inherent risk before controls from residual risk after controls.
- The best answer links scoring to action: reduce likelihood, reduce impact, improve detection, or accept the risk within appetite.
Big Picture: Risk Assessment Is a Decision Loop, Not a One-Time Table
Think of risk assessment as a loop that keeps converting uncertainty into managerial action. You identify what can go wrong, score it, choose controls, monitor early signals, and then update the score as the business changes.
Core Explanation: The Three Questions Every Risk Score Must Answer
A risk becomes decision-ready only when you can answer three questions clearly.
- Likelihood: How probable is the event? For example, will a supplier miss delivery, will demand spike, or will a regulatory issue occur?
- Impact: If it occurs, what is the consequence? Impact may be financial loss, customer disruption, safety damage, compliance penalty, or reputational harm.
- Detectability: How likely are we to detect the problem before it causes harm? This is where many candidates give shallow answers.
In many operational and procurement situations, these are scored on a 1-5 or 1-10 scale. A higher likelihood score means the event is more probable. A higher impact score means the consequence is more severe. A higher detectability score usually means the risk is harder to detect - so it is worse.
The Simple Scoring Logic: From Risk Register to Risk Priority
The practical tool most students should remember is the Risk Priority Number, commonly used in Failure Mode and Effects Analysis.
RPN = Likelihood × Impact × Detectability
If a manufacturing defect has likelihood 4, impact 5 and detectability 3 on a 1-5 scale, its RPN is 60. If another defect has likelihood 5, impact 2 and detectability 1, its RPN is 10. The first defect deserves more attention because it is severe and harder to catch, even though it is not the most frequent.
RPN is a prioritisation aid, not a moral law. A safety, legal or brand-destroying risk may need escalation even if its calculated RPN is not the highest.
Worked Example: Scoring a Supplier Delay Risk
Suppose an electronics company buys a critical chip from a single supplier. The team uses a 1-5 scale where 5 is worst.
The right recommendation is not simply “find another supplier.” A stronger answer is: qualify a second source, increase visibility through supplier scorecards, create a small buffer for critical parts, and agree escalation triggers in the contract. If you want to revise how supplier scorecards convert risk into measurable signals, the natural next step is Supplier Selection, Scorecards & Evaluation.
How to Read a Likelihood-Impact Matrix
The classic matrix helps managers separate noise from danger. Low-likelihood, low-impact risks can often be accepted. High-likelihood, high-impact risks need immediate mitigation. The tricky zone is low-likelihood but high-impact - for example, a cyberattack, plant shutdown, product recall, or regulatory ban.
Metrics to Track: Make the Assessment Measurable
Risk assessment fails when it stays as adjectives - “high”, “medium”, “low.” Use a small set of measures that connect scoring to action.
Definitions You Can Say in One Breath
- Risk: “Effect of uncertainty on objectives” - ISO 31000 risk management.
- Risk assessment: The process of identifying, analysing and evaluating risks to support decisions.
- Likelihood: The chance that a risk event will occur within a defined time horizon.
- Impact: The consequence of a risk event on cost, service, safety, compliance, reputation or strategy.
- Detectability: The ability to discover a risk early enough to prevent or reduce damage.
Case Study: Paytm Payments Bank and the Cost of Weak Detectability
Paytm Payments Bank shows why compliance risks must be assessed not only by likelihood and impact, but also by how early leadership can detect and correct control weaknesses.

Situation: Payments banks operate in a highly regulated environment where customer onboarding, wallet balances, KYC, merchant flows and operational controls must meet strict supervisory expectations. For a payments business, regulatory risk has very high impact because customer trust, transaction continuity and partner confidence are all at stake.
The move by the regulator: On 31 January 2024, the Reserve Bank of India placed business restrictions on Paytm Payments Bank, including restrictions on accepting fresh deposits or top-ups after the specified deadline, citing supervisory concerns (RBI press release, 31 January 2024).
How to read it through likelihood-impact-detectability: The impact was clearly high because regulated payment services depend on uninterrupted customer and merchant confidence. The important interview insight is detectability: compliance weaknesses may exist for some time inside process exceptions, KYC gaps, system controls, audit findings or escalation delays before they become a public regulatory action.
Outcome and lesson: The primary driver of the crisis was regulatory compliance risk. Supporting drivers included operating complexity at scale, dependence on regulated infrastructure, customer-facing trust sensitivity and the need for rapid partner-level response. The strategic lesson is simple: if impact is high and detectability is weak, the risk deserves senior attention even before probability looks alarming.
How AI Changes Risk Assessment: Likelihood, Impact and Detectability
AI does not remove risk judgment. It improves the speed and breadth of signals available to managers - especially for likelihood estimation and early detection.
- Earlier warning signals: Machine learning can scan supplier delivery patterns, quality deviations, payment delays, contract clauses, customer complaints and news signals to flag rising risk before a monthly review catches it.
- Better detectability through anomaly detection: AI models can identify unusual transactions, process exceptions, demand spikes or equipment behaviour that humans may miss in large datasets.
- Scenario generation: GenAI can help teams create plausible “what if” scenarios - supplier shutdown, port delay, regulatory inspection, cyber incident - and stress-test the current risk register.
A practical student workflow: load a company annual report, risk section, supplier notes and recent news into NotebookLM, then ask: “List the top operational risks, score each on likelihood-impact-detectability, and show what evidence supports each score.” For procurement-heavy cases, pair this with Supplier Risk, Compliance & Responsible Sourcing to connect risk scoring with supplier governance.
AI can flag patterns, but it can also over-rank risks that have more data and under-rank rare catastrophic risks. Human judgment is still needed for impact, ethics, regulation and risk appetite.
Interview Relevance
“Suppose you are assessing supplier risk for a critical component. How would you evaluate and prioritise the risks?”
In interviews, say “inherent risk first, residual risk after controls.” That one phrase shows maturity because it connects assessment to action.
Common Mistake
The biggest mistake is ranking risks only by likelihood. It costs candidates because they miss rare but business-critical failures - the risks leaders actually lose sleep over. One-line fix: always answer in the sequence likelihood, impact, detectability, then mitigation.