A score formed by multiplying probability and impact is an expected-value calculation being used as a prioritisation rule, which is correct only for an entity indifferent to variance — and no single project, and few enterprises, are that entity.
Every enterprise that manages risk at scale wants one number. Without it, four hundred entries across a dozen portfolios cannot be sorted, compared or resourced, and risk management becomes a contest between whoever argues most forcefully. The comparable score is what makes governance possible.
But the number that delivers comparability is not neutral. Multiply a probability rating by a consequence rating and the result is an expected value — the average outcome if the same gamble were run many times. Ranking by that product is correct for one kind of decision-maker: one who will face this exposure repeatedly, can absorb any single outcome, and therefore cares only about the long-run mean. Such an agent is indifferent to variance: it does not matter to them whether a loss arrives as a hundred small events or one large one, provided the total is the same.
That is the tension. The instrument needed to govern coherently embeds an assumption about the enterprise's appetite for ruin, and it is rarely the assumption leadership would make if asked. A single project runs once. A regulated operator with one licence faces the licence question once. A firm whose covenants trip at a defined loss does not experience the average; it experiences the draw.
The consequence is not that the scores are technically wrong. It is that the ranking they produce is the one a risk-neutral entity should act on, and the enterprise using it is not risk-neutral. Every allocation made from that ranking moves resources away from the exposures that could end the organisation and towards those that will merely irritate it.
The Strategic Context
The multiplication looks like a scoring convention. It is a decision rule — the one economics reserves for agents indifferent to the shape of a distribution.
Two properties follow, checkable against any matrix. First, the operator equates events no executive would treat as equivalent: a catastrophic consequence at the rarest expressible likelihood scores the same as a trivial one expected several times a year. On a common five-by-five grid both land in one band, and the band prescribes the same action for each.
Second, the operator ranks frequency above severity across most of the grid. A minor consequence occurring almost certainly outscores a major consequence occurring rarely, often by a factor of two. That is not a defect in the arithmetic; it is what expected value means. It becomes a defect only if the enterprise cannot survive the major consequence — in which case its ordering is inverted relative to its own interest.
The discipline's own teaching displays the difficulty without resolving it. Toolkits circulate holding two scoring instruments at once: a worksheet that adds consequence and likelihood, and a register that multiplies them. The guidance states both are valid if applied consistently — then specifies that the additive worksheet feeds the multiplicative register automatically. Consistency is asserted in the same breath as the wiring that defeats it.
A separate strand is equally revealing. It constructs numerical tolerability bands, assigns colours and escalation duties to score ranges, then warns in its own pitfalls that the scores are ordinal, not cardinal, and that a risk scored twenty is not twice as bad as one scored ten. The warning is correct — and it invalidates the bands printed a page earlier, with nothing to reconcile the two.
What Leaders Commonly Misread About the Score
The first misreading is that the choice between adding and multiplying is a matter of house style. The two operators encode different attitudes to the tail and produce different rank orders on identical inputs — systematically, in the region that matters most.
| Event | Likelihood | Consequence | Additive score | Multiplicative score |
|---|---|---|---|---|
| Rare, catastrophic | 1 | 5 | 6 | 5 |
| Unlikely, moderate | 2 | 3 | 5 | 6 |
The additive instrument ranks the catastrophe above the moderate exposure; the multiplicative ranks it below. Same events, same analysts, same judgements — opposite priority, and in most band schemes the scores fall either side of the threshold that determines whether anyone must act.
The second misreading is that the additive operator is the crude one. It is cruder in resolution and more conservative in the tail, because addition never lets a small probability divide a large consequence down to nothing. Neither is right in the abstract. Each is right for a particular attitude to variance, and the enterprise has never stated which it holds.
The third is that the inputs are numbers. They are labels: ordered categories with descriptive text. Multiplying category three by category four yields twelve, which has the arithmetic properties of a number without the meaning of one. The same distortion appears wherever ordinal ratings are multiplied and treated as cardinal — most consequentially in tender evaluation, the province of Article 40 in this collection.
The fourth is that the probabilities are comparable at all. This article takes the two ratings as given and asks only what the operator joining them asserts; what a stated probability is the probability of is examined in [Related article: What Exactly Was the Board Given the Probability Of?].
Reframing the Issue
The useful question is not which operator is more rigorous, but what would have to be true of this enterprise for expected value to be the right way to rank its exposures.
Three things. It would have to face this class of exposure many times, so that averages are realised rather than merely computed. It would have to absorb any single outcome without changing what it is. And it would have to be indifferent between one large loss and many small ones of the same total. Where all three hold, ranking by the product is optimal, and any other rule wastes resources.
Portfolios and large diversified balance sheets often satisfy all three, which is why the technique migrated from insurance and finance into project management. A single project satisfies none. It runs once, most severe outcomes would change what it is, and the difference between one large overrun and many small ones is the difference between a reset and a cancellation.
Consider a hypothetical aquaculture and fisheries operation running several coastal leases. Its register holds many routine entries: equipment failures, feed price movements, labour shortfalls, minor compliance findings. Across a season these behave like a portfolio, and expected value ranks them sensibly. It also holds a few of another kind: a disease incursion across a lease, an algal event in the growing season, a biosecurity finding that closes an export market. These are not portfolio items. Any one can remove a year's production and the balance sheet behind it, and their probabilities are low enough that the product operator places them below a recurring equipment fault.
Run the register through one ranking and the operation resources the equipment fault. That is not negligence. It is the instrument working as designed, on an enterprise for which the design assumption is false.
What the Multiplication Actually Asserts
The claim hidden in the operator
Multiplying probability by impact asserts that the enterprise's disutility is linear in loss — that losing ten units hurts ten times as much as losing one. For any organisation with a solvency constraint, a licence, a covenant, or one obligation it cannot fail, that is false near the top of the range. The curve bends sharply somewhere, and the location of the bend is the most important number in the enterprise's risk profile. It appears on no matrix.
Once the bend is acknowledged, the ranking problem changes shape. Below it, exposures are commensurable and expected value orders them well. Above it they are not exposures to be ranked at all but threats to continuity, and the question is not their score but the probability that any of them, or any combination, crosses the line.
A hypothetical regional airline maintenance planning function shows the shape of it. Its register fills with deferred-defect items — individually minor, moderately likely, easily scored. Beneath them sits a small set of failure modes, airworthiness-critical and rare. The product operator ranks the deferred defects higher, the budget follows the ranking, and the enterprise resources what it can survive at the expense of what it cannot.
Two operators, one toolkit, no decision
An enterprise can defensibly choose either operator. What it cannot do is run both and call the difference a formatting matter. Yet that is the common condition: an additive worksheet at the analyst's desk, a multiplicative register at the committee, automated transfer between them, and a governance statement asserting consistency.
The rank order presented to leadership is therefore an artefact of whichever instrument produced the final column. Nobody chose it, and nobody can name who did. Because both instruments carry the same band labels — Low, Medium, High — the substitution is invisible in the report.
Where the ranking is re-made without notice
Scores move. A treatment is implemented, a probability revised, a consequence re-scoped, and the ordering changes. In most enterprises the previous ordering is overwritten, so no one can see that an exposure sat above the action threshold for three quarters and then dropped below it without anything happening in the world. What that overwriting habit does to the record of commitments when a baseline is reset is a larger problem, examined in [Related article: Re-Baselining Erases the Record of Every Promise You Broke].
There is a matching gap at the other end of the scale. How the operator behaves as probability approaches certainty is often moot, because near-certain items are reclassified out of the register as issues before they are scored. That expulsion mechanism, and what it does to forward planning, is owned by [Related article: Where Do Your Near-Certainties Go?].
Decision Framework
The variance-tolerance question. Before a register is used to allocate money or attention, the enterprise answers one question in writing, and acts on the answer.
Would we accept this exposure repeatedly, at these odds, for this stake?
If yes, expected value is the correct rule and the product may stand. If no — if a single realisation would change what the organisation is — it is the wrong rule, and the entry leaves the ranked list.
Four steps make this runnable.
1. Fix the ruin threshold. Name the loss level, in the enterprise's own units, beyond which it cannot continue as presently constituted: capital exhaustion, covenant breach, licence withdrawal, loss of a single market, failure of an obligation with no substitute. One number, board-approved, reviewed annually.
2. Split the register. Classify every entry by whether its plausible severe outcome could cross that threshold. Two lists result. Do not merge them, rank across them, or give them a common colour scheme.
3. Rank each list by its own rule. The survivable list is ranked by expected value; state that operator and its warrant at the head of it. The threshold-crossing list is not ranked by score. It is ordered by the probability of crossing, and every entry requires a response irrespective of position.
4. Declare the operator. Every register states on its face which operator produced its scores, who approved that choice, and when. Where two instruments feed one another, the declaration names both and the enterprise picks one.
Three failure conditions. The merged list: one ranked register holding both survivable and threshold-crossing exposures applies an expected-value rule to a decision that is not an expected-value decision. The undeclared operator: a register whose arithmetic cannot be named by the person presenting it. The retrofitted band: boundaries chosen after the scores, which turns the instrument into a device for confirming a conclusion already reached.
From Strategy to Execution
Immediate — this cycle. Establish which operator each register actually uses, including those inherited through subsidiaries, joint ventures and major suppliers. Expect more than one, and expect the difference to be undocumented. Then set the ruin threshold; the argument required to agree it is the most valuable output of the exercise.
Medium-term — the next two reporting cycles. Split the two largest registers against the threshold and present the lists separately to the board, in different formats so they cannot be read as one. Retire any band scheme whose boundaries cannot be traced to a decision. Where an entry crosses the threshold, require a written note of what changed.
Long-term — the next framework revision. Write the variance-tolerance question into the risk policy as a precondition for ranking, not a commentary on it. Over time this changes what the risk committee does: it stops adjudicating scores and starts adjudicating which exposures belong in the ranked world.
Signals to Monitor
A register in which the highest-consequence entries never appear in the top ten by score. Band thresholds adjusted after a scoring round. Two instruments in use with automated transfer between them. Risk reports where the arithmetic is not stated. Treatment budgets concentrated on frequent, moderate exposures while severe entries carry monitoring only. Any exposure described in prose as potentially terminal and in the table as medium.
Questions for the Leadership Team
- What loss would change what this organisation is, as a number, and when did the board last approve it?
- Which operator produces the scores in our principal register, who chose it, and on what ground?
- Do we run more than one scoring instrument, and what happens to the ranking when a risk passes between them?
- Of our ten largest treatment budgets, how many address exposures that could cross that threshold?
- Where did our tolerability band boundaries come from, and were they set before or after the first scores?
- If our most severe exposure occurred once, would we call the outcome a bad draw from an acceptable gamble, or a decision we should never have made?
Closing Perspective
The multiplication is not a mistake. It is a well-founded rule imported from a setting where its assumptions hold, and applied where they do not, by people never told the assumptions existed. That is a governance failure rather than an analytical one, and it is corrected by a declaration rather than a model.
What leadership carries is a responsibility that cannot be delegated to the risk function: to say, before the next allocation round, which exposures it will treat as gambles it can run many times and which it must survive on the single occasion. Every instrument in use answers that question already. The only choice is whether the answer is the enterprise's or the template's.
About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.
