What it means
A quality control fails to catch an incorrect label, and the operational impact may be a reprint, a customer complaint or a serious safety issue, depending on the product. Control failure severity rating classifies the consequence under an agreed scale so teams know what needs urgent review.
ASQ discusses severity as part of failure-mode analysis and COSO's enterprise risk material describes assessing risk in relation to objectives, but a local severity rating should not be presented as a universal legal or safety classification. Define the control and know what failure it was meant to prevent or detect, because a vague "process failed" label hides the consequence.
Identify the failure by recording whether the control was absent, bypassed, late or ineffective, since different causes need different remedies, and describe the outcome by noting actual harm and credible potential harm separately, because a near miss can warrant high priority even when no loss occurred. Use a common scale with each level defined in plain language, such as minor rework, material financial loss or safety risk, and avoid numbers without anchors.
Rate impact, not blame, since severity concerns consequences for customers, people, finances, compliance or operations and not how hard an employee tried. Keep likelihood and detection separate: a rare catastrophic impact may still require action, so do not lower severity merely because the event seems unlikely, and finding a failure early can reduce actual harm while the potential consequence of an escaped failure may remain high.
Use evidence such as customer reports, defect records, downtime and confirmed costs, and mark unknowns for investigation. Review worst credible cases, because a wildly imagined disaster is not a sound basis but neither is assuming the best outcome in every instance.
Consider regulatory duties as well, since specific industries and countries may mandate notification or classification rules that a company score cannot replace. Check timing, scope and secondary effects: a payroll control failure before payday may be correctable while the same failure after a missed legal deadline has a different impact, a one-customer mistake differs from a system defect affecting all accounts, and a small data-entry error can trigger customer refunds or a reporting restatement.
Include recoverability, because a reversible internal mistake can differ from an irreversible disclosure or safety incident even if direct cost is similar, and distinguish potential from realised cost, since a risk rating is not a booked loss amount and finance should account for actual obligations separately. Define escalation so that higher levels specify who is informed and by when, and preserve independence by having someone outside the failing process review the evidence where stakes are high.
Avoid score gaming, because making a failure "low" to protect a dashboard creates risk, so compare ratings with objective criteria and past cases, and review repeated failures because many low-severity failures can create a material pattern and signal weak control design. Link severity to corrective action, since severity guides triage while root cause and action effectiveness determine the lasting fix, and compare functions fairly, as a warehouse defect and a privacy breach require different subject expertise and one broad scale may need specialist subcriteria.
Document the decision with event date, evidence, rating rationale, reviewer and any change as facts emerge, preserving the first assessment and why it changed; for an owner, severity rating helps decide what merits immediate attention and is credible only when the scale is explicit and high-consequence cases are not washed out by a composite score.
In practice
Real-world examples.
Example
A failed label check causes a reprint before shipment, a lower actual impact than a harmful customer delivery. The team still records what would have happened had the labels shipped.
Example
A payment approval bypass exposes a material account even if no money ultimately leaves it. The rating reflects the credible potential loss, and finance separately records that no actual loss was booked.
Example
Repeated minor inventory-control misses are reviewed as a pattern rather than dismissed individually. The pattern points to a design weakness that a single-incident rating would miss.
Formula
Calculation
Illustrative five-level scale: 1 = local rework with no customer impact; 2 = minor customer inconvenience, corrected quickly; 3 = material financial loss or regulatory query that can be recovered; 4 = significant loss or customer harm; 5 = credible severe safety, legal or irreversible impact. The anchors are examples and require sector-specific design. Do not multiply a high-severity score away through low frequency.
Worked example. An invented team logs 10 control failures in a quarter: nine at level 1 and one at level 5.
- The simple average severity = (9 x 1 + 1 x 5) / 10 = 14 / 10 = 1.4, which looks low.
- The maximum severity is 5, and that single failure needs escalation, root-cause analysis and independent review.
This is why the highest credible severity, not the average, should drive escalation.Case study
Seen in the real world.
This entirely fictional example follows Brook Foods. A barcode check was bypassed on a batch with a possible allergen-label mismatch. No goods had shipped, but the quality lead rated the credible escape consequence high and escalated testing. The team preserved the initial rating and later evidence rather than reporting "no harm" as proof the control was sound. The case does not establish food-safety obligations for any jurisdiction.
Watch out
Common mistakes.
- Lowering severity just because a failure was detected before harm this time.
- Using a number without written impact anchors or evidence.
- Treating a risk rating as the same thing as an actual financial loss.
Questions
People also ask.
Is severity the same as likelihood?
No. Severity describes consequence; likelihood describes chance of occurrence.
Can a near miss be severe?
Yes. Credible potential harm may be high even if actual harm was avoided.
Does the rating itself fix the problem?
No. Investigate causes, implement controls and verify their effectiveness.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
