Audit Finding Severity
Calculate severity from Likelihood and Impact.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Calculate finding severity
Audit and risk findings need a severity rating to prioritise them, and consistency matters. This calculator computes severity from likelihood and impact, so findings are rated the same way every time rather than by gut feel.
Why likelihood times impact
The severity of a risk or finding comes from two things: how likely it is to occur, and how bad it would be if it did. Combining them, typically by multiplying or mapping to a matrix, produces a severity that reflects both, so a rare catastrophe and a frequent nuisance are rated sensibly relative to each other. Rating consistently this way prevents the common failure of prioritising by whoever is loudest, and it produces ratings everyone understands. It is the standard basis for triaging findings so effort goes to what matters most.
A tool, not legal advice
It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input describes your security or compliance posture.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
How is severity calculated?
By combining likelihood, how probable the issue is, with impact, how bad it would be, typically multiplying them or mapping to a risk matrix.
Why combine likelihood and impact?
Because severity depends on both. A rare catastrophe and a frequent nuisance need rating sensibly relative to each other, which one factor alone cannot do.
Why does consistent rating matter?
Because it prevents prioritising by whoever is loudest and produces ratings everyone understands, so effort goes to the genuinely important findings.
What is a risk matrix?
A grid combining likelihood and impact levels into a severity, a common way to rate findings consistently, which the calculator applies.
Is my input uploaded?
No. The calculation runs entirely in your browser.
Privacy & Security
Processed locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.