One manager rates the incident as serious. Another sees a similar case as moderate. Both decisions feel reasonable, but the safeguarding system now has two different responses to the same level of risk.
If severity ratings are inconsistent, serious incident governance cannot guarantee equal protection or reliable escalation.
This is a fundamental issue in serious incident governance. Severity ratings shape who is informed, how quickly action happens, what evidence is preserved, and whether root cause review is required.
Severity decisions also need to align with wider adult safeguarding frameworks, because inconsistent thresholds can create unequal responses to harm, neglect, abuse risk, or repeated vulnerability. Across the Safeguarding Systems & Risk Governance Knowledge Hub, a severity framework should make safeguarding response predictable, defensible, and auditable.
This is where judgement needs a shared standard.
Why severity decisions drift
Severity drift usually happens when managers rely on experience rather than a shared framework. One person focuses on actual harm. Another focuses on potential harm. A third weighs reputational risk, family concern, or regulatory exposure.
All of those factors may matter, but they need to be applied consistently. Without a common severity framework, similar incidents can trigger different responses, and governance may not see the true pattern of serious risk.
A strong framework defines severity by impact, likelihood, vulnerability, recurrence, safeguarding concern, and system failure potential.
Standardising severity at first review
A provider identifies inconsistent ratings across three services. Similar medication omissions involving vulnerable adults were rated differently, leading to different escalation routes.
The safeguarding lead introduces a first-review severity tool. Required fields must include: actual harm, potential harm, person vulnerability, safeguarding concern, recurrence history, immediate protection action, and escalation requirement.
The rating cannot proceed without: a recorded rationale showing how each severity factor was considered.
Where uncertainty remains, the incident is rated at the higher provisional level until senior safeguarding review confirms the final classification.
Auditable validation must confirm: similar incidents receive consistent severity ratings or documented rationale for different classification.
This reduces reliance on individual interpretation during pressure.
Separating actual harm from potential harm
One of the most common rating failures is underestimating potential harm because the immediate outcome was less severe than it could have been.
A person is left without essential support for a period, but no visible injury occurs. The local manager initially rates the incident as low impact because harm was not confirmed.
The severity framework requires a different analysis:
- What could reasonably have happened?
- Was the person unable to protect themselves?
- Did the incident expose a failed control?
- Could the same failure cause serious harm next time?
The rating changes because potential harm and vulnerability were not adequately considered.
This is where severity decisions must look beyond outcome alone.
Required fields must include: actual outcome, credible worst-case outcome, vulnerability factors, protective controls, and recurrence risk.
Cannot proceed without: explicit consideration of potential harm where the person was dependent on staff, systems, or timely intervention.
Auditable validation must confirm: severity ratings account for potential harm and do not rely only on visible injury or immediate outcome.
Using severity ratings to trigger root cause review
Severity frameworks should not only label incidents. They should trigger the correct governance response.
A provider links severity ratings to review requirements. High-severity incidents automatically require root cause analysis, senior safeguarding oversight, evidence preservation, and action validation.
Required fields must include: severity rating, review level required, safeguarding lead assigned, evidence owner, action owner, and governance reporting route.
The incident cannot remain at local review level without: senior approval where severity indicators suggest serious harm, repeated failure, or major control weakness.
Auditable validation must confirm: severity ratings consistently trigger the correct level of investigation, escalation, and governance oversight.
This ensures classification changes the response, not just the label.
Governance expectations for severity consistency
Safeguarding governance should expect regular testing of severity decisions. This means sampling incidents across services, comparing similar events, reviewing classification rationale, and checking whether escalation followed the rating.
Useful assurance includes severity audit samples, rating calibration sessions, decision logs, senior review records, root cause triggers, and evidence that inconsistent ratings are corrected and learned from.
Where ratings vary without defensible rationale, governance should treat that as a system risk.
What strong evidence looks like
Strong evidence shows how the rating was reached. It should identify the factors considered, the rationale applied, who reviewed the rating, what escalation followed, and whether the classification matched provider thresholds.
For serious incident governance, severity evidence should make the response easy to defend: why this incident was serious, why another was not, and how the provider ensured consistency.
Conclusion
Severity ratings are not administrative labels. They determine safeguarding urgency, investigation depth, evidence controls, senior oversight, and root cause expectations.
The strongest providers standardise severity decisions so similar risks receive similar responses. They use clear factors, provisional higher ratings where uncertainty exists, and governance sampling to maintain consistency.
Without standardised severity thresholds, serious incident governance can depend too heavily on who reviews the incident rather than what the risk requires.