Not every incident deserves the same response.
A minor procedural issue and an incident with serious legal, financial, safety, or reputational consequences may enter the same case management process — but treating them with the same urgency creates an obvious problem.
Teams need a consistent way to distinguish between cases that can follow a standard investigation path and cases that require immediate attention.
Ethicontrol’s Incident Impact gives organisations a configurable severity attribute that can become part of the wider case management process — from prioritisation and scoring to notifications and automated workflows.
Why case severity needs structure
Investigators usually understand quickly that some cases are more serious than others.
The problem is turning that judgement into structured information that can be used consistently across the organisation.
Without a defined impact model:
- similar incidents may be prioritised differently;
- high-risk cases can remain mixed with routine cases;
- investigators may rely on free-text descriptions to communicate urgency;
- reporting becomes harder to compare;
- workflows cannot easily react to changes in severity.
Incident Impact turns severity into a standardised case attribute rather than leaving it only in the investigator’s interpretation.
What is Incident Impact?
Incident Impact is a configurable value that describes the potential or confirmed consequences of an incident.
An organisation can define its own impact scale. For example:
| Impact level | Typical meaning |
|---|---|
| Undefined | Impact has not yet been assessed |
| No consequences | No material consequences identified |
| Minor | Limited consequences |
| Significant | Meaningful organisational impact |
| Critical | Serious consequences requiring increased attention |
| Catastrophic | The highest configured level of impact |
The exact levels, names, and logic depend on the organisation’s Incident Impact dictionary.
This gives teams a common language for expressing severity across cases.
Impact can evolve as the investigation progresses
The initial report rarely contains every fact.
An incident that appears minor during intake may become significantly more serious once investigators understand the financial loss, affected people, regulatory exposure, or operational consequences.
For that reason, authorised users can update Incident Impact as new information becomes available.
For example:
Minor → Significant → Critical
The current value remains visible in the case, and changes are recorded in the activity history.
This makes impact a living assessment rather than a fixed label assigned at intake.
Want to learn more about Incident Impact?
Visit our Help Center for step-by-step guidance on viewing, updating, and working with Incident Impact.
From category to impact
Incident Impact does not always need to be assessed manually.
Ethicontrol can use the selected case category or subcategory as input to a custom rules matrix.
When a user selects or changes the classification, the system can apply the configured rule and automatically assign the corresponding impact.
For example:
A user changes the case sub-category to a high-risk violation
→ the configured rules matrix updates Incident Impact to Critical.
This creates an important connection between what happened and how seriously the organisation should treat it.
Instead of asking users to classify and prioritise the same incident independently, the taxonomy can help drive a consistent impact assessment.
Incident Impact as part of the wider case management process
The value of Incident Impact increases when other processes can use it.
Case prioritisation
Impact gives case managers an immediate severity signal.
Instead of relying only on the report description, teams can distinguish routine cases from incidents that may require faster review, escalation, or additional oversight.
Violation scoring and risk profiling
Incident Impact can also contribute to the calculation of a person’s violation score.
![]()
In Ethicontrol’s scoring model, Impact / Severity score can be combined with factors such as:
- violation sub-category;
- position grade severity;
- recurrence;
- other configured scoring values.
This means two violations within the same sub-category can contribute differently to the risk profile if their consequences are different.
For example, the same type of policy breach may result in a lower score when its impact is limited and a higher score when it creates serious organisational exposure.
Want to see how scoring works?
Learn how violation sub-categories, incident impact, position severity, and recurrence work together to calculate risk scores.
Automated notifications
Impact can also become a trigger for communication.
When a rule changes an incident to a specified impact level — for example Critical — Ethicontrol can automatically send a notification using a dedicated email template to selected roles such as the Case Manager.
This helps high-priority incidents reach the right people without relying on someone to notice the updated field and manually escalate the case.
Reporting and auditability
Because Incident Impact is structured data, it can provide additional context for reporting and case review.
![]()
Changes are also recorded in the case activity history, helping authorised users understand how the severity assessment developed during the investigation.
What this changes for case management teams
More consistent prioritisation |
Faster escalation |
|
| A shared impact scale gives teams a common way to distinguish routine incidents from high-severity cases. | Configured rules and notifications can surface critical cases to the appropriate roles more quickly. |
![]()
Better risk context
Incident severity can become part of the wider violation scoring and risk profiling model.
Less duplicated assessment |
A clearer case history |
|
| Category and sub-category mappings can help determine impact instead of requiring users to classify and assess the same incident independently. | Changes in severity remain visible as the investigation develops, providing additional context for later review. |
From severity label to workflow signal
Incident Impact starts as a simple case attribute, but it can do more than describe how serious an incident is.
When connected with case classification, scoring, notifications, workflows, and audit history, it becomes a structured signal that other parts of the case management process can use.
That helps organisations move from “this case looks serious” to a process where severity is recorded, traceable, and capable of driving the appropriate response.