Back to blog
Risk ModelMethodologyTravel RiskThreat Intelligence

The Event Happened. Is It Still Dangerous?

Part 2 of Inside the Risk Model: why ShadowIQ's likelihood axis asks whether a hazard is still live — not whether the event occurred — and why that distinction kills a whole class of false alarms.

July 15, 2026ShadowIQ Risk Intelligence Team

Here is the single most common way a travel risk score goes wrong: an event is confirmed, so the tool marks it high likelihood. A shooting definitely happened, therefore the risk must be high.

That reasoning is wrong, and correcting it is one of the sharpest distinctions in the ShadowIQ model.

This is Part 2 of Inside the Risk Model. Part 1 covered consequence — how bad an event could be. This post is likelihood — and the first thing to say is what likelihood is not.

Likelihood is not "did it happen"

An event happening is a fact about the past. Likelihood, in a risk model, is a question about the future: is this hazard still active and dangerous in the days ahead?

Those come apart constantly:

  • A protest that has dispersed definitely happened. There is nothing left to walk into. Low likelihood.
  • An earthquake that struck yesterday with no ongoing damage is 100% confirmed. The ground is still now. Low likelihood.
  • A road accident happened — to someone else, and it's cleared. It does not threaten your traveller at all. Low likelihood.
  • An active, spreading wildfire or an unfolding security situation is dangerous precisely because the hazard is still ahead of you. High likelihood.

ShadowIQ scores likelihood as the forward question: how likely is the hazard still live and dangerous in its own area over the coming days? A confirmed, severe, but already-resolved event scores low — because for a traveller planning their week, a hazard that's over carries little forward risk, no matter how dramatic the headline.

"But it was severe!"

A natural objection: surely a catastrophic event should score high on something? It does — on consequence (Part 1). Severity is a different axis. We deliberately do not let severity raise likelihood, because that's the exact double-count that inflates every confirmed, serious, finished event into a false alarm. How bad it could be and how likely it still is are two questions, scored on two dials.

The vocabulary we use

Rather than a false-precision percentage, ShadowIQ expresses likelihood in the standardised vocabulary used across the intelligence community (the ICD 203 analytic standard): a ladder from almost no chance, through unlikely and roughly even chance, up to very likely and almost certain. A defined ladder means "likely" means the same thing on every alert, rather than being one analyst's gut feel dressed up as a number.

Where "did it really happen?" goes

If likelihood isn't "did it happen," where does that question live? On a separate axis: confidence (source reliability and corroboration — a later post). This separation is a formal principle in intelligence analysis: never blend probability about the world with certainty about your information. A rock-solid report of a finished event is high confidence, low likelihood. A shaky rumour of an unfolding one is low confidence, potentially high likelihood. Collapsing those into one number destroys both.

Why it matters to you

When ShadowIQ scores an alert low likelihood, it is not saying the event didn't happen or wasn't serious. It is saying: the hazard is behind you, not ahead of you. That's the difference between a tool that keeps pinging you about yesterday's news and one that tells you what's actually still in your path.

Next in the series: Are Your People Actually In Its Way? — how ShadowIQ decides whether an event touches your trip at all.