Skip to main content
Category: Loss Modeling & Aggregation

Probable Maximum Loss

Also known as:
Simply put

Probable Maximum Loss (PML) is an estimate of the largest loss that could reasonably be expected to result from a single disaster or event, assuming that normal protective features function as intended. It is often expressed as a monetary figure or as a percentage of the total value of what is at risk. It helps organizations and insurers gauge worst-case exposure rather than everyday or average losses.

Formal definition

PML is a risk-quantification measure representing the value of the largest loss reasonably expected from a single event, generally assuming the normal functioning of passive protective features. It may be expressed as an absolute monetary amount or as a percentage of the total insured or asset value experienced by a structure or collection of assets. In actuarial usage it has been characterized as the maximum percentage of a risk that would be subject to loss at one time, or the maximum amount of loss that can be sustained within a given event. The concept is applied in domains such as seismic and physical-loss studies of buildings and infrastructure; note that PML is an estimate subject to defined assumptions (including the reliability of protective features), and its precise definition and application vary by context. Whether any modeled PML corresponds to an actual insured recovery depends on the specific policy wording, sublimits, retentions, and exclusions, which are outside the scope of the PML estimate itself.

Why it matters

Probable Maximum Loss gives risk managers and underwriters a way to reason about worst-case exposure rather than average or attritional losses. Everyday loss figures describe what an organization can expect to absorb routinely, but they say little about the severe, low-frequency events that determine how much capital, reinsurance, or insurance limit is genuinely needed. PML fills that gap by estimating the largest loss that could reasonably follow a single event, assuming that normal protective features operate as intended. This makes it a foundational input for sizing coverage limits, structuring retentions, and stress-testing an organization's financial resilience.

Who it's relevant to

Underwriters
Underwriters use PML to gauge the worst-case exposure a single event could present, informing decisions on limits, retentions, and how much of a risk to accept or cede. Because PML assumes normal functioning of protective features, underwriters should treat it as a conditional estimate and probe the assumptions behind it rather than as a firm loss cap.
Risk Managers
For risk managers, PML supports capital planning and the sizing of insurance programs by distinguishing severe, low-frequency exposure from routine losses. It helps frame how much risk to transfer versus retain, though it does not by itself reduce the likelihood of an event and must be paired with mitigation and resilience measures.
Insurance Brokers
Brokers rely on PML studies to advise clients on appropriate limits and to articulate worst-case exposure to markets. They should also clarify to clients that a PML figure describes potential loss, not guaranteed recovery, which depends on policy wording, sublimits, and exclusions.
Resilience and Continuity Planners
Continuity and resilience professionals can use PML to prioritize assets with the highest severe-loss exposure, as in seismic studies that identify high-risk structures. PML is a financial exposure estimate, however, and is distinct from operational recovery metrics such as RTO and RPO; it should inform, not replace, business continuity and disaster recovery planning.

Inside PML

Loss Estimation Basis
PML represents an estimate of the largest loss reasonably expected to result from a single incident or scenario, rather than the theoretical worst case. It is a modeling and underwriting construct used to size potential exposure, and its value depends heavily on the assumptions and scenario definitions applied.
Scenario Definition
The estimate is anchored to specific hypothetical events, such as a widespread ransomware event, a cloud service provider outage, or a systemic software vulnerability. Changing the scenario parameters materially changes the resulting figure, so the underlying assumptions must be stated explicitly.
Aggregation and Accumulation Considerations
In cyber contexts, PML analysis often accounts for correlated or systemic exposure, where a single event affects many insureds or systems simultaneously (for example, a shared vendor or common technology). This distinguishes it from isolated single-insured loss analysis.
Coverage Interaction
A PML estimate may span both first-party components (such as business interruption, data restoration, and cyber extortion costs to the insured) and third-party components (such as liability and regulatory defense). Whether any modeled loss is actually indemnified depends on policy wording, sublimits, retentions, waiting periods, and exclusions, subject to the specific terms.
Distinction from Related Metrics
PML is not the same as maximum foreseeable loss (an even more severe theoretical estimate) nor the same as policy limits or expected loss. It is a risk-quantification tool used in underwriting, capital allocation, and portfolio management, and its meaning can vary between insurers and modeling frameworks.

Common questions

Answers to the questions practitioners most commonly ask about PML.

Is probable maximum loss the same as the worst-case or total possible loss an organization could suffer?
No. Probable maximum loss (PML) is not the theoretical maximum or total possible loss. PML estimates the largest loss reasonably expected to occur under a defined adverse but plausible scenario, not the absolute ceiling in which every control fails simultaneously. The concept that captures a more extreme, near-total failure is sometimes distinguished as the maximum possible (or maximum foreseeable) loss. Conflating the two tends to understate tail exposure, so it is important to confirm which measure a given analysis is using and what assumptions bound the scenario.
Does the PML figure tell me how much cyber insurance limit I should buy?
Not directly. A PML estimate informs limit adequacy discussions, but it is not itself a coverage recommendation. Whether a given loss scenario would be paid depends on policy wording, sublimits, retentions, waiting periods, exclusions, and conditions precedent, so the insurable portion of a modeled PML may differ from the gross figure. PML also reflects assumptions that can change, and reasonable professionals disagree on scenario selection. Limit decisions typically weigh the PML alongside risk appetite, retained-loss tolerance, and the specific terms on offer, rather than treating PML as a single number to match.
What scenario should we base a cyber PML estimate on?
There is no single mandated scenario; the choice is a judgment that should be documented. Common approaches model a plausible severe event such as a widespread ransomware encryption affecting core systems, a large data breach triggering third-party privacy liability and regulatory response, or a prolonged outage driving first-party business interruption. Because PML depends heavily on the scenario chosen and its assumptions, it is good practice to define the event, its duration, the systems affected, and whether the estimate covers first-party losses, third-party liability, or both, so the resulting figure is interpretable and comparable over time.
How do we account for first-party versus third-party exposure in a PML analysis?
State explicitly which category each modeled loss belongs to, because they behave differently. First-party components such as business interruption, data restoration, and cyber extortion costs are the insured's own losses and are often shaped by waiting periods, restoration timelines, and RTO/RPO assumptions. Third-party components such as privacy claims and regulatory defense reflect liability to others and depend on affected-record counts, jurisdictions, and applicable regimes. A combined PML can be useful, but blending the two without distinction obscures which coverages and sublimits actually respond, so many analyses present them separately as well as in aggregate.
How often should a PML estimate be revisited?
PML is not a fixed value; it reflects the environment and assumptions at the time it was produced. It is commonly reassessed when the risk profile changes materially, for example after significant changes to systems, dependencies, revenue, data holdings, controls, or the threat landscape, and often at a regular review cadence such as renewal. Because the estimate is conditional on the chosen scenario and inputs, documenting the assumptions supports meaningful comparison across successive reviews and helps identify when a change in exposure, rather than a change in method, is driving a shift in the figure.
How should PML interact with our resilience planning rather than replace it?
PML is an exposure estimate, not a resilience measure, and buying insurance sized to a PML does not reduce the likelihood of an incident. The two disciplines inform each other: resilience assumptions such as RTO and RPO, business continuity and disaster recovery capabilities, and incident response maturity feed the duration and severity inputs of a PML scenario, while a large PML can signal where mitigation, avoidance, or improved recovery capability may be more effective than transfer alone. Treating PML as a driver of both risk-transfer and risk-mitigation decisions, rather than a substitute for preparedness, keeps the analysis aligned with actual operational risk.

Common misconceptions

PML is the absolute worst loss that could ever occur.
PML typically reflects the largest loss reasonably expected under a defined scenario, not the theoretical maximum. More severe theoretical estimates are usually treated under separate concepts such as maximum foreseeable loss. The figure is conditional on the assumptions and scenario chosen and should not be read as a hard ceiling.
A PML figure tells you how much insurance will pay after an incident.
PML is an estimation and underwriting construct, not a statement of coverage. Actual indemnification depends on policy wording, applicable sublimits, retentions, waiting periods, endorsements, and exclusions, and may differ substantially from any modeled loss amount.
PML measures an organization's resilience or recovery capability.
PML quantifies potential financial exposure; it is not a resilience metric like RTO or RPO and does not reduce the likelihood of an incident. Risk transfer through a PML-informed policy is distinct from mitigation, and a PML estimate says nothing by itself about how quickly or effectively an organization can recover.

Best practices

State the underlying scenario and assumptions explicitly whenever citing a PML figure, since the estimate is meaningful only in relation to the event it models.
For cyber exposures, incorporate aggregation and systemic-correlation analysis, accounting for shared vendors, common technologies, and cloud dependencies that can drive many losses from a single event.
Keep the PML estimate separate from coverage determinations, and cross-check any modeled loss against policy limits, sublimits, retentions, waiting periods, and exclusions to understand what would actually be indemnified.
Clarify which portions of a modeled loss are first-party (such as business interruption and data restoration) versus third-party (such as liability and regulatory defense), rather than treating the total as a single undifferentiated number.
Avoid conflating PML with maximum foreseeable loss, expected loss, or policy limits, and document which definition and framework are being used given that usage varies across insurers.
Treat PML as an exposure-quantification input to risk transfer decisions, not as a substitute for mitigation or resilience planning, and pair it with distinct resilience measures where recovery capability is the concern.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps