If you focus nearly exclusively on impact, how do you judge controls that mostly (only?) affect probability? (For example, most detection mechanism I can think of are imperfect, so they have a range of potential impact reduction between "down to 0" and "no reduction", with some nonnegligible probability assigned to "no reduction".)