Not Every Typo Is Low Severity
A severity model for creative QA borrowed from security: how materiality, exposure, trust boundaries, reversibility and business consequence decide what a defect actually costs.
A typo is usually considered a small mistake.
A misspelled word, an extra letter, a missing punctuation mark. Something easy to fix and easy to dismiss.
In many cases, that is exactly what it is.
But sometimes the typo is not the problem.
The problem is where it appears, who sees it, what it changes, and what happens next.
A typo in an internal draft may have no consequence at all.
The same typo in a client presentation may undermine confidence.
The same typo in a public campaign may embarrass the brand.
And the same typo in a price, date, legal statement, offer, or call to action may create financial or reputational consequences far larger than the defect itself.
This is why creative QA needs a better way to think about severity.
Not every typo is low severity.
And not every serious incident begins with a serious-looking mistake.
This is the second article in this series. The first, Assume Error: What Creative QA Can Learn From Cybersecurity, argued that a defect and an escaped defect are not the same event. This one is about how to tell them apart.
The Defect Is Not the Impact
Cybersecurity has spent years developing ways to distinguish between a technical flaw and the consequences that flaw can create.
A vulnerability is not evaluated by asking:
"How complicated does the bug look?"
It is scored. There is a published scale, CVSS, with defined dimensions: how the flaw is reached, how hard it is to exploit, what privileges it needs, whether a user has to be involved, and what it does to confidentiality, integrity and availability. Feed those in and you get a number and a vector string that encodes how you got there.
The number is not the point. The shared vocabulary is.
Two analysts scoring the same flaw independently will land close to each other, and more importantly, a vendor, a researcher, a client and a regulator all read the resulting number the same way. Disagreements become arguments about a specific dimension (is this really network-reachable?) rather than about whether the thing is "serious."
Creative QA has nothing like this.
It has adjectives. Minor. Small. Embarrassing. Bad. And those adjectives are assigned informally, by whoever happens to be describing the problem, at the moment they describe it.
That would be tolerable if everyone were merely imprecise in the same direction.
They are not.
Imagine a social post that says:
"Your going to love this."
The spelling or grammar problem is obvious.
But the defect itself tells us very little about its actual severity.
If it is caught in a draft, the impact is effectively zero.
If it is published on a small account and corrected two minutes later, the impact may still be minimal.
If it appears in the launch campaign for a major client, gets promoted with paid media, and is noticed first by the client, the exact same defect has a very different business meaning.
The words did not become more incorrect.
The context changed the consequence.
This distinction is fundamental:
Defect severity and incident severity are not always the same thing.
"It's Just a Typo" Can Be a Dangerous Sentence
In creative environments, we often classify defects informally.
A broken link is "small."
A typo is "minor."
A wrong image is "embarrassing."
A date error is "bad."
But these labels are often assigned without considering the actual business context.
That can create two opposite problems.
First, teams can overreact to trivial findings.
A tiny spacing inconsistency in an internal draft may receive more attention than it deserves.
Second, teams can underestimate defects that look small but carry disproportionate risk.
Consider a few examples.
A typo in the middle of a long blog post may be mildly unprofessional.
A typo in the CEO's name is different.
A typo in a product description may be annoying.
A typo that changes $10.00 to $100.00 is different.
A wrong date in an unpublished event draft is harmless.
A wrong date in an email sent to 40,000 attendees is different.
A broken link in an internal document is inconvenient.
A broken link in the primary CTA of a paid campaign can waste real money.
The defect category alone does not tell us enough.
The important question is:
What can this mistake become if it escapes?
Three Parties Score It, and They Do Not Agree
A creative defect is evaluated by at least three parties, and each one is scoring a different thing.
The creator scores by effort and intent. How long does it take to fix, and did I mean it? A missing letter is thirty seconds and no change in meaning. By that measure it is close to nothing, and that measure is not stupid. It is simply the only one the creator has direct access to.
The client scores by exposure and by what it implies. They do not experience the fix. They experience seeing it, in public, attached to their name. And the question they are actually answering is not "how wrong is this?" but "what does this tell me about the work I am not looking at?"
The client's customer does not score it at all. They form an impression, usually without articulating it, and they attach that impression to the brand. They do not know the agency exists.
Now notice the shape of that.
The party with the most information about the defect (the creator, who knows exactly what happened and how small it was) has the least visibility into what it will cost. The party who ultimately generates the cost has no idea there is an agency in the chain at all.
Severity, in other words, is routinely assessed by the person least equipped to assess it, using the one dimension that correlates worst with consequence.
And the three assessments do not merely differ in precision. They can run in opposite directions. The defect the creator finds most embarrassing (a clumsy sentence, a layout they are not proud of) is frequently invisible to everyone else. The defect they wave off in three seconds (a digit, a date, a name) is the one that produces the phone call.
One Error in Thousands Is Still One Cancelled Account
Here is the case that makes the whole problem concrete, and it is the reason a severity model cannot be inferred from a track record.
You run social for a marketing agency. Across dozens of clients you publish thousands of posts a year. Over that period, two of them go out with a typo.
By any statistical standard that is excellent work. It is a defect rate most disciplines would be pleased with.
And for almost the entire life of that account, the rate is what matters. Nobody notices. Or somebody notices, it gets fixed, and the week continues. Everyone makes mistakes, life goes on, and the agency's reputation is completely unaffected.
Then one client sees one of them.
Not at a neutral moment, but in a quarter where they were already quietly wondering whether the retainer is worth it, or where a new stakeholder is forming a first impression, or where they had just been asked internally to justify the spend.
They cancel.
The defect was a missing letter. The consequence is a lost client, the revenue that client represented, a promoter you no longer have, and a reference you can no longer use.
For the agency, that outcome is Critical. Not because the typo became worse, since it did not change at all, and not because the rate got worse, since it is still two in several thousand.
What changed is that a business outcome attached itself to one of them.
This is the part worth sitting with:
An excellent defect rate does not bound your worst outcome.
Rate and consequence are independent axes. You can be genuinely good, statistically, and still lose an account to a single event, because the client is not evaluating your rate. They are evaluating the one instance they saw.
Which is exactly why severity has to be assessed per finding, prospectively, before you know how it lands, rather than inferred afterward from how rarely it happens.
Is Every Error Critical, Then?
No. And the reason that answer is not obvious is the whole problem.
If one typo can end a relationship, the honest reading is that any of them might, which leaves a team with two bad options: treat everything as potentially fatal, or go back to calling things minor and hoping. The first is unsustainable and the second is what we already had.
The way out is not to care more. It is to be able to tell the cases apart before you find out which one this was, to hunt adversarially for the finding that could cost a client, while the people doing the hunting stay unafraid of what they turn up.
That is achievable, and it depends on two things this article can only set up. The severity assessment has to be separated from any judgment about the person who produced the defect, and finding something has to be visibly rewarded rather than quietly filed. Where that lands is A Critical Defect Caught Internally Is a Win, later in this series.
The first step is smaller: having something more precise than adjectives.
Severity Should Include Context
If creative teams want a more useful way to think about quality, severity should reflect several dimensions.
It does not need to become a complicated scoring system.
The goal is not mathematical perfection.
The goal is to stop treating every finding as if its impact were obvious.
A practical assessment can begin with five questions.
1. How Material Is the Error?
Does the defect merely affect appearance, or does it change meaning?
A minor alignment issue is different from a wrong date.
A typo that does not change meaning is different from a typo that changes the price.
A slightly awkward sentence is different from an unsupported factual claim.
The first question is simply:
How wrong is the output itself?
2. How Much Trust Can It Damage?
In agency work, trust is often the real asset at risk.
Clients do not hire agencies simply to produce files.
They hire them because they expect professional judgment, attention to detail, reliability, and protection of their brand.
A typo may be objectively minor but still trigger a disproportionately strong reaction if it confirms an existing concern:
"They are not paying attention."
This is the dimension that behaves least like a measurement.
The same defect can be absorbed without comment by a client who is confident in the relationship, and treated as evidence by a client who is not. Severity here depends partly on a history the defect knows nothing about.
Which is why this question is worth asking explicitly rather than assumed: a recent escape, a tense renewal, a new stakeholder who did not choose you, all raise the severity of the next finding before it happens.
The mechanics of how a defect crosses from your team to the client to their customers are the subject of the next article, The Trust Chain. For scoring severity, the short version is enough: the further a defect can travel, the less of its cost you control.
3. Who Is Exposed? (Reach)
The same error behaves differently depending on who can see it.
An internal draft has almost no external exposure.
A client-facing presentation crosses the first important trust boundary.
A public post crosses another.
A paid campaign, newsletter, or high-traffic landing page may expose the defect to thousands of people almost immediately.
Exposure does not make the mistake itself worse.
It makes the potential consequence larger.
4. Can It Be Reversed?
Some mistakes disappear with an edit.
Others do not.
A typo on a website can usually be corrected quickly.
A newsletter that has already been delivered cannot be pulled back from every inbox.
Printed materials cannot be edited after distribution.
A social post can be deleted, but screenshots may remain.
A misleading offer may already have influenced purchasing decisions.
Confidential information may already have been copied.
The cost of a mistake is not only what went wrong.
It is also:
How difficult is it to make things right?
5. What Is the Business Consequence?
This is the question traditional creative QA often avoids because it feels subjective.
But pretending the consequence does not exist does not make it less real.
A defect can create:
- Additional labor.
- Wasted ad spend.
- Confused customers.
- Missed registrations.
- Incorrect purchases.
- Client complaints.
- Regulatory concerns.
- Reputation damage.
- Reduced confidence.
- Client churn.
The same defect can have a completely different business consequence depending on the client, campaign, audience, and timing.
That does introduce judgment.
But informed judgment is better than pretending all typos belong in the same bucket.
A Simple Example
Consider two errors.
Finding A
A social post contains a missing comma.
It is caught internally before scheduling.
The meaning is unchanged.
No client or customer sees it.
It takes ten seconds to correct.
This should probably be treated as Low severity.
Finding B
A campaign announcing a limited-time client event uses the wrong date.
The email has already been sent to thousands of recipients.
The client discovers the error after customers begin asking questions.
The agency must issue a correction.
The client is unhappy because the campaign has made their organization look unreliable.
Technically, the error may have been a single incorrect number.
Operationally, the impact is High.
Maybe Critical, depending on what happens next.
This is exactly why creative QA needs to separate how small the mistake looks from how large the consequence can become.
A Critical Finding Can Still Be a Success
A severity model introduces one risk the previous article did not have to handle: the word "Critical" appearing in a report about a colleague's work.
The way out is to keep two variables separate.
Severity describes the potential impact of the defect. The detection point describes whether the process contained it.
Imagine QA finds the wrong pricing in a major email campaign that has not been sent yet. The severity is Critical, because that is what the impact would have been. The detection point is internal, which means the process worked exactly as designed.
Recorded as one number, that event reads as a disaster. Recorded as two, it reads as a Critical impact that a control caught.
This is why the two fields should never be collapsed. A team that only tracks severity will start under-rating findings to keep its reports calm, which destroys the model. A team that tracks both can report a Critical finding without it sounding like an accusation, because the second field already says the system held.
Low Severity Does Not Mean Low Value
The reverse is also true.
Finding a low-severity defect internally still has value.
Most creative QA work is not about preventing catastrophic incidents.
It is about consistently preventing small imperfections from accumulating into a perception of carelessness.
One typo rarely destroys a client relationship.
Neither does one spacing inconsistency.
Or one broken link.
Or one missing alt tag.
Or one awkward sentence.
But quality is cumulative.
So is trust.
A client may never consciously think:
"This relationship is failing because of seven minor errors."
They may simply begin to feel:
"I have to check everything they send me."
That sentence should terrify any service business.
The moment the client believes they must become the agency's QA department, part of the value proposition has already collapsed.
Not Every Error Is Critical Either
There is a danger in going too far in the opposite direction.
If every typo becomes a "Critical risk," the framework becomes useless.
Teams become exhausted.
Everything becomes urgent.
Severity stops communicating priority.
And the organization recreates the same fear-based culture the framework was supposed to avoid.
The point is not to dramatize mistakes.
The point is to differentiate them intelligently.
A minor typo in a draft should remain minor.
A typo that changes a financial amount should not.
A small visual imperfection may be Low.
The wrong client logo may be High.
An unsupported marketing claim may be more serious than a dozen spelling mistakes.
Good QA does not treat everything as an emergency.
It helps the team understand what deserves attention first.
Creative QA Is Risk Management
This is the larger shift.
QA should not merely answer:
"Is there an error?"
It should also ask:
"What matters if this error escapes?"
That moves quality assurance away from checkbox compliance and toward risk management.
And risk management changes behavior in useful ways.
You spend more review effort on irreversible, high-exposure work.
You double-check prices, dates, names, claims, and audiences.
You apply stronger controls before sending 100,000 emails than before publishing an internal draft.
You recognize that some clients or campaigns carry greater reputational sensitivity than others.
You automate trivial checks when possible so human attention can focus on context.
You do not waste the same amount of review effort everywhere.
That is not lowering quality standards.
It is applying them intelligently.
Severity Without Blame
There is one final rule that matters.
Severity should describe the potential impact of the defect.
It should not describe the value, competence, or professionalism of the person who created it.
A Critical finding does not mean:
"A terrible employee did something terrible."
It means:
"If this had escaped, the consequence could have been serious."
Those are completely different statements.
The first creates defensiveness.
The second creates prioritization.
One assigns identity.
The other assigns risk.
That distinction is essential if creative organizations want to borrow ideas from cybersecurity without importing a culture of fear.
The Question Is Not "How Bad Does This Look?"
A useful severity model for creative work should force us to look beyond the visible defect.
Ask the five:
- How wrong is the output? (materiality)
- Whose trust is exposed? (trust impact)
- How many people can see it? (reach)
- Can it be undone? (reversibility)
- What could it cost? (business consequence)
Only then can we understand what the mistake actually means.
Answered together, those questions produce something more useful than a label. They produce a score with two halves: how much impact the defect could have had, and how far it got before somebody stopped it.
That pair is the whole idea. Later in this series it gets a name, CQIS, the Creative Quality Impact Score, and a formal definition in From QA Checklist to Creative Risk Management. It is deliberately not a formula yet.
For now the questions are enough. A team that asks them consistently is already doing the harder half of the work.
Because sometimes a typo really is just a typo.
It gets caught, corrected, and forgotten.
And sometimes the smallest visible defect is simply the first step in a much larger chain of consequences.
That is why not every typo is Low severity.