RaptorGRC —Self-Hosted GRC

BLOG

Quantitative vs Qualitative Risk Assessment Which Should You Use

Published 25 July 2026 · By P Larner

Risk Management#ALE#FAIR#hybrid approach#risk matrix#quantitative risk#qualitative risk

Quantitative vs Qualitative Risk Assessment: Which Should You Use?

Illustration for: Quantitative vs Qualitative Risk Assessment: Which Should You Use?

Illustration for: Quantitative vs Qualitative Risk Assessment: Which Should You Use?

Every risk function eventually faces the same argument, which is whether to keep the familiar 5x5 matrix or move to numbers and probability distributions. Both camps overstate their case. The honest answer is that each approach fits different decisions, and most organisations need a deliberate mix rather than a conversion project.

What each approach actually is

Qualitative assessment rates risks on ordinal scales, with likelihood running from “rare” to “almost certain” and impact from “negligible” to “severe”, usually combined on a matrix to give a colour or a band. It is fast, it needs no historical data, and anyone can participate after ten minutes of explanation.

Quantitative assessment expresses risk in units that mean something outside the risk team, normally money per year. The classic form is annualised loss expectancy, which multiplies the estimated frequency of the event per year by the expected loss per event. A phishing-led credential compromise expected twice a year at £40,000 a time gives an annualised loss expectancy of £80,000. Modern practice, led by the FAIR model (Factor Analysis of Information Risk), replaces single-point estimates with ranges and runs Monte Carlo simulation over them, producing outputs like “90% chance the annual loss falls between £30,000 and £400,000”.

Side by side comparison of a five by five qualitative risk matrix and a quantitative loss exceedance curve

Side by side comparison of a five by five qualitative risk matrix and a quantitative loss exceedance curve

The same question answered two ways, as a band and a colour, or as money and probability.

Where qualitative assessment earns its place

  • Speed and coverage. You can triage 50 risks in an afternoon workshop. No quantitative method comes close for breadth.
  • Accessibility. Engineers, HR managers and facilities staff can all contribute without training in probability.
  • Regulatory familiarity. ISO 27005, NIST SP 800-30 and most UK regulator guidance accept qualitative methods without argument. The same is true of the audit world, because ISO 27001 certifications and ISAE 3402 control reports are earned every year on the back of a well-run qualitative process.

Its weaknesses are well documented and real. Ordinal scales invite inconsistency, because one assessor’s “likely” is another’s “possible”, and multiplying ordinal numbers (a 4 times a 3 equals 12) is mathematically meaningless even though every matrix does it. Matrices also compress badly. A £50,000 risk and a £5 million risk can land in the same amber cell, and the register then treats them as equals. Most risk matrices fail here, and the failure is invisible because the colours look so tidy.

A five by five risk matrix with one amber cell magnified to reveal a 50,000 pound risk and a 5 million pound risk sharing it

A five by five risk matrix with one amber cell magnified to reveal a 50,000 pound risk and a 5 million pound risk sharing it

The compression problem, with one amber cell hiding a hundredfold difference in exposure.

Where quantitative assessment earns its place

Numbers force clarity. To estimate loss event frequency you must define the loss event precisely, and half the value of FAIR is that this definition step kills vague risks like “cyber risk” on contact.

  • Investment decisions. “This control costs £120,000 a year and reduces expected annual loss by £600,000” is an argument a CFO can act on. “It moves the risk from red to amber” is not.
  • Comparing unlike risks. Money is a common unit across ransomware, supplier failure and regulatory fines.
  • Insurance and risk transfer. Limits and retentions are numbers, and you cannot negotiate them sensibly with colours.

The weaknesses are equally real. Good estimates take effort, so expect half a day to two days per risk for a defensible FAIR analysis, which is why nobody quantifies a 200-row register. The outputs carry false-precision risk, because a Monte Carlo result quoted to the pound can seduce an audience into forgetting it was built on expert ranges. And it needs at least one practitioner who genuinely understands calibrated estimation, not just the spreadsheet.

One myth is worth killing, which is the claim that “we have no data, so we cannot quantify”. You always have some data, whether incident history, industry reports or pentest findings, and calibrated ranges are designed for exactly this situation. The barrier is effort, not possibility.

A comparison at a glance

Factor

Qualitative (e.g. 5x5)

Quantitative (e.g. FAIR or ALE)

Speed per risk

Minutes

Hours to days

Output

Bands, colours

Money, probability ranges

Skill needed

Low

Moderate to high

Consistency

Poor without anchored scales

Good if estimators are calibrated

Best for

Triage, broad coverage

Investment cases, top risks

Main failure mode

False equivalence in cells

False precision in outputs

The hybrid that actually works

I have never seen a wholesale conversion to quantitative assessment succeed in a mid-size organisation. What works is layering.

  • Use qualitative scoring for the full register, but anchor the scales in real quantities. “Major” impact means £250,000 to £1 million, not “significant harm to objectives”. This single change removes most scoring arguments.
  • Quantify the top five to ten risks properly, plus any risk that is about to drive a spending decision above some threshold, say £100,000.
  • Feed the quantitative results back into the qualitative scales. If your FAIR analysis shows the ransomware risk sits at £2 million expected annual loss, and it was scored amber, your matrix calibration is wrong and now you know.
  • Reassess the quantified set annually or when the threat picture shifts, while the triage layer can move faster.

This gets you 90% of the decision value for perhaps 15% of the effort of quantifying everything.

Two layer pyramid showing anchored qualitative scoring for the full register and full quantitative analysis for the top risks

Two layer pyramid showing anchored qualitative scoring for the full register and full quantitative analysis for the top risks

The hybrid model, which quantifies the few risks that drive decisions and anchors the rest.

Choosing for your situation

Some honest heuristics from practice.

  • If your register has never driven a budget decision, your problem is not methodology, it is governance. Fix ownership and reporting first, because no amount of Monte Carlo will help.
  • If the board asks “how much should we spend on security?”, you need quantification for at least the headline risks. Colours cannot answer that question.
  • If you are a 50-person organisation with one security lead, run an anchored qualitative process well and do not apologise for it. A disciplined 5x5 beats an abandoned FAIR programme.
  • If you operate in financial services, expect supervisors to push toward quantification for operational risk anyway, so get ahead of it on your cyber scenarios.

Putting it into practice

Start by anchoring your existing qualitative scales to money and frequency ranges this quarter, because it costs a two-hour workshop and immediately improves consistency. Then pick your single scariest risk and run one proper quantitative analysis on it, using FAIR or even plain annualised loss expectancy with ranges. Present both views side by side to your risk committee and watch which one changes the conversation. In my experience the quantified version provokes the first genuinely useful challenge the register has had in years, and that reaction, not any methodology paper, will tell you how far down the quantitative road your organisation needs to go.

Run your GRC programme in your own network.

RaptorGRC Community Edition is free: every module, offline licence activation, nothing phones home.

Register / Download Contact us
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.