BLOG
Quantitative vs Qualitative Risk Assessment Which Should You Use
Published 25 July 2026 · By P Larner
Risk Management#ALE#FAIR#hybrid approach#risk matrix#quantitative risk#qualitative risk
Quantitative vs Qualitative Risk Assessment: Which Should You Use?
Illustration for: Quantitative vs Qualitative Risk Assessment: Which Should You Use?
Every risk function eventually faces the same argument, which is whether to keep the familiar 5x5 matrix or move to numbers and probability distributions. Both camps overstate their case. The honest answer is that each approach fits different decisions, and most organisations need a deliberate mix rather than a conversion project.
What each approach actually is
Qualitative assessment rates risks on ordinal scales, with likelihood running from “rare” to “almost certain” and impact from “negligible” to “severe”, usually combined on a matrix to give a colour or a band. It is fast, it needs no historical data, and anyone can participate after ten minutes of explanation.
Quantitative assessment expresses risk in units that mean something outside the risk team, normally money per year. The classic form is annualised loss expectancy, which multiplies the estimated frequency of the event per year by the expected loss per event. A phishing-led credential compromise expected twice a year at £40,000 a time gives an annualised loss expectancy of £80,000. Modern practice, led by the FAIR model (Factor Analysis of Information Risk), replaces single-point estimates with ranges and runs Monte Carlo simulation over them, producing outputs like “90% chance the annual loss falls between £30,000 and £400,000”.
Side by side comparison of a five by five qualitative risk matrix and a quantitative loss exceedance curve
The same question answered two ways, as a band and a colour, or as money and probability.
Where qualitative assessment earns its place
- Speed and coverage. You can triage 50 risks in an afternoon workshop. No quantitative method comes close for breadth.
- Accessibility. Engineers, HR managers and facilities staff can all contribute without training in probability.
- Regulatory familiarity. ISO 27005, NIST SP 800-30 and most UK regulator guidance accept qualitative methods without argument. The same is true of the audit world, because ISO 27001 certifications and ISAE 3402 control reports are earned every year on the back of a well-run qualitative process.
Its weaknesses are well documented and real. Ordinal scales invite inconsistency, because one assessor’s “likely” is another’s “possible”, and multiplying ordinal numbers (a 4 times a 3 equals 12) is mathematically meaningless even though every matrix does it. Matrices also compress badly. A £50,000 risk and a £5 million risk can land in the same amber cell, and the register then treats them as equals. Most risk matrices fail here, and the failure is invisible because the colours look so tidy.
A five by five risk matrix with one amber cell magnified to reveal a 50,000 pound risk and a 5 million pound risk sharing it
The compression problem, with one amber cell hiding a hundredfold difference in exposure.
Where quantitative assessment earns its place
Numbers force clarity. To estimate loss event frequency you must define the loss event precisely, and half the value of FAIR is that this definition step kills vague risks like “cyber risk” on contact.
- Investment decisions. “This control costs £120,000 a year and reduces expected annual loss by £600,000” is an argument a CFO can act on. “It moves the risk from red to amber” is not.
- Comparing unlike risks. Money is a common unit across ransomware, supplier failure and regulatory fines.
- Insurance and risk transfer. Limits and retentions are numbers, and you cannot negotiate them sensibly with colours.
The weaknesses are equally real. Good estimates take effort, so expect half a day to two days per risk for a defensible FAIR analysis, which is why nobody quantifies a 200-row register. The outputs carry false-precision risk, because a Monte Carlo result quoted to the pound can seduce an audience into forgetting it was built on expert ranges. And it needs at least one practitioner who genuinely understands calibrated estimation, not just the spreadsheet.
One myth is worth killing, which is the claim that “we have no data, so we cannot quantify”. You always have some data, whether incident history, industry reports or pentest findings, and calibrated ranges are designed for exactly this situation. The barrier is effort, not possibility.
A comparison at a glance
Factor | Qualitative (e.g. 5x5) | Quantitative (e.g. FAIR or ALE) |
|---|---|---|
Speed per risk | Minutes | Hours to days |
Output | Bands, colours | Money, probability ranges |
Skill needed | Low | Moderate to high |
Consistency | Poor without anchored scales | Good if estimators are calibrated |
Best for | Triage, broad coverage | Investment cases, top risks |
Main failure mode | False equivalence in cells | False precision in outputs |
The hybrid that actually works
I have never seen a wholesale conversion to quantitative assessment succeed in a mid-size organisation. What works is layering.
- Use qualitative scoring for the full register, but anchor the scales in real quantities. “Major” impact means £250,000 to £1 million, not “significant harm to objectives”. This single change removes most scoring arguments.
- Quantify the top five to ten risks properly, plus any risk that is about to drive a spending decision above some threshold, say £100,000.
- Feed the quantitative results back into the qualitative scales. If your FAIR analysis shows the ransomware risk sits at £2 million expected annual loss, and it was scored amber, your matrix calibration is wrong and now you know.
- Reassess the quantified set annually or when the threat picture shifts, while the triage layer can move faster.
This gets you 90% of the decision value for perhaps 15% of the effort of quantifying everything.
Two layer pyramid showing anchored qualitative scoring for the full register and full quantitative analysis for the top risks
The hybrid model, which quantifies the few risks that drive decisions and anchors the rest.
Choosing for your situation
Some honest heuristics from practice.
- If your register has never driven a budget decision, your problem is not methodology, it is governance. Fix ownership and reporting first, because no amount of Monte Carlo will help.
- If the board asks “how much should we spend on security?”, you need quantification for at least the headline risks. Colours cannot answer that question.
- If you are a 50-person organisation with one security lead, run an anchored qualitative process well and do not apologise for it. A disciplined 5x5 beats an abandoned FAIR programme.
- If you operate in financial services, expect supervisors to push toward quantification for operational risk anyway, so get ahead of it on your cyber scenarios.
Putting it into practice
Start by anchoring your existing qualitative scales to money and frequency ranges this quarter, because it costs a two-hour workshop and immediately improves consistency. Then pick your single scariest risk and run one proper quantitative analysis on it, using FAIR or even plain annualised loss expectancy with ranges. Present both views side by side to your risk committee and watch which one changes the conversation. In my experience the quantified version provokes the first genuinely useful challenge the register has had in years, and that reaction, not any methodology paper, will tell you how far down the quantitative road your organisation needs to go.
Run your GRC programme in your own network.
RaptorGRC Community Edition is free: every module, offline licence activation, nothing phones home.
Register / Download Contact us