Skip to main content
Case studyFortune 100: 80% less compliance workRead the Story
RiskWatch
Risk assessment methods

Qualitative vs quantitative risk assessment

Qualitative risk assessment scores risk with descriptive scales like low, medium, and high. Quantitative risk assessment assigns numbers, usually money or probability, to produce figures like annualized loss expectancy. Qualitative is faster and easier to explain; quantitative is more precise and better for financial decisions. Most mature programs use both.

What is qualitative risk assessment?

Qualitative risk assessment rates each risk using descriptive categories rather than numbers. Assessors judge likelihood on a scale, from rare to almost certain, and impact on a scale, from negligible to catastrophic, then plot the two on a matrix. The most common tool is a 5x5 risk matrix that multiplies a 1 to 5 likelihood by a 1 to 5 impact for a score of 1 to 25, banded into low, medium, high, and extreme.

It is fast, visual, and easy to run in a workshop, which is why it is the default for screening a full register and briefing a board. The trade-off is subjectivity: bands have to be documented so that likely and major mean the same thing to every assessor.

What is quantitative risk assessment?

Quantitative risk assessment puts numbers on risk, most often money. The core metric is annualized loss expectancy: single loss expectancy multiplied by the annualized rate of occurrence. Single loss expectancy is the asset value multiplied by the exposure factor, the fraction of the asset lost in one event. The result is a dollar figure per year you can compare directly against the cost of a control.

More advanced methods model uncertainty rather than a single point: Monte Carlo simulation runs thousands of scenarios to produce a loss-exceedance curve, and FAIR (Factor Analysis of Information Risk) decomposes cyber and operational risk into frequency and magnitude. Quantitative analysis is repeatable and defensible, but it is only as good as the data behind it, so it is usually reserved for the risks that matter most.

Qualitative vs quantitative, side by side

Qualitative versus quantitative risk assessment compared by dimension.
DimensionQualitativeQuantitative
ScaleDescriptive bands (low, medium, high)Numbers, usually money or probability
Typical outputA ranked risk matrix, heat mapAnnualized loss expectancy, a loss curve, ROI on a control
SpeedFast, a workshop can score a register in hoursSlower, needs data collection and modeling
Data neededExpert judgment, past incidentsAsset values, frequency and loss data, distributions
ObjectivitySubjective, depends on the raterRepeatable, but only as good as the inputs
Best forScreening the whole register, board communicationThe top risks, budget and insurance decisions

When to use each

Reach for qualitative when
  • You need to score the whole register quickly
  • Data on frequency or loss is thin
  • You are communicating priority to a board or non-specialists
  • You are screening to decide what deserves deeper analysis
Reach for quantitative when
  • You must justify a control budget in dollars
  • You are setting an insurance limit or risk transfer
  • You are comparing two mitigation options on ROI
  • The risk is material enough to fund the data work

How to combine both

The two methods are not rivals. A semi-quantitative approach puts numeric scores behind the qualitative bands so the matrix still produces a comparable figure. A tiered approach runs a fast qualitative pass across the entire register, then a full quantitative analysis on the top quartile where the exposure justifies the effort. You get the breadth of qualitative scoring and the depth of quantitative analysis without modeling every minor risk. Standards like ISO 31000 and NIST SP 800-30 support all three modes and leave the choice to you.

Frequently asked questions

What is the difference between qualitative and quantitative risk assessment?

Qualitative risk assessment rates each risk with descriptive scales, usually likelihood and impact on a scale like 1 to 5, and plots them on a matrix or heat map. Quantitative risk assessment assigns numeric values, most often money or probability, and produces figures like annualized loss expectancy or a loss-exceedance curve. Qualitative is faster and easier to communicate; quantitative is more precise and better for financial decisions, but it needs more data.

Which is better, qualitative or quantitative risk assessment?

Neither is universally better. Qualitative assessment is the right tool for screening a full risk register quickly and explaining priorities to a board. Quantitative assessment is the right tool for the handful of top risks where you need to justify a control budget, set an insurance limit, or compare options in dollars. Most mature programs use both: qualitative to triage everything, quantitative on the risks that clear the threshold.

What is annualized loss expectancy (ALE)?

Annualized loss expectancy is the core quantitative metric. ALE = single loss expectancy multiplied by annualized rate of occurrence. Single loss expectancy is the asset value multiplied by the exposure factor, the share of the asset lost in one event. If a data breach would cost 500,000 dollars per event and you expect it once every five years, the ALE is 500,000 times 0.2, or 100,000 dollars a year, which you can compare directly to the annual cost of a control.

Can you combine qualitative and quantitative methods?

Yes, and most programs do. A semi-quantitative approach puts numbers behind the qualitative bands, for example scoring likelihood 1 to 5 and impact 1 to 5 and multiplying them. A tiered approach runs a fast qualitative pass over the whole register, then a full quantitative analysis on the top quartile. This gives you breadth from qualitative scoring and depth where the exposure justifies the effort.

Which method do risk frameworks require?

Most frameworks allow both. ISO 31000 and NIST SP 800-30 describe qualitative, quantitative, and semi-quantitative analysis and leave the choice to the organization. FAIR (Factor Analysis of Information Risk) is an explicitly quantitative model for cyber and operational risk. Compliance frameworks like SOC 2, ISO 27001, and HIPAA require a documented risk assessment but do not mandate a specific scale.

From assessment to a living register

Score risk qualitatively or quantitatively, in one platform.

RiskWatch runs both methods against the same register, with custom impact, likelihood, and criticality scoring per assessment type.

No credit card required · 30-day free trial · Cancel anytime

Request a Demo