Qualitative assessment rates risk on descriptive scales - high, medium, low. Quantitative assessment estimates it in money and probability. The choice is not about rigour for its own sake; it is about what decision the output has to support.
Qualitative: scales and heat maps
Likelihood and impact are rated on ordinal scales, usually 1-5, and multiplied or plotted into a matrix. It dominates practice because it is fast, needs no loss data, and everyone in the room can participate.
Where it works: broad coverage across a large risk universe, prioritising a backlog, satisfying framework requirements, and communicating with people who do not want a probability distribution.
Where it breaks:
- The numbers are labels, not quantities. A "4" is not twice a "2", so multiplying likelihood by impact is arithmetic on rankings. It is convention, not mathematics.
- You cannot aggregate. Thirty medium risks do not sum to anything, so "what is our total exposure?" has no answer.
- No cost comparison. Nothing tells you whether a control costing 400,000 is proportionate to the risk it reduces.
- Central clustering. Assessors avoid extremes, so most risks land as medium and the ranking stops discriminating.
- Inconsistency between assessors unless the scale definitions are unusually precise.
The fix for most of these is not abandoning qualitative scoring - it is defining each scale point concretely. "Likely = expected more than once a year" and "Major = over 1m loss or regulatory notification" produce far more consistent results than "Likely" and "Major" alone.
Quantitative: money and probability
Risk is expressed as a loss distribution - typically an annualised loss expectancy, or a range with confidence bounds. The best-known structured approach is FAIR, which decomposes risk into frequency of loss events and magnitude of loss, each built from estimable sub-factors.
Where it works: justifying a specific investment, comparing options, setting insurance limits, and any conversation with a CFO. A statement like "this control reduces expected annual loss from 2.1m to 400k at a cost of 250k" is decidable in a way that "reduces risk from high to medium" is not.
What it costs: considerably more effort per risk, calibration training so estimates are not overconfident, and comfort with ranges rather than single numbers. It is also easy to over-trust: a model built on weak inputs produces confident nonsense with decimal places.
Assess risk against your controls, not a blank page
GRC Copilot scores risks against your actual control coverage and evidence, keeps inherent and residual ratings current, and produces the register your auditors and board both need.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
The hybrid most organisations should run
Treat them as a funnel rather than a choice:
- Screen everything qualitatively. The full risk universe, scored quickly on well-defined scales.
- Quantify the top tier only - the handful heading for material investment, board attention or an accept/transfer decision.
- Quantify anything contested. When two teams disagree about priority, monetary estimates usually resolve it faster than another workshop.
- Re-screen annually, re-quantify on change.
This keeps the effort proportionate: you get coverage from the qualitative pass and decision quality where it actually matters.
Semi-quantitative middle ground
A cheap improvement on pure qualitative: attach monetary bands to impact levels and frequency bands to likelihood levels. "Impact 4 = 1m-10m", "Likelihood 3 = once every 1-3 years". You keep the speed of a matrix while making the scale mean something, and you can produce rough expected-loss figures without building a model.
For most organisations this is the highest-return change available to an existing risk process.
What frameworks require
ISO 27001 requires a defined, repeatable methodology producing consistent, comparable results - it does not mandate either approach. Most certified organisations use qualitative. Sector regulators in financial services increasingly expect quantification for material risks, and boards ask for it more often than they used to.
Frequently asked questions
Are heat maps discredited?
They are criticised for exactly the reasons above - ordinal arithmetic and central clustering. They remain useful for screening and communication, provided nobody treats the score as a quantity.
Do we need loss data to quantify?
Not necessarily. Calibrated expert estimates expressed as ranges are the normal starting point; industry loss data and your own incident history refine them.
How long does a quantitative assessment take?
Hours per risk once the team is trained, versus minutes qualitatively. That ratio is the reason to reserve it for decisions of consequence.
Can we mix both in one register?
Yes, and it is the recommended pattern - qualitative ratings for everything, with monetary estimates added on the risks that warrant them. Keep the columns distinct so nobody compares a 4 with 2.1m.
Key takeaways
- Qualitative scores are rankings, not quantities - they cannot be summed or cost-compared.
- Quantitative models support investment decisions but cost real effort and need calibration.
- Screen everything qualitatively, quantify the top tier and anything contested.
- Attaching monetary and frequency bands to your scale points is the cheapest big improvement.