Ask two risk teams to assess the same threat and one returns "High" on a heat map while the other returns "expected annual loss: $340,000." Both are doing risk analysis; they are answering different questions with different costs. Knowing when each approach earns its keep — and how exam questions test the distinction — is core risk practitioner skill.
Qualitative analysis: ordered judgment
Qualitative analysis rates likelihood and impact on ordinal scales — low/medium/high, 1-to-5 — and combines them, usually on a matrix, into a risk rating. Its strengths are speed, accessibility and coverage: a workshop can triage fifty risks in an afternoon, stakeholders without statistics can participate meaningfully, and risks with no good loss data (reputation, regulatory, strategic) can still be compared.
Its failure modes are just as real. Ordinal scales invite false arithmetic — a "4 × 3 = 12" risk score looks numeric but multiplying ranks has no mathematical meaning. Ratings drift with the rater: one assessor's "high" is another's "medium," and without calibrated definitions the register encodes personalities, not risk. And heat maps compress everything to a handful of cells, hiding the difference between a risk that just made "high" and one that dwarfs it.
Quantitative analysis: the classic formulas
Quantitative analysis expresses risk in money and probability. The exam-canonical chain:
| Term | Meaning | Formula |
|---|---|---|
| AV | Asset Value | — |
| EF | Exposure Factor — fraction of value lost per incident | — |
| SLE | Single Loss Expectancy | AV × EF |
| ARO | Annualized Rate of Occurrence | incidents per year |
| ALE | Annualized Loss Expectancy | SLE × ARO |
The chain's power is decision support: a control costing $50,000 a year that cuts ALE from $340,000 to $90,000 justifies itself in one line. Cost-benefit, insurance sizing, and security budget defence all run on this arithmetic, and it is the only language some CFOs will accept.
Its weakness is the inputs. EF and ARO are estimates, often resting on thin incident history, and a precise-looking output inherits all their uncertainty while appearing to have none. The classic sin is false precision: "$342,750 expected loss" computed from an ARO somebody guessed in a meeting.
A number is not more true than a judgment. It is the same judgment wearing a suit.
More sophisticated quantitative methods — FAIR-style factor models, Monte Carlo simulation over ranges instead of point estimates — address this by carrying uncertainty through the calculation and reporting distributions ("90% chance annual loss falls between $80k and $600k"). They cost more effort and demand more skill, which is exactly why they are reserved for the risks that matter most.
How mature programs actually choose
Not either/or but layered. Qualitative analysis triages the full register — fast, inclusive, complete. The handful of risks that are large, decision-laden or board-visible then get quantitative treatment, because those are the decisions where the cost of better analysis is smaller than the cost of a wrong call. The hybrid (semi-quantitative) middle — calibrated scales with defined monetary bands behind each rating — disciplines the qualitative layer without the full cost of modelling.
Three practical rules. Define every scale point in observable terms ("Major = customer-facing outage > 8h or loss > $1M"), or qualitative ratings are noise. Never average or multiply ordinal scores as if they were measurements. And when you do go quantitative, present ranges, not points — precision you don't have is credibility you'll lose.
Exam angles
CRISC and CISSP test this area predictably. Memorise the formula chain — SLE = AV × EF, ALE = SLE × ARO — because direct calculations appear. Expect "which approach is MOST appropriate" scenarios: limited data, many risks, broad participation point qualitative; cost-justifying a specific control, comparing against insurance, or briefing in financial terms point quantitative. And remember the trap option: the answer that treats heat-map scores as arithmetic is always wrong.
The mature position is neither faith in numbers nor comfort in colours. It is knowing that both approaches are structured judgment — and choosing, per decision, how much structure the judgment deserves.