Skip to content

Qualitative risk assessment

Definition

A methodology that rates likelihood and impact on descriptive or ordinal scales (such as 1-5 or low/medium/high) and combines them in a matrix to produce a risk priority. Fast to apply and accessible to non-technical stakeholders, but inherently subjective and not directly comparable to financial metrics.

Related terms

ALE (Annualised Loss Expectancy)
The expected monetary loss from a specific threat over a one-year period. Calculated as: ALE = SLE x ARO (Annualised Rate of...
FAIR (Factor Analysis of Information Risk)
A quantitative risk framework standardised by The Open Group (Open FAIR) that decomposes risk into Loss Event Frequency and Loss Magnitude, each...
Quantitative risk assessment
A methodology that assigns monetary values to threat scenarios using metrics such as asset value, exposure factor, SLE, ARO, and ALE. Outputs...
Risk appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
SLE (Single Loss Expectancy)
The expected monetary loss from a single occurrence of a specific threat event against a specific asset. Calculated as: SLE = Asset...

Explained in

  • Risk Assessment MethodologiesA methodology that rates likelihood and impact on descriptive or ordinal scales (such as 1-5 or low/medium/high) and combines them in a matrix to produce a ris...

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.