Skip to main content

đź”” Notifications Hub: See compliance updates in one place

  • blog
  • Risk Assessment Methodologies: 6 Types, Examples + How to Choose

Risk Assessment Methodologies: 6 Types, Examples + How to Choose

  • September 30, 2026
Author

Emily Bonnie

Senior Content Marketing Manager

Reviewer

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

Every organization has more risks than it has time and budget to address. A risk assessment methodology gives you a consistent way to decide which ones matter most, so your team spends its effort on the risks that threaten operations, customers, and compliance.

That consistency is where many programs struggle. In the 2026 State of Risk Oversight study from NC State University's ERM Initiative and the AICPA, only 30% of executives described their risk oversight processes as mature or robust.

This guide explains the six most common types of risk assessment methodologies, shows how each one scores the same risk, covers established methods like NIST SP 800-30 and ISO/IEC 27005, and walks through a six-step assessment process you can use right away.

What is a risk assessment methodology?

A risk assessment methodology is the defined method an organization uses to identify, analyze, and prioritize risks. It sets the rules for how likelihood and impact are measured, what scales are used, and how scores translate into priorities, so different people assessing the same risk reach the same answer.

A methodology is narrower than a risk management framework. The framework structures your whole program, including governance, roles, and review cycles. The methodology is the scoring engine inside it. Most frameworks, including NIST CSF 2.0 and ISO/IEC 27001, let you choose your own methodology as long as it's defined and repeatable. To compare program-level frameworks, see our guide to risk management frameworks.

6 types of risk assessment methodologies

Risk assessment methodologies differ in two ways: how they measure risk (qualitative, quantitative, or semi-quantitative) and where they start looking for risk (assets, threats, or vulnerabilities). Most organizations combine one from each group, for example a semi-quantitative scoring scale applied to an asset-based inventory.

1. Qualitative risk assessment

A qualitative assessment rates likelihood and impact using descriptive categories such as low, medium, and high. Assessors work through risk scenarios, often in workshops with process and system owners, and plot each risk on a risk matrix. Risks that are both likely and severe land in the top-right corner and get treated first. For example, a team might rate "ransomware encrypts the primary file server" as medium likelihood and high impact, which places it in the high-priority zone of their matrix.

Use a qualitative approach for first-time assessments, early-stage companies, or teams without reliable historical data. It's fast and easy for the whole business to understand, though it depends heavily on judgment. Without clear definitions for each rating, two assessors can score the same risk differently, which makes it hard to compare results over time or defend decisions to leadership.

2. Quantitative risk assessment

A quantitative assessment expresses risk in numbers, usually dollars. A common formula is annualized loss expectancy (ALE):

ALE = single loss expectancy (SLE) x annualized rate of occurrence (ARO)

Say a company estimates a ransomware attack on its primary file server would cost $400,000 in recovery, downtime, and response. Based on industry and internal data, it expects that attack about once every 20 years, for an ARO of 0.05. That puts its ALE at $20,000 per year. The company can then use the same math to evaluate a control. Immutable backups and endpoint detection cost $12,000 per year and reduce the ARO to 0.01, bringing the ALE down to $4,000. Spending $12,000 to cut expected annual loss by $16,000 means the control pays for itself. More advanced quantitative models, such as FAIR, use ranges and Monte Carlo simulation in place of single-point estimates to show the full distribution of likely losses.

Use a quantitative approach when you need to justify security investments, compare remediation options, or report risk to executives and boards in financial terms. Keep in mind that the results are only as good as the inputs. Building reliable estimates takes time, data, and expertise, and precise-looking numbers can hide weak assumptions, so most teams reserve full quantification for their top risks.

3. Semi-quantitative risk assessment

A semi-quantitative assessment assigns numbers to qualitative categories so risks can be ranked and compared. The most common version uses 1-5 scales for likelihood and impact, then multiplies them for a risk score from 1 to 25. Using the scales in the scoring section below, the ransomware scenario would score a 3 for likelihood (possible) and a 5 for impact (severe), for a risk score of 15. That falls in the high band, which calls for a treatment plan within 30 days.

This is the most common approach for SOC 2 and ISO/IEC 27001 programs, and a good fit for growing teams that want more consistency than qualitative scoring without the data demands of full quantification. One caution: the scores rank risks without measuring them, so a risk scored 20 is higher priority than a 10, but not twice as risky. Clear written definitions for each level keep scoring consistent across assessors.

4. Asset-based risk assessment

An asset-based assessment starts with an inventory of what you need to protect: hardware, software, data, facilities, people, and intellectual property. Asset owners then identify the threats and vulnerabilities that could affect each asset's confidentiality, integrity, or availability. Starting from the file server in the asset register, for example, a team might identify ransomware, hardware failure, and accidental deletion as risks and assess each one.

Asset-based assessments suit IT and security teams with a well-maintained asset inventory, and they're a familiar approach for organizations pursuing ISO 27001 certification. They're thorough for known systems, but they can miss risks that don't live on a single asset, such as process gaps, human error, and third-party dependencies.

5. Threat-based risk assessment

A threat-based assessment starts with who or what could cause harm and how. Teams look at threat actors, their techniques, and the scenarios most likely to affect the organization, often drawing on threat intelligence or frameworks like MITRE ATT&CK. In the ransomware example, the team would start with ransomware groups targeting their industry, map their typical entry points (phishing, exposed remote access, unpatched VPNs), and assess how well current controls would stop each one.

This approach works well for security teams that want their priorities to reflect how real attacks unfold. It does require current threat intelligence and ongoing effort to maintain, and it can underweight non-malicious risks like outages and natural disasters.

6. Vulnerability-based risk assessment

A vulnerability-based assessment starts from known weaknesses, usually findings from vulnerability scans, penetration tests, and audits, then evaluates which threats could exploit them and what the impact would be. Risk-based vulnerability management tools add exploitability data and asset criticality to help rank findings. For example, if a scan flags a critical vulnerability with a known public exploit on the file server's operating system, the team would rate the risk as high because the server holds business-critical data, and patch it within their critical remediation window.

Vulnerability-based assessments are a strong fit for organizations with mature scanning and patching programs and good visibility into their infrastructure. They only cover weaknesses you've already found, though, so unknown vulnerabilities and non-technical risks fall outside their view.

Risk assessment methodologies compared

Methodology Starting point or scoring style Speed Data needed Best for
Qualitative Descriptive ratings (low/medium/high) Fast Low First assessments, early-stage teams
Quantitative Financial estimates (ALE, FAIR) Slow High Budget decisions and board reporting
Semi-quantitative Numeric scales (1-5 x 1-5) Moderate Moderate SOC 2 and ISO 27001 programs
Asset-based Asset inventory Moderate Asset register ISMS and IT-focused programs
Threat-based Threat actors and scenarios Moderate to slow Threat intelligence Security-mature teams
Vulnerability-based Known weaknesses Fast once scanning is in place Scan and test results Teams with mature vulnerability management

Risk Management Kit

Every methodology starts with knowing how much risk you're willing to accept. The free Risk Management Resources Kit includes a risk appetite worksheet and statement template, plus third-party risk, incident response, and disaster recovery templates.

Established risk assessment methods

Several published methods package these approaches into a documented process. Using one makes your assessment easier to explain to auditors and to repeat year over year.

NIST SP 800-30 Revision 1

NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments, is NIST's detailed guidance for information security risk assessments. It organizes the work into four steps: prepare for the assessment, conduct it, communicate the results, and maintain it over time. It also describes three analysis approaches (threat-oriented, asset/impact-oriented, and vulnerability-oriented) and includes example scales and tables for threat sources, likelihood, and impact. It's free, detailed, and widely used by organizations following NIST frameworks.

ISO/IEC 27005:2022

ISO/IEC 27005 provides guidance on managing information security risk to support an ISMS under ISO/IEC 27001. It applies the general ISO 31000 process to information security: establishing context, assessing risk, treating it, communicating, and monitoring. The 2022 edition describes both event-based and asset-based approaches to risk identification and aligns its terminology with ISO/IEC 27001:2022. Read our ISO 27005 guide for a deeper look.

OCTAVE Allegro

OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) was developed at Carnegie Mellon University's Software Engineering Institute. OCTAVE Allegro, a streamlined version, focuses on information assets: where they're stored, transported, and processed, and what threats could affect them in each of those locations. It's designed for teams that want a structured, workshop-driven assessment without extensive risk expertise.

FAIR

FAIR (Factor Analysis of Information Risk) is the most widely used model for quantitative cyber risk analysis. It breaks risk into loss event frequency and loss magnitude and uses ranges and simulation to estimate likely financial loss.

Recommended reading

Risk Management Frameworks: 10 Options Compared and How to Choose

How to build a risk scoring matrix

Whichever methodology you choose, written scoring criteria are what make results consistent. Here's an example of 5-point scales you can adapt. Adjust the dollar amounts and timeframes to fit your organization's size and risk appetite.

Likelihood scale

Score Rating Definition
1 Rare Not expected to occur in the next 5 years
2 Unlikely Could occur once in the next 3 to 5 years
3 Possible Could occur once in the next 1 to 3 years
4 Likely Expected to occur within the next year
5 Almost certain Expected to occur multiple times a year

Impact scale

Score Rating Definition
1 Minimal Negligible cost; no customer or regulatory impact
2 Minor Limited cost or disruption; handled within normal operations
3 Moderate Noticeable disruption to a business function or a small number of customers
4 Major Significant financial loss, extended outage, or reportable incident
5 Severe Threatens the business, major regulatory penalties, or widespread customer harm

Risk score bands

Score (likelihood x impact) Rating Example response
1-4 Low Accept and review annually
5-9 Medium Treat within planned work; review semiannually
10-16 High Treatment plan within 30 days; executive visibility
20-25 Critical Immediate action; escalate to leadership

A 6-step risk assessment process

Conducting regular risk assessments is a critical step in keeping your organization safe from a breach and maintaining compliance with many security frameworks. Below we outline the risk management process in six basic steps.

Step 1: Determine your organization’s acceptable level of risk

Risk is an inevitability for all businesses. But with greater awareness and understanding of those risks, companies can identify ways to either resolve, reduce, or work around them to achieve their goals. Sometimes risk can even be turned into opportunity — so it’s important to have a risk management approach that balances risk awareness and strategic risk-taking. 

Low risk can lead to stagnation and a lack of innovation. High risk can result in unnecessary losses in both time and money. Effective risk management finds a balance that allows organizations to achieve their goals while minimizing potential losses.

Defining an organization’s risk appetite typically involves a few key steps: 

  1. Define your company’s strategic objectives. What is your organization working to achieve? How much risk are you willing and able to accept in order to achieve those goals?
  2. For each of the primary targets you’ve identified, decide the acceptable level of risk. 
    undefinedundefinedundefinedundefinedundefined
  3. Communicate your risk appetite to company stakeholders. Leadership and management teams should work together to discuss risk appetite, mitigation, share feedback, and determine how it will impact day-to-day operations. Writing a risk appetite statement can clarify your strategy for leadership, employees, and other key stakeholders, and allows for more informed risk decisions throughout the company.  

Risk tolerance and risk appetite are commonly used interchangeably, but they are not the same thing.

Risk appetite is how much risk your business is willing to accept before treating it. Risk appetite varies widely based on factors like your company’s industry, financial situation, competitive landscape, and company culture. What’s the cost-benefit analysis of each risk? If you have more resources, you may be open to accepting greater risk in order to fuel a faster pace of innovation, for example. 

Risk tolerance is how much residual risk you’re willing to accept after treatment. Say you identify a risk that has a 40% probability of occurring, which falls outside your risk appetite. After treating the risk, you bring the probability of it occurring down to 10%. Is 10% residual risk acceptable for your business? 

Step 2: Select a risk assessment methodology

Ask yourself the following questions: 

  • What are you hoping to gain from the assessment? A quantitative risk assessment can provide data-driven insights, while a qualitative assessment often offers greater efficiency. 
  • What’s the scope of the assessment? Decide if the risk assessment will be conducted across your entire organization or focus on a single department or team. 
  • What compliance or regulatory requirements do you need to comply with? Some information security standards such as ISO 27001, SOC 2, PCI, and HIPAA may have specific risk assessment procedures you’ll need to follow to satisfy requirements. 
  • What cost or time constraints do you need to work around? An accelerated timeline may require a qualitative assessment over a quantitative one. Organizations that lack the internal expertise to complete a risk assessment may need to hire a third party. 

Step 3: Risk identification

Security risks are ever-changing, with new threats popping up seemingly every day. The only way to address risks is to first identify they're there.

Start with a list of information assets and then identify risks and vulnerabilities that could impact data confidentiality, integrity, and availability for each one. You’ll need to consider your hardware (including mobile devices), software, information databases, and intellectual property. 

  • Vulnerabilities are flaws in the state of your environment that could be exploited.
  • Threats are the potential for someone or something to take advantage of a vulnerability. 
  • Risks are a measure of the likelihood that a given threat will take advantage of a given vulnerability and the impact it will have on the cardholder data environment.

For example, let’s consider a software system that hasn’t been updated with a new version meant to patch a cybersecurity vulnerability. That vulnerability is outdated software, the threat is that a hacker could infiltrate the system, and the cyber security risk is not ensuring software is up-to-date. 

Consider these categories of threats and vulnerabilities:

  • Digital: Not updating software with security patches
  • Physical: Improper disposal of data
  • Internal: Employees
  • External: Hackers
  • Environmental: Natural disaster

Step 4: Risk analysis

Once you’ve identified risks, determine the potential likelihood of each one occurring and its business impact. Remember that impact isn’t always monetary — it could be an impact on your brand’s reputation and customer relationships, a legal or contractual issue, or a threat to your compliance. 

  • Risk likelihood: Consider how likely it is for a threat to take advantage of a given risk. For example, if you experienced a data breach in the last year, your likelihood of another occurring would be high unless you remediated the vulnerability that caused the breach. 
  • Risk potential: Consider the damage a risk could pose to your organization. For example, improperly configured firewalls would have a high probability for unnecessary traffic to enter or exit information systems.

Assign each risk a likelihood and impact score. On a scale from 1-10, how probable is it that the incident will occur? How significant would its impact be? These scores will help you prioritize risks in the next step. 

Step 5: Risk treatment

No business has unlimited resources. You’ll need to decide which risks you should spend time, money, and effort to address and which fall within your acceptable level of risk. 

Now that you’ve analyzed the potential impact of each risk, you can use those scores to prioritize your risk management efforts. A risk matrix can be a helpful tool in visualizing these priorities (find a free risk register + risk matrix template here). 

A risk treatment plan records how your organization has decided to respond to the threats you identified in your security risk assessment. 

Most risk assessment methodologies outline four possible ways to treat risk: 

  • Treat the risk with security controls that reduce the likelihood it will occur 
  • Avoid the risk by preventing the circumstances where it could occur 
  • Transfer the risk with a third party (i.e., outsource security efforts to another company, purchase insurance, etc.) 
  • Accept the risk because the cost of addressing it is greater than the potential damage 

Step 6: Risk control and mitigation

Now it’s time to create an action plan and decide your risk mitigation options. Risk controls can include operational processes, policies, and/or technologies designed to reduce the likelihood and/or impact of a risk. 

For example, the risk of accidental data loss can be mitigated by conducting regular information systems backups that are stored in different locations. 

Each of your identified risks should have an assigned owner who’s responsible for overseeing any risk mitigation tasks, from assigning implementation deadlines to monitoring control effectiveness.

Common risk assessment mistakes to avoid

Even a well-chosen methodology can produce unreliable results if the process around it breaks down. These are the issues that most often weaken risk assessments, along with how to prevent them.

Leaving scoring scales undefined
If "high likelihood" or "major impact" isn't defined in writing, each assessor fills in their own interpretation. Scores drift between people and from one year to the next, and you lose the ability to compare results or explain why one risk ranked above another. Write a plain-language definition for every level of your likelihood and impact scales, and share them with everyone who scores risks.

Scoring only inherent risk
Inherent risk shows how serious a risk is before controls. Residual risk shows what's left after them. Without both scores, you can't demonstrate what your controls are accomplishing or justify a decision to accept a risk. Auditors reviewing SOC 2 or ISO 27001 programs will often ask for both, so capture them side by side in your risk register.

Leaving risks without owners
A risk without an owner rarely gets treated. When accountability is spread across a team, treatment tasks slip and reviews get skipped. Assign every risk to a named individual who is responsible for tracking treatment progress, monitoring control effectiveness, and updating the score when conditions change.

Treating the assessment as an annual event
An annual assessment captures your risk picture at a single moment. New vendors, product launches, acquisitions, and security incidents can change that picture well before your next scheduled review. Build in triggers for reassessment when significant changes happen, and review high and critical risks more often than the rest of the register.

Tracking too many risks at the wrong level
A register with hundreds of granular risks becomes hard to maintain, hard to review, and hard for leadership to act on. It can also raise questions during an audit about whether the program is under control. Group related issues into clear risk statements that name the cause, event, and consequence, and keep the detail in the linked controls and treatment tasks.

Streamline risk assessments with Secureframe

However you choose to monitor and manage risk, it’s an ongoing process. An all-in-one GRC solution like Secureframe can help you evaluate security safeguards and identify weaknesses to provide a clear picture of your risk profile and security posture.

Secureframe makes it easy to build and maintain robust risk management processes: 

  • Guided assessments based on the ISO 27005 methodology, with customizable scoring scales, score groups, and tags.
  • A risk library of pre-built risks based on NIST risk scenarios to speed up identification.
  • Comply AI for Risk drafts likelihood, impact, treatment plans, and residual risk from a risk description and your company information.
  • Linked controls and owners so you can see residual risk, assign accountability, and send review reminders.
  • Historical snapshots of your risk register to show auditors and executives how risk has changed over time.

Learn more about how Secureframe can help you build a strong, scalable security posture by scheduling a demo today. 

Use trust to accelerate growth

Request a demo

FAQs

What are the main types of risk assessment methodologies?

The six most common types are qualitative, quantitative, semi-quantitative, asset-based, threat-based, and vulnerability-based. The first three describe how risk is measured; the last three describe where the assessment starts.

What's the difference between qualitative and quantitative risk assessment?

Qualitative assessments rate risk with descriptive categories like low, medium, and high. Quantitative assessments express risk in numbers, usually expected financial loss. Qualitative is faster; quantitative supports budget decisions but needs more data.

Which risk assessment methodology is best?

The best methodology depends on the decisions you need to make, your data, and your compliance requirements. Many organizations use a semi-quantitative 5x5 matrix for their full register and quantitative analysis for their top risks.

What's the difference between a risk assessment methodology and a risk management framework?

A methodology is how you score individual risks. A framework, such as NIST CSF 2.0 or ISO 31000, structures the entire risk program, including governance, roles, and review cycles.

How often should you perform a risk assessment?

Most organizations perform a full risk assessment at least annually, and many frameworks and auditors expect that. Review high risks more often, and reassess after significant changes such as new systems, vendors, or incidents.

What is residual risk?

Residual risk is the risk that remains after controls and other treatments are applied. You compare residual risk against your risk tolerance to decide whether further treatment is needed or the risk can be accepted.

Emily Bonnie

Senior Content Marketing Manager

Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.