Is qualitative risk assessment finished now that boards can get quantitative answers?
No, but its job has changed. Cheap access to data, lakehouse architectures and the ability to pull unstructured sources have genuinely moved several risk categories from expert judgement into measurement, and boards are increasingly ready to make quantitative decisions where the data supports it. The categories where it does not support it have not shrunk as much as the enthusiasm suggests.
Published
Maximilian Bazzi, Founder and CEOWhat has genuinely changed
The case for quantitative risk assessment has strengthened for real reasons, not only for fashionable ones. Lakehouse architectures make it practical to hold loss history, transaction data and unstructured sources such as incident reports and correspondence in one place and query them together. Boards that were previously offered a five-point scale are now being offered a distribution, and where that distribution is built on enough real data, it is a genuinely better answer, not a more sophisticated-looking version of the same guess.
Several risk categories have moved as a result. Certain operational loss types with enough historical incidents behind them, credit and market exposures with long-established quantitative disciplines already, and increasingly cyber incident costs, where claims and breach data has accumulated enough volume to be usable, now support genuine quantitative treatment where a purely qualitative heat map would have been the only option a decade ago.
Why the case is overstated for the categories that have not moved
The categories that have not moved have not shrunk as much as the current enthusiasm for quantitative risk suggests. Conduct risk, strategic risk, reputational risk and genuinely novel scenarios, the kind with no comparable prior event to calibrate against, do not have the transaction volume or loss history a credible quantitative model needs. Building a model for these categories anyway does not remove the underlying judgement. It relocates that judgement into the model's inputs, where it becomes harder to see and easier to mistake for measurement.
The carried fact that separates the two cases
If the quantitative model's inputs are themselves expert estimates rather than observed data, the output is a qualitative assessment wearing a number. This is the single test worth applying before trusting any quantitative risk figure presented to a board: ask where each input came from. A loss distribution built on ten years of incident data deserves quantitative confidence. A loss distribution built on three practitioners' best guesses of frequency and severity deserves qualitative confidence, regardless of how precisely the resulting number is expressed.
A rule for which categories go which way
The dividing line is data volume and comparability, not the importance of the category or the sophistication of the tooling available. A category with enough independent, comparable historical observations to calibrate a distribution against is a candidate for quantitative treatment. A category that depends on judgement about intent, culture, or a scenario genuinely without precedent is not, and dressing it in a quantitative model adds false precision rather than removing judgement from the answer.
How Bazzi Consulting helps
We assess which of your risk categories the data genuinely supports moving to quantitative treatment, and keep the rest honestly qualitative rather than quantified for appearance's sake. See risk and resilience advisory.