Types of Risk Assessment

Photo of author
Written By Chris Ekai

The six main types of risk assessment are qualitative, quantitative, semi-quantitative, asset-based, vulnerability-based, and threat-based. Qualitative methods rank risks descriptively, quantitative methods price them in numbers, and the remaining types change the starting point of the analysis. Pick by decision stakes and data available; high-stakes calls deserve quantified methods.

In 2018, engineer Frank Morabito handed the Champlain Towers South condo association a report documenting major structural damage beneath the pool deck, with a repair estimate attached. On June 24, 2021, the Surfside, Florida tower partially collapsed at 1:30 in the morning, killing 98 people.

The risk assessment existed; its type failed the moment. A qualitative condition survey names damage without pricing collapse probability or time-to-failure, and the association was still debating assessments when the building fell; the class settlement passed $1 billion within a year.

Types of Risk Assessment: Key Takeaways
Six types of risk assessment cover practice: qualitative, quantitative, and semi-quantitative describe how results are expressed; asset-based, vulnerability-based, and threat-based describe where the analysis starts.
Real programs combine one from each group: a threat-based assessment can be scored qualitatively or priced quantitatively, and the pairing is a choice, never an accident.
Surfside’s Champlain Towers South had a 2018 engineering report naming major structural damage; without quantified urgency it never forced the repair vote. 98 people died on June 24, 2021, and the settlement passed $1 billion.
Precision follows stakes: qualitative for screening, semi-quantitative for ranking, quantitative (Monte Carlo, FAIR, expected loss) when the decision is expensive to get wrong.
IEC 31010:2019 catalogs 40+ assessment techniques; NIST SP 800-30 defines the asset, vulnerability, and threat lenses for information risk.
Match the type to the domain and regulator: OSHA hazard analysis for safety, HHS SRA for HIPAA, HACCP for food, ICH Q9 for pharma, FAIR for cyber dollars.

We choose assessment types for clients weekly, and Surfside is the case we teach from: the choice of type decides whether findings move budgets. NIST’s technical findings, released in June 2026, traced the failure to the pool deck connections the 2018 report had flagged.

What the Types of Risk Assessment Have in Common

Every type answers the same three questions from a different angle: what can happen, how likely, how bad. That shared skeleton is the risk assessment process itself, standardized in ISO 31000 as identification, analysis, and evaluation; the types in this guide are strategies for running that skeleton, chosen to fit the decision.

The six divide into two working groups, and seeing the split saves hours of confusion. Qualitative, semi-quantitative, and quantitative describe how results get expressed, while asset-based, vulnerability-based, and threat-based describe where the analysis starts; a real program pairs one from each group, which is why the flat six-item lists in most articles confuse more than they teach.

Types of Risk Assessment

Figure 1. Types of risk assessment in two groups: expression on top, starting point below.

The technique catalog behind all six is bigger than most teams realize. IEC 31010:2019, the companion standard to ISO 31000, documents more than 40 assessment techniques from brainstorming through Bayesian networks, each mapped to the process stage it serves; our methodology guide walks the selection logic.

When the Wrong Type Costs Everything

Surfside shows the stakes of that selection logic. The 2018 report was competent within its type: a visual condition assessment that documented spalling, failed waterproofing, and deteriorating slabs, exactly what the format asks for. What the format never asks for is a probability of structural failure or a deadline.

Types of Risk Assessment

Figure 2. Three years sat between the written finding and the collapse; the report format carried no clock.

A quantified structural assessment behaves differently in a boardroom. When a finding arrives as a failure probability with a confidence range and a cost curve, deferral becomes a decision someone must sign, the dynamic how you manage risk formalizes as risk acceptance; descriptive findings let deferral stay nobody’s decision.

The pattern repeats far from structural engineering. Screening-level risk assessments get stretched to answer questions they cannot carry, from a 5×5 grid deciding a nine-figure investment to a checklist standing in for a fire safety review; the fix is never a better checklist, it is moving up the precision continuum when stakes rise.

The Six Types of Risk Assessment Compared

Here is the working taxonomy in one table, expression types first and starting-point types below them. Each row carries the core question the type answers and the situation where it fits best, with the deeper method links carried in the sections that follow.

Type Core question it answers Where it fits
Qualitative Which risks deserve attention first? Screening, workshops, low-data environments
Semi-quantitative How do scored risks rank against each other? Register ranking, audit planning, site comparisons
Quantitative What is the exposure worth in numbers? Capital decisions, insurance limits, safety cases
Asset-based What do we own and what would its loss cost? IT estates, facilities, anything inventoriable
Vulnerability-based Where are we weak regardless of attacker? Patch programs, structural surveys, audits
Threat-based Who or what targets us, and how? Security programs, fraud, geopolitical exposure

These risk assessment types sit on a continuum of precision and cost. Qualitative work runs on a 5×5 matrix with anchored likelihood definitions; semi-quantitative scoring adds weighted scales; full quantification brings Monte Carlo simulation and expected-loss models priced in currency.

Types of Risk Assessment

Figure 3. Risk assessment precision rises left to right, with data demands and defensibility.

Moving right on that continuum is a budget decision, so make it explicitly. We quantify when the decision is expensive to reverse, when regulators or courts will probe the basis, or when ranking ties need breaking; everything else stays qualitative on purpose, documented in the step-by-step process so reviewers can see the choice.

Asset, Vulnerability, or Threat: Picking a Cyber Lens

The starting-point types were codified by information security and now travel everywhere. NIST SP 800-30 builds its method on the triad: threats exploit vulnerabilities to harm assets, and a risk assessment can enter that chain at any of the three points, with different blind spots at each entrance.

Lens Strength Blind spot
Asset-based Complete inventory view; maps to budgets and insurance Misses attack paths that chain minor assets
Vulnerability-based Actionable fix lists; feeds patch and repair programs Weights every weakness equally without threat context
Threat-based Realistic scenarios; prioritizes by adversary intent Underweights decay and accidents nobody targets

Mature programs rotate through all three lenses on a schedule instead of picking a favorite. CISA’s assessment services follow that rotation for critical infrastructure, and NIST IR 8286 wires the outputs into enterprise risk reporting so the three views reconcile in one register.

For quantification inside the cyber lenses, the FAIR model prices loss-event frequency and magnitude in dollars, which turns a threat-based finding into a board-grade number. Pair it with scenario-based assessment when the threat is novel and history offers no frequency data.

Matching the Assessment Type to the Decision

Risk assessment selection is a two-axis judgment, and the axes are stakes and data. Plot the decision before choosing the method: high-stakes calls justify buying the data that quantification needs, while low-stakes screening should stay cheap and fast, a discipline risk identification tools support at the front end. Completed risk assessment examples show what each band’s paperwork looks like.

Types of Risk Assessment

Figure 4. Stakes set the risk assessment precision floor; data sets what is feasible today.

Domain Type pairing that fits Anchor framework
Workplace safety Vulnerability-based, qualitative to semi-quantitative OSHA hazard identification and JHA
Healthcare privacy Asset-based, semi-quantitative HHS Security Risk Assessment (HIPAA)
Food production Vulnerability-based, semi-quantitative HACCP with scored severity bands
Pharma and cleanrooms Vulnerability-based, semi-quantitative ICH Q9(R1) quality risk management
Cybersecurity Threat-based, quantitative where stakes demand NIST SP 800-30 with FAIR pricing
Environmental exposure Quantitative dose and pathway modeling EPA human health risk assessment

Regulated domains often fix the pairing for you. OSHA’s hazard identification expectations shape safety work, the HHS SRA tool carries the HIPAA risk assessment, and EPA’s risk assessment framework governs exposure modeling; check the regulator’s template before inventing one.

Domain guides on this site carry the worked detail: HACCP scoring for food plants, environmental monitoring assessment for cleanrooms under ICH Q9(R1), and country risk indicators for jurisdiction exposure; each is one of these six risk assessment types wearing domain clothing.

Types of Risk Assessment FAQs: Expert Answers

These questions surface in training sessions and audit interviews whenever the risk assessment taxonomy comes up. Each answer leads with the practical rule, and the links carry the worked methods; if a question maps to your live decision, start with the quadrant above and confirm against the answer here.

What are the five main types of risk assessment?

Five-type lists usually name qualitative, quantitative, generic, site-specific, and dynamic risk assessment, a framing common in UK safety practice. The six-type taxonomy here absorbs them: generic and site-specific are scoping choices, dynamic assessment is a rapid qualitative cycle, and the expression and starting-point groups cover the rest.

What is the difference between qualitative and quantitative risk assessment?

Qualitative risk assessment expresses likelihood and impact in descriptive scales and produces a ranked list; quantitative risk assessment expresses them as probabilities and monetary values and produces an exposure number. The practical divider is defensibility: rankings guide internal priorities, while numbers survive board challenge, regulator scrutiny, and litigation.

When should a semi-quantitative risk assessment be used?

Use semi-quantitative scoring when you need forced ranking across many risks but lack the data or budget for full quantification: register prioritization, audit planning, and multi-site comparisons are the classic cases. Scored scales with anchored definitions remove most of the subjectivity that pure ratings carry, at almost no extra cost.

Which type of risk assessment does a small business need?

Start qualitative with a 5×5 matrix and anchored scales, run it on the cadence your volatility demands, and quantify only the one or two exposures that could end the business. Regulated activities override this default; a safety, food, or health-data obligation fixes the method regardless of company size.

Is a risk assessment the same as a risk analysis?

Analysis is one stage inside assessment: identification finds the risks, analysis estimates likelihood and impact, and evaluation compares results against criteria. Assessment covers all three, and management then acts on the output; the six types in this guide are strategies for the whole assessment span.

What type of risk assessment does cybersecurity use?

Threat-based assessment under NIST SP 800-30 dominates, layered on asset inventories and vulnerability scans, so mature security programs actually run all three starting-point types on rotation. Quantification through FAIR converts the top findings to dollars, and data integrity reviews keep the inputs trustworthy.

The Mistakes Assessment Teams Keep Making

Type-selection errors repeat so reliably that we screen for them first in every risk assessment program review. The table pairs the six most common with the correction that works, and the first row is Surfside’s row; treat it with the respect the case has earned.

Mistake Why it happens Correction
Screening tool carrying a high-stakes call The matrix was already there and cheap Precision floor rule: stakes set the minimum type
One lens run forever Familiarity; last year’s template Rotate asset, vulnerability, and threat views
Quantification theater False precision pasted on guessed inputs Publish ranges and confidence, never point estimates
Type chosen after the conclusion Method picked to justify a decided answer Log the type choice before fieldwork starts
Findings without deadlines Format lacks a clock, Surfside-style Every finding carries a review-by date and owner
Ignoring the regulator’s template Teams invent instead of checking Map the domain to its anchor framework first

The quantification-theater row deserves its own warning, because numbers borrow authority. The Society for Risk Analysis has spent decades on honest uncertainty communication, and the working rule is simple: a quantitative assessment that hides its input quality is a qualitative assessment wearing a lab coat.

The Next Wave: Trends Practitioners Can’t Ignore

Expect quantification to keep spreading downmarket through 2028. Tooling that once demanded consultants now ships in software, GAO’s risk framework work keeps pushing US agencies toward evidence-based methods, and boards that have seen one FAIR-style dollar figure stop accepting color grids for material exposures.

Continuous assessment is the second shift. Sensor data, telemetry, and live registers are collapsing the annual risk assessment cycle into standing dashboards, which changes the type question from which assessment to run into which feeds deserve quantified models; the NIST findings on Surfside will harden inspection cadences in the same direction.

AI will pressure both groups of types. Machine-assisted identification widens the risks a team can see while creating model-risk exposures that need their own risk assessments, and the honest position is that every AI-scored register still needs the anchored scales and documented type choice this guide describes.

If your register cannot say which type produced each score, the register is the first thing to fix. We select and build assessment programs across all six types, from matrix design through Monte Carlo; our services outline the formats, and a message through the contact page with your highest-stakes open decision starts the scoping.