Quantified Risk Estimate
Expressing a risk as a probability distribution over financial loss rather than as a colour, which makes risks comparable and mitigations arguable on cost.
The ubiquitous five-by-five matrix produces categories: this is high, that is medium. Two high risks cannot be compared, a mitigation cannot be justified against its cost, and the aggregate of thirty medium risks is unknown — because ordinal categories cannot be summed.
Quantification, in the style of the FAIR method, expresses risk as an annualised loss distribution: frequency of occurrence multiplied by magnitude, both as ranges with confidence intervals rather than point estimates. The output is a curve — a ten percent chance of losing more than a stated amount in a year.
That output supports decisions the matrix cannot. A control costing a known amount can be compared with the loss reduction it produces. Risks across different domains become comparable. The portfolio can be aggregated.
The standard objection is that the inputs are estimates. They are, and so are the matrix's — the matrix simply hides it behind a colour. Calibrated estimation with explicit ranges is more honest than a category that implies precision it does not have.
The genuine cost is effort, which is why the sensible arrangement is quantification for the small number of risks where the decision is expensive, and a qualitative screen for the rest.