- Compliance & Regulation, Risk
Quantitative and Qualitative Risk Measurement: Why Balance Matters in Uncertain Times
Robert Sales
Share
Driven by rising geopolitical fragmentation, transformative technology, and the increasing complexity and escalation of cyber threats and financial crime, financial institutions are reassessing their approach to risk measurement. To avoid falling behind competitors and potentially missing key risk indicators, firms must supplement traditional quantitative analysis with qualitative assessment.
Indeed, in today’s volatile and uncertain markets, there is a greater need than ever for qualitative, forward-looking tools that can assess both fast-moving events and growing tail risks, which are extremely difficult to predict.
“Tail events appear to be occurring with greater frequency, and the operating environment suggests that volatility will remain a defining feature rather than an exception. While tail risk is inherently difficult to predict, qualitative tools can help firms think more rigorously about plausible scenarios, early warning indicators, and response options,” says Joseph Iraci, founder and CEO of Atlas Quotient and a member of ProSight’s Editorial Advisory Council. “The goal is not to forecast every shock precisely, but to improve preparedness—whether that means mitigating downside exposure or positioning the firm to act on opportunities that arise from disruption.”
Of course, when building a risk measurement framework, the choice between quantitative and qualitative tools is not an “either/or” decision. Rather, a balanced approach is necessary to assess everything from credit and market risk to operational resilience, culture and governance, and emerging risk.
Iraci, the former CRO and Head of Enterprise Risk Management and Internal Audit at Robinhood, knows this from firsthand experience. Prior to Robinhood, he was the CRO of TD Ameritrade, TD Ameritrade Clearing, and TD Ameritrade Futures & FX, LLC. Today, in addition to his CEO post at Atlas Quotient, he is an instructor for an advanced risk management program co-sponsored by ProSight and the Wharton School of Business.
ProSight recently spoke with Iraci about the evolution of qualitative and quantitative approaches, the impact of AI and geopolitics in risk measurement, the best approach for assessing emerging risk, and trends that could shape the future of risk measurement.
ProSight: Do you think financial institutions have traditionally over-relied on quantitative risk management? If so, what do you see as the limitations of a heavy quantitative approach?
Iraci: I would frame it less as over-reliance and more as a reflection of the tools available at the time. Quantitative models became central to risk management because they aligned with the data, computing power, and analytical methods firms could practically use. The limitation is that quantitative models are strongest when the future resembles the past.
In a more volatile environment, firms need to complement quantitative techniques with qualitative assessments that capture emerging risks, changing behaviors, and scenarios that historical data may not fully reveal.
In which areas of risk management (e.g., credit risk, market risk, operational risk, or culture and governance) are qualitative tools most necessary today?
Qualitative tools are most valuable where risks are difficult to observe, measure, or reduce to historical data. That makes them especially important for non-financial risks such as operational resilience, culture, conduct, and governance. By contrast, market and credit risk typically benefit from deeper pools of financial data, which makes them more naturally suited to quantitative modeling.
How has geopolitical volatility changed the risk measurement landscape?
Geopolitical fragmentation has made the risk landscape more uncertain and less linear. Business leaders and investors are generally more comfortable assessing known risks than navigating uncertainty created by shifting alliances, trade barriers, sanctions, regional conflicts, and competing spheres of influence.
This is precisely the type of risk that requires qualitative analysis: firms need to evaluate a range of possible outcomes, understand second- and third-order effects, and consider how political developments could alter markets, operations, and strategy.
What do you see as AI’s role today? Is it more of a qualitative or quantitative tool, and what are the pros and cons of this technology in the risk assessment space?
AI should be viewed as an enabling technology rather than a replacement for risk judgment. Its immediate value lies in helping firms gather information faster, detect patterns across larger data sets, test scenarios, and improve the speed and consistency of analysis. That can support both risk identification and risk quantification.
The challenge is that AI also introduces model risk, governance questions, explainability concerns, and the potential for overconfidence in outputs that may appear precise but still require human interpretation. The firms that benefit most will be those that use AI to strengthen, not substitute for, experienced risk oversight.
These are all good points, but can you elaborate on what you think the specific role of AI is, or could be, in risk measurement?
In risk measurement, AI’s most useful role is to expand the range and speed of analysis. It can help ingest large volumes of structured and unstructured data, identify patterns that may not be visible through traditional methods, and support scenario design, monitoring, and reporting.
Over time, AI could make risk measurement more dynamic by allowing firms to refresh assumptions more frequently and connect signals across business lines. But the technology still needs strong governance. Human experts must define the questions, challenge the outputs, and decide how AI-generated insights should influence business decisions.
U.S. regulators have recently omitted “reputation risk” from supervisory frameworks. What’s the rationale behind this decision, and is this another indicator of the importance of qualitative risk assessment tools in evaluating hard-to-define issues such as reputation, culture and human capital?
I cannot speak for the regulators, but one likely reason is that reputation risk is exceptionally difficult to define and measure consistently. That does not make it less important. In fact, reputation is often where the limits of traditional metrics become most visible.
Firms may recover from a financial loss, but reputational damage can have longer-lasting effects on customers, employees, counterparties, and franchise value. Risk managers and business leaders therefore need tools that help them evaluate these less tangible exposures before they become enterprise-level problems.
Do you have any recommendations for specific tools that financial institutions can deploy today to try to more effectively measure reputation risk?
Scenario analysis and stress testing are two practical tools firms can use today. Together, they allow management to examine how reputational issues could develop across different conditions, how quickly they might spread, and what actions would be needed to contain the impact.
As the technology supporting these exercises improves, firms can build a more complete view of their operating environment and make reputation risk part of strategic planning, rather than a reactive concern.
I know you’ve spoken previously on the evolution of perspectives of human capital. Do firms now have a broader view on what people risk means? In the past, people have been judged primarily by their downside risk (such as misconduct and internal fraud) but are now starting to be seen through a wider lens as drivers of firm value, or a source of strategic risk, correct?
Yes. Firms are increasingly recognizing that people risk is not only about preventing misconduct, fraud, or control failures. Human capital is also a source of resilience, innovation, and competitive advantage. Attracting, developing, and retaining the right talent can directly influence a firm’s strategic options and long-term value.
Even as AI becomes more embedded in business processes, experienced professionals will remain essential for interpreting information, exercising judgment, and making decisions in uncertain conditions.
What do you see as the best risk measurement approach for emerging risks, like supply-chain disruptions, ESG and cyber threats?
Emerging risks require a disciplined framework, not a reactive process that chases every possible threat. Firms should begin by defining the risk clearly, identifying the conditions under which it could become material, and assessing both likelihood and potential impact.
From there, risk teams can prioritize the risks that matter most and translate the analysis into practical guidance for management. The approach may rely heavily on qualitative judgment, but it should still be structured, evidence-informed, and connected to business decisions.
Which risk measurement trends do you think financial institutions will need to pay close attention to over the next 12 months?
Three trends deserve close attention.
First, institutions need to monitor the level of outstanding debt across the global economy. Many governments have used debt issuance to address spending pressures, and elevated debt levels could limit fiscal flexibility in a future crisis.
Second, firms should remain focused on geopolitical fragmentation and the move toward a more multi-polar world, where competing spheres of influence may increase the risk of economic and political conflict.
Third, institutions need to assess political risk in the markets where they operate, especially as longstanding alliances are tested and policy direction becomes harder to predict.
Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.