One risk, quantified properly
The matrix asks you to pick a single consequence number for a risk that has a range of them. When a real decision hangs on that risk, model the range.
There is a moment in most risk committee meetings that everyone recognises and nobody enjoys. A risk is up for review, the matrix says High, and the argument starts about whether the consequence is really a 4 or actually a 3. Twenty minutes later the argument has not converged, because it cannot: both sides are right. The plausible bad outcome for that risk runs from an inconvenience to a company-defining loss, and the matrix has asked the room to compress that whole range into one cell.
The standard knows this. Buried in IEC 31010's own limitations list for the consequence/likelihood matrix is the exact defect: it "requires a single indicative value for consequence to be defined, whereas in many situations a range of consequence values are possible and the ranking for the risk depends on which is chosen". The twenty-minute argument is not a failure of the people in the room. It is the technique running out of road.
For most of the register, that is fine. A matrix rating is cheap, fast, and good enough to sort sixty risks into the ones that need attention and the ones that do not. The trouble starts when a real decision, usually a spending decision, hangs on one specific risk. Approve the $400k control program or not. Accept the vendor's limitation of liability or negotiate. Self-insure or transfer. At that point "High, probably" is not an input a decision deserves, and the honest move is to take that one risk out of the matrix and model it.
What modelling one event means
Single-event quantification is a Monte Carlo model of one risk event: the likelihood of the event occurring in a period, the range of consequences if it does, and the controls and treatments that modify both. Instead of one indicative consequence value, you give each impact a distribution, a low, likely and high with a shape, and instead of one likelihood word, a probability the drivers support. The simulation then plays the year out thousands of times and hands back the distribution the matrix could not hold: the chance of a quiet year, the typical loss when it is not quiet, and the tail you actually fear.
Monte Carlo earns its place here for the reason the standard gives: once inputs are distributions rather than numbers, "it is often not possible to derive analytical solutions", and simulation is the practical way of doing the arithmetic. Nothing about the method is exotic. It is the same technique cost engineers run across whole project registers, pointed at a single event.
The output that changes meetings is not the headline exposure figure. It is what happens when you run the model twice.
The two-pass trick
Run the model once with the controls you have. Run it again with the proposed treatment in place, reducing the likelihood, the impact, or both. The difference between the two runs is the treatment's expected benefit, in dollars, on the same assumptions both times. Put the treatment's cost next to it and you have the thing the committee was actually trying to decide: whether this control earns its keep at the margin.
This is where single-event modelling beats both of its neighbours. The matrix cannot do it at all: move a risk from High to Medium and you have recorded an intention, not measured a benefit. A full register quant does it but at the cost of modelling everything, when the decision in front of you concerns one risk. IEC 31010's guidance on technique selection says the effort "should be scaled to the significance of the decision", and a significant decision about a single risk is precisely the case for quantifying that risk alone.
One warning from honest experience of the pattern: sometimes the two-pass result says the celebrated treatment does not pay. The reduction is real but the cost is larger than the expected benefit at any plausible reading of the inputs. That result feels like the model failing. It is the model working. A cost-benefit table that only ever endorses the proposal is decoration, and the whole point of doing the arithmetic is that it is allowed to come back negative.
Keeping it honest
Quantifying one event does not make the inputs true, and a model this small has nowhere for bad inputs to hide. Three disciplines keep it defensible.
Elicit ranges, not points, and write down whose ranges they were. A distribution built from one person's guess is one person's guess with better formatting. The gain over the matrix is that the guess is now explicit, inspectable and arguable line by line.
Report percentiles as statements about the model. "The P90 annual exposure is $2.1M" means: in 90% of simulated years, on these assumptions, the loss was at or below $2.1M. It is not a promise about next year, and it collapses the moment the assumptions do.
And resist the slide into false precision. The matrix's other documented limitation, that its use "is very subjective and different people often allocate very different ratings to the same risk", does not vanish because the subjectivity now enters through distribution parameters. What changes is that the subjectivity is on the record, attached to named inputs, where a reviewer can find it and a better estimate can replace it.
Where to draw the line
Not every risk deserves this. The matrix remains the right tool for sorting the register, and a full register simulation remains the right tool for funding a project contingency. The single-event model owns the middle case: one risk, materially uncertain in its consequence, with a genuine decision attached. If the twenty-minute argument about 4-versus-3 has a budget line waiting on its answer, that is the signal.
Event Risk Exposure is a free browser tool built for exactly this shape: multi-driver causes, impact distributions, shared controls, treatments with per-treatment cost-benefit and ROI from the two-pass comparison, and a seed field so a result you put in a paper can be reproduced to the dollar. The worked example walks a customer data breach through the whole method, including a treatment the arithmetic declines to endorse. The methodology page covers the model in detail, including the parts that deserve scepticism.
The next time the room starts arguing about which single number to give a risk that obviously has a range, the productive answer is on the table: stop compressing, and model the range.