In practice, most organisations manage with a qualitative approach — a likelihood × impact matrix — as long as they can defend it. A semi-quantitative approach works with indices, a quantitative one with financial modelling. The choice depends on the requirements that apply to you, on the standards you already use and on what the organisation needs.
If you want a reference process, ISO/IEC 27005 describes one: establishing the context, identifying, analysing and evaluating risks, treating them, and monitoring and reviewing the result. It is written to fit ISO/IEC 27001. If you already have a methodology in place — because of ISO/IEC 27001 or group rules, for example — there is no point in replacing it.