A fundamental question in software quality management is whether quality measures pay back their costs, i.e., whether they have a positive return on investment? This question especially arises during software maintenance when budgets are small, schedules are tight, and aged source code has to be dealt with. We propose a practical risk-based model that allows judging the cost effectiveness of quality measures by estimating risk as a monetary value using results of static code analysis tools.