Residual Risk

Remaining risk level after implementing mitigating measures.

Residual risk is what is left once your controls are working. You score the risk twice: once as it would be with nothing in place, and again with your controls counted. The second number is the residual risk, and it is the one you compare against your risk appetite.

Inherent and residual

Both numbers are worth keeping, because the distance between them is the only direct evidence you have that a control is doing something.

Inherent riskResidual risk
ScoredBefore controlsAfter controls
AnswersHow bad could this be if we did nothing?How bad is it now, given what we do?
Used forPrioritising which risks deserve controlsDeciding whether to accept, and proving control value

If a risk scores the same before and after, your controls are not reducing it. That is worth investigating rather than recording, because it usually means the control addresses a different risk than the one it is linked to.

Accepting one is a decision, not a default

Residual risk below your appetite can be accepted. What matters is that acceptance is explicit: a named person, a date, and a reason. An unaccepted risk sitting quietly in the register is the version auditors object to, because nobody has taken responsibility for it.

Above appetite, you have three options rather than one: add controls, transfer the exposure through insurance or contract, or stop the activity. Choosing to do nothing is also available, but it has to be recorded as a decision at the right level.

How it is scored

Most methods reuse the same scale for both passes, so the two numbers are comparable. In Tidal Control you set likelihood and impact for the inherent risk, choose a treatment, then set them again with your controls in place, and the residual score is calculated the same way.

See the likelihood and impact matrix for the grid both scores land on, and re-score after the controls change rather than at the next annual review.

Frequently asked questions

What is residual risk?
Residual risk is the risk that remains after your controls are in place. It is what is left of the inherent risk once mitigation has been applied, and it is never automatically zero.
What is the difference between inherent and residual risk?
Inherent risk is the exposure before any controls; residual risk is the exposure after them. The gap between the two is what your controls actually buy you.
Who has to accept residual risk?
The risk owner, not the security team. ISO 27001 requires the risk owner to approve the treatment plan and explicitly accept the remaining risk, and that documented acceptance is what an auditor asks to see.