Residual risk is what is left once your controls are working. You score the risk twice: once as it would be with nothing in place, and again with your controls counted. The second number is the residual risk, and it is the one you compare against your risk appetite.
Inherent and residual
Both numbers are worth keeping, because the distance between them is the only direct evidence you have that a control is doing something.
| Inherent risk | Residual risk | |
|---|---|---|
| Scored | Before controls | After controls |
| Answers | How bad could this be if we did nothing? | How bad is it now, given what we do? |
| Used for | Prioritising which risks deserve controls | Deciding whether to accept, and proving control value |
If a risk scores the same before and after, your controls are not reducing it. That is worth investigating rather than recording, because it usually means the control addresses a different risk than the one it is linked to.
Accepting one is a decision, not a default
Residual risk below your appetite can be accepted. What matters is that acceptance is explicit: a named person, a date, and a reason. An unaccepted risk sitting quietly in the register is the version auditors object to, because nobody has taken responsibility for it.
Above appetite, you have three options rather than one: add controls, transfer the exposure through insurance or contract, or stop the activity. Choosing to do nothing is also available, but it has to be recorded as a decision at the right level.
How it is scored
Most methods reuse the same scale for both passes, so the two numbers are comparable. In Tidal Control you set likelihood and impact for the inherent risk, choose a treatment, then set them again with your controls in place, and the residual score is calculated the same way.
See the likelihood and impact matrix for the grid both scores land on, and re-score after the controls change rather than at the next annual review.