Glossary

Residual Risk

Remaining risk level after implementing mitigating measures.

A

B

C

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

Residual risk is the level of risk that remains after all identified controls and mitigation measures have been applied. No control environment can eliminate risk entirely, so residual risk represents the exposure an organisation consciously accepts. It is calculated by considering the original risk level minus the effectiveness of implemented controls.

Understanding residual risk is essential for informed decision-making by senior management. If the residual risk exceeds the organisation's defined risk appetite, additional controls must be implemented or the risk must be transferred, for instance through insurance. Documenting residual risk in the risk register ensures ongoing visibility and facilitates periodic reassessment.

S

T

U

V

W

Z

Frequently asked questions

What is residual risk?
Residual risk is the risk that remains after your controls are in place. It is what is left of the inherent risk once mitigation has been applied, and it is never automatically zero.
What is the difference between inherent and residual risk?
Inherent risk is the exposure before any controls; residual risk is the exposure after them. The gap between the two is what your controls actually buy you.
Who has to accept residual risk?
The risk owner, not the security team. ISO 27001 requires the risk owner to approve the treatment plan and explicitly accept the remaining risk, and that documented acceptance is what an auditor asks to see.