Inherent risk is the exposure before your controls; residual risk is what remains after them. Most registers record only the second, which quietly destroys the most useful piece of information the exercise produces: how much work your controls are doing.
The definitions
- Inherent risk - the level of risk assuming the relevant controls are absent or ineffective. Not "if the company did not exist"; just this risk, without the mitigations you have chosen to place against it.
- Residual risk - the level remaining once existing controls operate as designed. This is the number compared against risk appetite and the number that drives accept/treat decisions.
- Target risk - where you intend to be after planned treatment. Optional, but it makes a treatment plan measurable.
Why the gap is the interesting number
The distance between inherent and residual is a direct measure of control reliance. A risk that drops from critical to low is being held there entirely by controls - which means:
- If those controls fail, the exposure returns to critical immediately.
- They deserve stronger monitoring, testing and change control than controls holding a small gap.
- Nobody should quietly decommission them in a cost-saving exercise, which is exactly what happens when only the residual number is visible.
This is the answer to "why are we still spending on this, the risk is low?" - the risk is low because of the spend. Without the inherent figure recorded, that argument is anecdotal.
Track both scores without the spreadsheet
GRC Copilot records inherent and residual scores per risk, links the controls holding the gap, and shows what happens to your exposure when one of them is failing.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Scoring the two consistently
The usual method is likelihood x impact for both, with one rule that keeps the pair honest: controls normally reduce likelihood, rarely impact. Access controls make a breach less likely; they do not make it less damaging once it happens. Impact reduction comes from a narrower set - encryption, segmentation, backups, insurance, data minimisation.
If your residual impact scores are consistently lower than inherent across the register, the scoring is probably wrong.
Common mistakes
- Scoring inherent risk as an apocalypse. "No controls at all" for every risk pushes everything to critical and the scale becomes meaningless. Assume the control being assessed is absent, not that the organisation is lawless.
- Scoring residual on the control as designed rather than as it operates. A control failing its tests should not be reducing anything. Residual scores must reflect the last assessment of effectiveness, or the register is fiction.
- Never revisiting inherent risk. It changes with the business - new markets, new data, more customers - even when controls do not.
- Recording residual only. The gap disappears, and with it your ability to justify control spend or spot fragile dependencies.
- Treating residual as objective. It is an estimate conditioned on your view of control effectiveness. Record what that view is based on.
How it drives decisions
- Score inherent. High inherent risks warrant attention even where residual is currently low - they are your fragile dependencies.
- Score residual. Compare against appetite. Above appetite means treat; within means accept and monitor.
- Where residual sits far below inherent, identify the specific controls responsible and mark them critical - they get priority in testing, change control and continuity planning.
- Where residual sits close to inherent, your controls are doing little. Either the risk is not worth mitigating, or the controls are ineffective. Both conclusions are actionable; neither is visible from residual alone.
Frequently asked questions
Do frameworks require both?
ISO 27001 requires residual risk to be determined and approved by risk owners. Inherent risk is not mandated, but it is standard practice and makes the residual figure defensible.
Should residual risk ever be zero?
No. Controls reduce risk; they do not eliminate it. A zero residual score signals a scoring problem, not an achievement.
How often should both be reviewed?
At least annually, and whenever a control's effectiveness rating changes or the business context shifts. A control that failed testing should move its residual score the same week.
Who approves residual risk?
The risk owner - a business leader with authority over the activity, not the security team. Acceptance without that authority is not acceptance.
Key takeaways
- Inherent is before controls, residual after; the gap measures control reliance.
- Controls usually cut likelihood, not impact - score accordingly.
- Residual must reflect how controls actually operate, not how they are designed.
- A large gap marks a fragile dependency worth protecting, not a solved problem.