What “residual risk” actually means
A short definition, and the two questions a board should ask whenever the phrase appears in a paper.
Residual risk is the risk that remains after controls have been applied. Inherent risk is what you would face with no controls at all; residual risk is what you are actually carrying today.
Why the distinction matters
Boards approve residual risk, not inherent risk. When a paper says a risk is “mitigated”, that is not a status — it is a claim that residual risk has fallen to a level someone has accepted. The useful question is who accepted it, and against what threshold.
Two questions to ask
- What is the residual score, and who signed for it? Risk acceptance is a decision with a name attached. If no name appears, the risk has not been accepted — it has been noted.
- What would it cost to move it one band? This converts a colour on a heat map into a budget decision, which is the only form in which a board can act on it.
A common error
Residual risk is frequently scored by asking how effective a control is in design. It should be scored on how effective it is in operation, which is a different number and usually a worse one. A control that exists but is bypassed under deadline pressure has not reduced residual risk, whatever the policy says.
Related terms: inherent risk, risk appetite, risk tolerance, control effectiveness, risk acceptance.
