Residual Risk
Residual risk is the amount of risk that remains after an organization has put security measures and controls in place to address a threat. Even after protective steps are taken, some level of risk typically persists because controls rarely eliminate risk entirely. It represents what an organization is left exposed to once its risk treatment efforts have been applied.
Residual risk is the portion of risk remaining after security measures, controls, or other risk treatment and remediation efforts have been applied to reduce inherent risk. It is generally understood as the difference between inherent risk (the exposure before controls are accounted for) and the risk mitigated by implemented controls. The assessment of residual risk is context-dependent and typically informs decisions on whether remaining exposure is acceptable or requires further treatment; the specific methodology, thresholds, and acceptance criteria vary by organization and applicable risk management framework, and application to a specific situation may require professional judgment.
Why it matters
Residual risk is a central concept in risk management because it reflects the practical reality that controls rarely eliminate risk entirely. No matter how robust an organization's security measures are, some portion of exposure generally persists after risk treatment and remediation efforts have been applied. Understanding and quantifying this remaining exposure is what allows leadership to make informed decisions about whether the organization can live with what is left over or whether further treatment is warranted.
The concept matters most at the point of risk acceptance. Once residual risk has been assessed, an organization must decide whether the remaining exposure falls within its risk appetite or requires additional controls. Blurring the distinction between inherent risk (the exposure before controls are accounted for) and residual risk (what remains after them) can lead to misinformed decisions, either overestimating protection already in place or underestimating what still needs attention. Because acceptance criteria and thresholds vary by organization and applicable framework, the same residual risk figure may be tolerable in one context and unacceptable in another.
Residual risk assessment is inherently context-dependent, and its output should inform rather than replace professional judgment. Methodologies, thresholds, and acceptance criteria differ across risk management frameworks, so a residual risk determination in one organization is not directly comparable to another's. Treating residual risk as a static or universal number, rather than a decision input that depends on the controls in place and the framework applied, can undermine the value of the exercise.
Who it's relevant to
Inside Residual Risk
Common questions
Answers to the questions practitioners most commonly ask about Residual Risk.
