Purpose: Use the distinction to show how safeguards change exposure and where uncertainty remains. Both assessments should refer to the same scenario and consequence.
Comparison points
Starting pointInherent risk considers the scenario before the effect of selected safeguards; residual risk considers remaining exposure after them.
PurposeInherent risk shows the need for protection; residual risk supports acceptance, further treatment, and monitoring.
EvidenceInherent assessment relies on the business context and threat path; residual assessment also requires evidence about safeguard effectiveness.
Common scaleBoth ratings should use compatible definitions so the change is meaningful.
ConfidenceResidual risk should state uncertainty when control operation or recovery capability is not well proven.
Worked examples
| Example | Context / Rating | Condition / Safeguard | Decision / Result |
|---|
How to use this page
- Write the scenario and consequence once.
- Assess exposure without credit for the selected safeguards.
- Identify exactly how each safeguard changes likelihood or consequence.
- Evaluate evidence and control confidence.
- Record residual exposure, acceptance authority, and monitoring.
Cautions
- Do not change the scenario between inherent and residual ratings.
- Do not give full control credit without evidence.
- Avoid treating residual risk as permanent; conditions change.
Educational use: Tailor the language and decision authority to the organization. This page is not a certification, legal opinion, security assessment or substitute for professional advice.
Frequently asked questions
Can a small organization use this tool?
Yes. Reduce the number of fields or questions, but retain the scenario, business consequence, accountable owner, decision and review date.
Does this replace professional advice?
No. It is an educational structure. Legal, insurance, compliance, cybersecurity and other professional decisions may require qualified advice.
How often should it be updated?
Update it when the related service, supplier, data, threat conditions, controls, incident history or business priorities change materially.