Residual Risk

Residual risk is the risk that remains once the agreed controls have been implemented. It can only be quantified sensibly if the risk without any controls and the risk with the controls effective today have been determined as well. A residual risk is not ignored: it is knowingly approved by a named position and reviewed regularly.

RisikomanagementLast reviewed:

Three states of the same risk

Risk is not a fixed number but a quantity with several states. Carry only one of them and you lose exactly the information decisions need.

StateGuiding questionWhat it is needed for
Inherent risk (gross)How large would the risk be with no controls at all?Shows what the existing controls actually contribute
Current risk (net)How large is it with the controls effective today?The steering figure for day-to-day operation and reporting
Residual riskWhat remains once the additional controls agreed are implemented and effective?The basis for approval and for the question of whether the effort pays

The terms are not used consistently. In many organisations "residual risk" already denotes the current net risk; in others, exclusively the state after the treatment plan has been fully implemented. What matters is less the label than a written statement in the risk policy of which state is meant, and that every report means the same state.

Why the distinction matters

Without the inherent risk, the contribution of a control cannot be measured. That removes the basis for three everyday decisions: which control is implemented first, which one can be dropped when the budget is tight, and whether an existing control justifies its running cost. A risk register showing only net values looks calm. It hides the fact that a single tool falling over would invalidate several assessments at once.

The converse also holds. If residual risk is not kept separate from current risk, the effect of planned controls blends with the effect of ones already in place. Reporting then shows an improvement that has not yet occurred.

Approving a residual risk

Accepting a residual risk is a valid and often correct decision, but a decision that has to be taken, not omitted. It requires:

  • a named risk owner with authority to decide for the area concerned;
  • a threshold rule from which the decision moves to a higher level, up to executive management;
  • a documented justification recording the state of knowledge at the time of the decision;
  • an expiry or review date, because the threat landscape, the business model and the legal position change.

ISO/IEC 27001 addresses this point expressly: clause 6.1.3 provides that the risk owners approve the risk treatment plan and accept the remaining information security risks. For executive management, the documented approval is at the same time evidence that a decision was taken knowingly and on an informed basis, something that counts for duties of care under § 43 GmbHG (the German Limited Liability Companies Act) or § 93 AktG (the German Stock Corporation Act).

There is no zero risk

A residual risk of zero does not exist in practice. Every control can fail, every assumption can be wrong, and controls that reduce a risk to zero on paper usually cost more than the damage they prevent. The task of risk management is therefore not to eliminate the residual risk but to bring it to a level the organisation is willing and able to carry, and to keep it visible.

Expressing residual risk in money

As long as the three states are carried as colour bands, neither the difference between them nor the benefit of a control can be quantified. Carry them as amounts instead and the effect of a control becomes the difference between two numbers, which can be set against its cost. That is precisely what makes the discussion with executive management comparable to any other investment decision.

How Rizzqo keeps the three figures apart

Residual risk only says something when the starting value stands beside it. In Rizzqo every risk assessment therefore carries three states separately: the inherent risk without controls, the current risk with the controls effective today, and the residual risk after the planned ones. Each is valued in two figures, likelihood as a percentage and impact in euros, with the level coming from a configurable matrix rather than a hidden score.

The difference between the current and the residual figure comes from the tasks. A planned task carries its reduction as a reservation, visible only in the residual value; completion is what actually lowers the current risk, and cancelling releases the reserved room again. That makes it possible to show which part of the improvement has already happened and which is still outstanding.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework