Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

inherent vs residual risk explained

Inherent vs Residual Risk: The Complete 4-Column Register Guide

Inherent vs residual risk is the distinction every risk register draws and few define carefully: inherent risk is the level of risk before any controls are considered, residual risk is the level that remains after the controls in place are taken into account, and the difference between them is what the controls are worth. The terms come from the audit and COSO tradition — COSO ERM 2017 uses inherent, residual and target risk in its performance principles — rather than from ISO 31000:2018, which uses neither word: ISO 31000 assesses risk “with existing controls” and then treats it, and ISO Guide 73 defines residual risk as the risk remaining after risk treatment.

The two vocabularies describe the same movement from left to right across a heat map, but they disagree about the starting point, and that disagreement is the source of most register errors: scoring a risk with no controls at all produces a number nobody believes, and scoring the current state and calling it inherent hides what the controls do. This guide defines the terms as each framework uses them, shows how inherent, current and residual risk relate on a register, explains what each score is for — control valuation, appetite comparison, prioritisation — and sets out the errors that make inherent-versus-residual scoring meaningless.

Inherent vs residual risk on a register
Inherent (gross): before controls — the exposure the activity creates · Current (with existing controls): what ISO 31000 assesses · Residual (net): after treatment — compared with risk criteria and appetite · Target: the residual level the organisation intends to reach · control effectiveness = inherent → residual movement.

Inherent vs residual risk: the definitions, framework by framework

Term COSO ERM 2017 / internal audit usage ISO 31000:2018 and ISO Guide 73 What a register records
Inherent risk The risk to an entity in the absence of any direct or focused actions by management to alter its severity Not used. ISO 31000 6.4.3 analyses risk considering the effectiveness of existing controls The gross exposure: likelihood and consequence as if no control existed
Current risk Not a COSO term; used in practice for the level with controls as they actually operate The level ISO 31000 assesses — risk with existing controls, before further treatment Likelihood and consequence given controls that are in place and working as they do
Residual risk The risk remaining after management’s actions to alter its severity Guide 73 3.8.1.6: risk remaining after risk treatment; ISO 31000 6.5.2 requires the residual risk to be documented and subjected to monitoring, review and, where appropriate, further treatment Likelihood and consequence after planned treatment is implemented
Target risk The level of residual risk the entity intends to achieve, within appetite Implicit in risk criteria (6.3) and treatment plans (6.5) The residual score the treatment plan is designed to reach, by a date

The practical reconciliation: a register with four columns — inherent, current, residual and target — satisfies both vocabularies, and most organisations that use only two are collapsing current and residual into one without saying so. Our guide to ISO 31000 covers the process the columns sit in; the COSO ERM principles covers principle 11, where COSO’s severity assessment uses inherent and residual.

Why inherent vs residual risk matters

Use Which scores What it tells you
Control valuation Inherent → current How much the existing controls are worth; which controls are key, and what happens if one fails
Prioritisation of treatment Current vs criteria Which risks are outside criteria now and need treatment
Appetite comparison Residual and target vs appetite Whether the planned treatment brings the risk within appetite, and when
Control testing focus Risks with the largest inherent-to-current gap Where a control failure would matter most; the internal audit plan
Assurance reporting All four What the organisation is exposed to, what it relies on, what it plans, and where it will be

Without an inherent score there is no way to show what the controls do, and a register full of green residual scores tells a board nothing about how much of that green depends on a single control. Without a residual score there is no way to show that the treatment plan reaches appetite. The two-column register loses one of these; the four-column register keeps both.

Estimating inherent risk without inventing it

The objection to inherent risk is real: “the risk of a data breach with no controls at all” is not a number anyone can estimate. The answer is to define what “no controls” means for the register.

  1. Exclude direct, focused controls only. COSO’s definition excludes actions by management to alter severity — the specific controls for this risk — not the existence of the organisation, its legal structure or the laws it operates under. A breach risk’s inherent score assumes no access control, encryption, monitoring or training; it does not assume the data is published.
  2. Anchor on the activity, not the worst imaginable case. Inherent likelihood is how often the event would occur given the activity’s volume and exposure; inherent consequence is the realistic outcome of an uncontrolled occurrence. Both use the same scales as the residual score.
  3. Use it comparatively. Inherent scores are most useful relative to each other — which activities create the most exposure — and relative to the current score of the same risk; absolute precision is not the point.
  4. State the convention in the criteria. The risk criteria document says what inherent means for this organisation, so that two assessors score the same risk the same way. Our guide to risk criteria covers the document.

Inherent vs residual risk in practice: scoring current and residual

  1. Current risk uses the controls as they operate, not as designed. ISO 31000 6.4.3 asks for the effectiveness of existing controls; a control that exists on paper and is not applied does not reduce the score. Control testing results feed this column.
  2. Residual risk uses the treatment plan as it will operate when complete. Each treatment option — avoid, take, remove the source, change likelihood, change consequence, share, retain — is scored for its effect; the residual is the score after the selected options are implemented.
  3. Residual is compared with criteria and appetite. ISO 31000 6.5.2 requires residual risk to be documented and monitored; COSO principle 11 compares severity with appetite. If residual is still outside, either more treatment or a documented acceptance by the authority the policy names.
  4. Target is the residual with a date. A treatment plan that takes eighteen months has a current score today, a target score at completion, and interim residuals as options land; the register shows the trajectory.

Errors that make inherent vs residual risk meaningless

  • Scoring current and calling it inherent. The commonest: the gap between “inherent” and residual is then the planned treatment only, and the existing controls are invisible.
  • Inherent scores that are all red. If every inherent risk sits in the top-right cell, the scale is not being applied; inherent likelihood and consequence still vary by activity.
  • Residual scored before the treatment exists. A residual score that assumes a control not yet implemented is a target score mislabelled — and a board reading it as current is misled.
  • Control effectiveness assumed, never tested. Current scores that never move when controls fail testing are not using ISO 31000 6.4.3’s “effectiveness of existing controls”.
  • Different scales for different columns. Inherent on a 5 × 5 and residual on a 3 × 3 cannot be compared; the criteria fix one scale.
  • Appetite compared with inherent. Appetite is a statement about the risk the organisation is willing to carry after controls; comparing it with the gross score makes every risk a breach of appetite. Our guide to risk appetite covers the terms.

Inherent vs residual risk: a worked example

Column Likelihood Consequence Score (5 × 5) Basis
Inherent 4 Likely 5 Severe 20 Customer database, 2 million records, internet-facing application, no access control, encryption, monitoring or training assumed
Current 2 Unlikely 4 Major 8 MFA, encryption at rest, monitoring and annual training in place and tested; consequence reduced by encryption and breach response
Residual (planned) 2 Unlikely 3 Moderate 6 Tokenisation of card data and data minimisation reduce the records exposed in a breach
Target 2 3 6 by Q2 next year Within the appetite threshold of 6 for data protection risks

The inherent-to-current gap (20 to 8) values the existing controls and tells internal audit where to test; the current-to-residual gap (8 to 6) is the treatment plan; the target date is the commitment the board tracks.

Frequently asked questions

What is the difference between inherent and residual risk?
Inherent risk is the level of risk before any direct controls are considered — COSO’s ‘absence of any direct or focused actions by management’; residual risk is the level remaining after treatment — ISO Guide 73’s ‘risk remaining after risk treatment’. The difference is the value of the controls.

Does ISO 31000 use the term inherent risk?
No. ISO 31000:2018 analyses risk considering the effectiveness of existing controls (6.4.3) and requires residual risk after treatment to be documented and monitored (6.5.2); ‘inherent’ and ‘gross’ are COSO and audit vocabulary. Registers reconcile the two with inherent, current, residual and target columns.

How do you estimate inherent risk realistically?
Define what ‘no controls’ means — exclude the direct controls for the risk, not the organisation’s existence — score likelihood on the activity’s exposure and consequence on the realistic uncontrolled outcome, use the same scales as the other columns, and use the result comparatively.

What is target risk?
The residual level the organisation intends to reach through its treatment plan, within appetite, by a date; COSO ERM names it, ISO 31000 implies it through risk criteria and treatment plans.

Should risk appetite be compared with inherent or residual risk?
Residual (and current). Appetite is the risk the organisation is willing to carry after controls; comparing it with inherent risk makes every risk look out of appetite.

Where this leaves you

Run inherent vs residual risk as four columns, not two: inherent as the gross exposure under a stated convention, current as the risk with controls as they actually operate, residual as the level the treatment plan reaches, and target as that level with a date — because the first gap values the controls, the second is the plan, and a register that shows only one of them is hiding the other from the board.

References

More on ISO 31000

The four-column risk register, the risk criteria with the inherent-scoring convention, the control effectiveness assessment and the treatment plan template are in the ISO 31000 Risk Management Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.