ISO 27001 residual risk is the level of information security risk that remains after you have applied your chosen treatment, and it is the number your risk owners are really signing for. The standard requires you to compare the treated risk with your acceptance criteria, obtain owner approval and keep the results as documented information.
This guide shows how to calculate residual risk consistently, what auditors expect to see, and how to keep the figures honest over time. It builds on risk criteria and feeds directly into your risk treatment plan.
Free gap assessment
Where do you actually stand against ISO 27001?
Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.
Run the free ISO 27001 gap assessment → or View premium report sample
What ISO 27001 residual risk means
Residual risk is the risk left over once controls from your treatment plan are in place and working. Inherent risk is the level before those controls. The gap between them is the value your controls actually deliver, which makes it a useful measure of whether spending is justified.
Clause 6.1.3 of ISO/IEC 27001:2022 asks you to formulate a risk treatment plan and obtain risk owners’ approval of it and their acceptance of the residual information security risks. That single sentence is why residual scoring matters. See the standard listing at ISO/IEC 27001:2022 on iso.org to confirm the wording in your licensed copy.
Free ISO 27001 risk assessment
Which of your risks sit above your appetite line?
Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.
Run the free risk assessment → or View premium report sample
Where the standard requires residual risk
Three places matter. Clause 6.1.2 requires a repeatable assessment with criteria. Clause 6.1.3 requires treatment, comparison of chosen controls with Annex A, a Statement of Applicability and owner acceptance of what remains. Clause 8.3 requires you to implement the plan and keep documented results.
Auditors therefore look for a chain: risk, treatment, control, residual score, owner approval and date. A break anywhere in that chain is a common nonconformity.
How to calculate ISO 27001 residual risk
Use the same scales you used for the inherent score, so the numbers are comparable. Re-estimate likelihood and impact assuming the controls operate as designed, then multiply or map through your matrix.
Controls usually reduce likelihood, but some reduce impact instead, such as backups or insurance. Say which you are claiming. If a control affects both, justify each change in a sentence rather than dropping the score by an arbitrary step. Our guide to the risk assessment methodology explains how to fix the scales.
| Risk | Inherent score | Control applied | Residual score | Decision |
|---|---|---|---|---|
| Ransomware on file servers | 20 | Offline backups, EDR, segmentation | 8 | Accept with owner approval |
| Leaver keeps system access | 12 | Automated deprovisioning | 4 | Accept |
| Supplier data breach | 16 | Contract clauses, audit rights | 12 | Treat further |
| Lost unencrypted laptop | 15 | Full disk encryption | 3 | Accept |
A worked example of residual scores
The table below uses a five by five matrix with scores from one to 25. The figures are illustrative only, so replace them with your own scales and evidence.
Notice that the supplier breach risk stays at 12 because contract clauses do not stop an incident at the supplier. If your acceptance threshold is 10, that risk needs further treatment or a formal exception.
Setting acceptance thresholds for residual risk
You cannot judge residual risk without a line to compare it against. Define the threshold in your criteria, for example that scores of nine or below are accepted by the risk owner and scores above that need senior management approval.
Tie the thresholds to your stated appetite. The article on risk appetite shows how to translate a board statement into numbers, and the guide to risk acceptance covers the approval step in detail.
Who approves ISO 27001 residual risk
The approver is the risk owner, meaning the person with accountability and authority over the asset or process. Approval by the security team alone is a frequent finding, because the security team rarely owns the business consequence.
Record the name, role, date and the score approved. Our note on the risk owner role explains how to assign ownership so that approvals are meaningful.
Documenting ISO 27001 residual risk in the register
Add columns for residual likelihood, residual impact, residual score, acceptance status, approver and approval date. Keep the inherent score visible alongside them so reviewers can see the effect of each control.
A risk register that shows only residual scores hides your reasoning, and one that shows only inherent scores hides your progress. Show both.
Residual risk after treatment options compared
The four treatment options leave different amounts behind. Modifying a risk with controls lowers the score but seldom to zero. Avoiding a risk by stopping the activity removes almost all of it, though the business may lose the benefit too. Sharing a risk through insurance or outsourcing moves part of the financial impact, yet accountability for data protection stays with you. Retaining a risk leaves the score unchanged and simply records a decision. Comparing these options side by side in your plan shows why one route was chosen, and it gives an auditor a clear reason for each residual figure.
When you choose to share a risk with a supplier, remember that the supplier introduces its own risks. Score the new dependency separately, then check that the combined position still sits within your thresholds. Contract terms, audit rights and evidence of the supplier’s own controls all belong in the file.
Common mistakes with residual risk
Teams tend to make the same errors, and most are easy to avoid once you know them.
- Scoring residual risk on planned controls that are not yet operating.
- Reducing the score without evidence such as test results or audit findings.
- Using a different scale from the inherent assessment.
- Accepting risks above threshold with no senior sign-off.
- Never revisiting the score after an incident or a major change.
Testing that controls really reduce risk
A residual score is only as credible as the control behind it. Link each reduction to evidence: a restore test for backups, a phishing simulation result, a penetration test finding closed, or an access review completed.
When evidence is missing, hold the score at the inherent level or apply a conservative reduction and note the gap. Auditors respond well to honesty about immature controls and badly to optimistic scores.
Handling ISO 27001 residual risk above the threshold
Sometimes the number after treatment is still higher than your criteria allow. You have three honest choices: add controls, change the activity, or obtain a documented exception from senior management. An exception should state the risk, the score, the reason further treatment is not practical, the compensating measures, the approver and an expiry date. Exceptions without expiry dates quietly become permanent, and auditors notice.
Keep a short list of open exceptions in your management review pack so that leaders see how much risk is being carried beyond the normal line and for how long.
Linking residual scores to Statement of Applicability decisions
Your Statement of Applicability explains which Annex A controls apply and why. Residual scores support those choices: if excluding a control leaves a risk within threshold, the exclusion is justified, and if not, the control should return to the plan. Cross-reference the two documents so a change in one prompts a check of the other.
Reviewing residual risk over time
Residual risk moves. Threats change, controls degrade and the business alters its processes. Set a review cycle, at least annual and more often for high scores, and add triggers such as incidents, new suppliers or major system changes.
Indicators help. Thresholds on metrics such as patch latency or failed backups can warn you that a residual score is drifting; see our note on KRI thresholds.
Audit evidence for residual risk decisions
Prepare a small evidence pack before the audit. Include the scoring scales, the register extract showing inherent and residual figures, the signed approvals, the exceptions list and two or three examples where you can trace a risk from assessment through control testing to acceptance. Sampling is how auditors work, so every row must hold up when they pick it. If a sampled risk lacks an approval date or a control test, fix the process, not just that row.
Also keep the minutes of the management review where residual positions were discussed, since they prove that leadership engaged with the numbers rather than receiving them passively.
Presenting ISO 27001 residual risk to management
Management review under clause 9.3 should see the distribution of residual risks, the ones above threshold, exceptions granted and trends since the last review. A risk heat map of residual positions is quicker to read than a spreadsheet.
Keep the message short: what remains, who accepted it, what is being done about the rest.
Speeding up documentation with a ready structure
If you would rather not design the record yourself, the ISO 27001 Risk Assessment Report and Workbook gives you a structured report and workbook with inherent and residual scoring, treatment mapping and approval fields. Whichever route you take, use one format across all assessments.
ISO 27001 residual risk FAQ
Is residual risk mandatory in ISO 27001?
Yes. Clause 6.1.3 requires risk owners to accept the residual information security risks, and clause 8.3 requires documented results of the treatment.
Can residual risk be zero?
Almost never. Controls reduce risk but rarely remove it, and a zero score usually signals overconfidence or missing scenarios.
Who signs off residual risk?
The risk owner signs off, with senior management approval for risks above your defined threshold.
How often should residual risk be reviewed?
At least annually, and after incidents, major changes or new suppliers. High residual scores deserve shorter cycles.
Do I need to score residual risk for every risk?
You need an evaluated, approved outcome for every risk you treat. Risks you accept without treatment carry their current score as the accepted level.