TPRM glossary

Residual risk, what is left once the controls are counted

Residual risk is the risk that remains after controls have been applied — the exposure you are actually carrying, as opposed to the exposure you would carry with no defences at all. It is what gets accepted, transferred or treated further, and it is the number that belongs in board reporting.

How residual risk is derived

Start from inherent risk — what is at stake before anything is done about it — then reduce it by the controls that are actually in place and actually working. The second qualifier is where the honest version of this exercise diverges from the comfortable one: a control that exists on paper, is not tested, and has never been evidenced does not reduce residual risk, however good the policy describing it reads.

In third-party risk the controls are largely someone else's, which is why evidence matters more here than in internal risk work. A vendor asserting multi-factor authentication reduces inherent risk by the amount you are willing to take on trust. A vendor producing a current SOC 2 Type II covering the relevant criteria reduces it by considerably more, because the assertion has been tested by someone whose job was to try to disprove it.

Accepting residual risk

Residual risk that sits inside appetite is accepted; residual risk outside it needs treatment, and the decision belongs to the business owner who receives the benefit of the relationship rather than to the risk team who measured it. Recording who accepted what, on what date, against which stated appetite, is the entire audit trail — and its absence is the most common finding in third-party risk audits.

It also decays. Controls lapse, certifications expire, estates change and a vendor's posture drifts between assessments. Residual risk calculated in March is a March number, which is the argument for continuous monitoring rather than an annual recalculation.

Common questions

What is the formula for residual risk?
Conceptually, residual risk is inherent risk reduced by control effectiveness. It is usually expressed as a rating rather than a calculation, because control effectiveness is an evidence-based judgement rather than a coefficient — and a formula implying otherwise gives a false impression of precision.
Who should accept residual risk?
The business owner accountable for the service the vendor supports, at a level of seniority matching the size of the exposure, against a documented risk appetite. Risk teams measure and advise; they should not be the ones accepting risk on behalf of a business they do not run.
Can residual risk be zero?
No. Controls reduce risk, they do not eliminate it, and any assessment producing zero residual risk has almost certainly assumed perfect control operation. What is achievable is residual risk within appetite, which is a different and much more useful claim.

Related terms and pages

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.