Residual risk, what is left once the controls are counted
Residual risk is the risk that remains after controls have been applied — the exposure you are actually carrying, as opposed to the exposure you would carry with no defences at all. It is what gets accepted, transferred or treated further, and it is the number that belongs in board reporting.
How residual risk is derived
Start from inherent risk — what is at stake before anything is done about it — then reduce it by the controls that are actually in place and actually working. The second qualifier is where the honest version of this exercise diverges from the comfortable one: a control that exists on paper, is not tested, and has never been evidenced does not reduce residual risk, however good the policy describing it reads.
In third-party risk the controls are largely someone else's, which is why evidence matters more here than in internal risk work. A vendor asserting multi-factor authentication reduces inherent risk by the amount you are willing to take on trust. A vendor producing a current SOC 2 Type II covering the relevant criteria reduces it by considerably more, because the assertion has been tested by someone whose job was to try to disprove it.
Accepting residual risk
Residual risk that sits inside appetite is accepted; residual risk outside it needs treatment, and the decision belongs to the business owner who receives the benefit of the relationship rather than to the risk team who measured it. Recording who accepted what, on what date, against which stated appetite, is the entire audit trail — and its absence is the most common finding in third-party risk audits.
It also decays. Controls lapse, certifications expire, estates change and a vendor's posture drifts between assessments. Residual risk calculated in March is a March number, which is the argument for continuous monitoring rather than an annual recalculation.
Common questions
What is the formula for residual risk?
Who should accept residual risk?
Can residual risk be zero?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.