Two numbers, one risk. Most registers get the definitions right and the arithmetic wrong — here's both, with the maths shown.
Every mature risk register carries two scores for each risk. Inherent risk is the exposure before you take credit for your controls. Residual risk is what remains after they do their job. The gap between them is, in effect, the value your control environment delivers — which is why boards look at both and why auditors ask how you got from one to the other.
Inherent risk is the exposure a risk presents assuming no controls are operating, or — depending on which convention your organisation adopts — assuming only the most basic ones are. It answers: if we did nothing about this, how bad is it?
Residual risk is the exposure that remains once your controls are applied and working as designed. It answers: given what we actually have in place, how bad is it now?
You will also hear these called gross and net risk. The terms are interchangeable — see gross vs net risk — though "inherent and residual" is the COSO and ISO vocabulary and the safer choice in formal documents.
On a standard 5×5 matrix, inherent risk is the product of two judgements:
Inherent score = likelihood × impact
Both scored 1–5, giving a range of 1 to 25. A risk scored 4 for likelihood and 5 for impact carries an inherent score of 20 — firmly in critical territory on most scales. Plot it on a heat map and it sits top-right.
The common failure here is scoring likelihood and impact with your controls already in mind. If you catch yourself thinking "well, it's unlikely because we patch monthly," you have just scored residual risk and labelled it inherent. Patching is a control. Set it aside for this number.
This is where most registers become indefensible. Someone scores inherent as 20, decides residual "feels like a 9," and types 9. There is no method, so there is nothing to audit and nothing to challenge.
A defensible approach ties the reduction to a rated assessment of control effectiveness. In Rukn ERM the model is deliberately simple and explicit — each control mapped to a risk carries an effectiveness rating from 1 to 5, and each point of effectiveness reduces inherent exposure by 15%:
Residual = inherent × (1 − effectiveness × 0.15)
A maximum rating of 5 therefore yields a 75% reduction — never 100%. That ceiling is intentional, and worth defending when someone asks why a perfectly controlled risk still scores above zero.
Likelihood 4, impact 4, so inherent is 16. Mapped controls — encryption at rest, access reviews, a tested incident response plan — assess collectively at effectiveness 4. That gives a 60% reduction:
16 × (1 − 0.60) = 6.4 → residual 6
The risk moves from high to medium. Still live, still owned, but no longer the thing that keeps the board awake.
Likelihood 4, impact 5, so inherent is 20. Controls are real but partial — backups exist, restoration has never been tested end to end — so effectiveness assesses at 3, a 45% reduction:
20 × (1 − 0.45) = 11 → residual 11
Still high. This is the honest outcome of a control that exists on paper but hasn't been proven — and it's exactly the case where an untested backup flatters a register that uses judgement instead of arithmetic.
Likelihood 5, impact 5, so inherent is the maximum 25. Every control is mature, tested and rated 5 — a 75% reduction:
25 × (1 − 0.75) = 6.25 → residual 6
Even a flawless control environment leaves a residual 6 against a maximum inherent risk. That is the model refusing to let anyone claim a catastrophic risk has been controlled out of existence. Controls fail, people make mistakes, and a register that can print zero against a severe risk is telling the board something untrue.
Both, and in that order. Inherent alone overstates your exposure and makes every risk look unmanaged. Residual alone hides how much work the control environment is doing — and hides what happens if it stops. Shown together, the gap becomes the argument for the risk function's budget.
Residual is the number you manage against day to day. It's what you compare to risk appetite and tolerance, and what should trigger escalation when it breaches.
Scoring inherent with controls in mind. The most common error, and it compresses the gap until the register shows the control environment doing almost nothing.
Setting residual by feel. If you cannot explain the arithmetic, you cannot defend the number to an auditor — and you cannot reproduce it next quarter.
Rating controls that have never been tested. An effectiveness rating is a claim about performance. Without a test date and a result behind it, it is an opinion. Record when each control was last tested, by whom, and what the result was.
Letting the numbers go stale. Residual risk should move when control testing moves. If your register's residual scores haven't changed in a year, either nothing has changed or nobody is updating them. It's almost never the former.
The reason most registers drift is that the link between control testing and residual score is a human being remembering to do arithmetic. In Rukn ERM's risk assessment software that link is mechanical: when a control's effectiveness rating changes, every risk mapped to that control recalculates its residual score immediately, and if the new score breaches appetite the risk owner is notified without anyone raising it. The register stays current because staying current isn't a task.
Inherent and residual scoring across your whole risk register, with control effectiveness built in — and a free template to start from.
Start free trial Free register template