Inherent risk is the score a risk carries before anything is done about it. Residual risk is the score that remains after the mitigations you run. Same risk, same scale, two readings taken either side of the work. The distance between them is what the mitigation bought, and it is the only number that argues for its cost.
Two scores, one risk
Open any risk register that has been running for more than a quarter and you will find a column of scores that never move. Twelve, twelve, twelve, sixteen, twelve. The mitigations column is full. The scores are unchanged.
That is what scoring a risk once costs you. A single number says how worried to be. It cannot say whether anything being done about the risk is working, which is the only question in the room when somebody is being asked to fund the doing.
Two readings fix it, taken either side of the response and on one scale. The federal definitions are as plain as they come. OMB Circular A-123 sets out inherent risk as “the exposure arising from a specific risk before any action has been taken to manage it beyond normal operations”, and residual risk as “the exposure remaining from an inherent risk after action has been taken to manage it, using the same assessment standards as the inherent assessment”. The same guidance asks a risk profile to be clear about the difference between the two, which is a polite way of saying that most are not.
That final clause carries the whole method. Same assessment standards, or the subtraction is meaningless. If a likelihood of 4 means better than even odds inside the next quarter when you score the inherent side, it has to mean the same thing when you score the residual side. If impact 5 means a month of delay in one column and reputational discomfort in the other, the gap between them measures nothing but the drift between two conversations held six weeks apart.
The subtraction is only as good as the shared scale underneath it. Both scores off one published definition of likelihood and impact, agreed at the same review, by people looking at the same risk. Two numbers from two vocabularies do not make a measurement, however neatly they line up in adjacent columns.
The gap is what the mitigation bought
Take a real one. A supplier holds an accreditation that expires mid delivery, and the renewal has slipped twice already. Likelihood 4, impact 5, so the inherent score is 20 on a five by five matrix. The proposed response is to onboard a second accredited supplier and split the volume, which takes likelihood to 2 and impact to 3, so the residual score is 6.
Fourteen points. That is the entire business case for the second supplier, and it is a figure you can set against the cost of onboarding one. Without it the conversation has only one number in it, the cost, and a cost with nothing on the other side of the scale always looks like an expense rather than a purchase.
Read a whole register that way and the column of gaps ranks what your risk spend has returned.
- Supplier accreditation lapses 20 to 6
- Data migration defects 16 to 8
- Regulatory approval slips 9 to 4
- Integration lead leaves 12 to 12
- Manual interface workaround 6 to 9
The fourth row is the most useful line in the register. Identical scores say that the money and the management attention spent on that risk have bought nothing measurable, and there are only three honest explanations: the response has not started, the response does not work, or nobody re-scored the risk and the residual column is a copy. Each of those is worth knowing and none of them is visible on a register that records one score. A single number is at its most convincing precisely when it is at its least informative.
The bottom row is the other one worth stopping on, and it is covered in the section on wrong residual scores below. A response that moves the score the wrong way is real, it happens, and a register that quietly averages it away has stopped being a record.
Where the inherent impact figure came from is worth asking too, because a score chosen to feel proportionate and a score with evidence behind it look identical in the column. Sensitivity work is the usual source of the honest version: a tornado bar reports the same measurement in weeks or in pounds, and it hands you an impact figure defensible on its range assumptions rather than on your seniority.
The middle score most registers skip
There is a serious objection to inherent risk, and it is worth meeting head on rather than working around. Scoring the world with no controls in it is a thought experiment. Anything running inside an organisation already sits behind procurement rules, access controls, testing gates and an approvals process that nobody would actually switch off, so an inherent score is a score for a scenario that will never occur.
NIST takes that objection seriously enough to change its own vocabulary. Its report on integrating cybersecurity and enterprise risk management notes that the federal examples reference inherent risk describing conditions in the absence of risk management actions, then says there are “often likely to be at least some elements that help mitigate risks, so this publication typically refers to current risk (rather than inherent risk) that represents a baseline risk posture”. Not a rejection of the two score idea. A correction to where the first score is taken from.
| Score | What it measures | What changes it |
|---|---|---|
| Inherent | Exposure with nothing at all in the way. | The risk itself, not your progress. |
| Current | Exposure given the controls already running. | Controls that exist today. |
| Residual | Exposure once the planned response lands. | The response you are asking to fund. |
| Target | Exposure you are willing to live with. | Appetite, set above the register. |
The fourth row is the one people conflate with the third, and the same NIST report is careful to separate them: actual residual risk is what remains after management has acted, and it “should be equal to or less than the target residual risk”. Target is a statement of appetite made before the work. Residual is a measurement made after it. Recording the target in the residual column is the single commonest way a register turns into a wish list.
Two columns is the minimum that means anything, and three is better wherever real controls already exist, because three splits the credit. Inherent to current is what the standing control environment is worth. Current to residual is what this project’s response is worth, and that second gap is the one somebody is being asked to pay for.
Every risk in the register carries inherent, current and residual scores against the same likelihood and impact scale, the reduction between them is totalled across all open threats, and the risks still carrying no residual target at all are counted rather than left to be noticed.
See the risk registerRecording both without doubling the register
The mechanical worry is that two scores mean twice the register. They do not. One risk is still one row; what changes is that likelihood and impact are recorded twice across it, plus a derived score at each end. The register does not get longer, it gets wider, and the width is where the argument lives.
The matrix workflow is the same either way. Place the risk on a five by five grid using the inherent likelihood and impact and note the cell, then place it again using the likelihood and impact you expect once the response has landed. The two cells and the distance between them are the whole output, and the paired scoring matrix on this site does exactly that for one risk at a time.
Sequence matters more than most teams expect. Score the inherent side once, at identification, and then leave it alone. It describes the risk and the world, not your progress against the risk, so it should move only when the underlying exposure genuinely changes: the contract value doubles, the regulator publishes a new deadline, the delivery date moves onto the same weekend as a system freeze. An inherent score that drifts downward month by month is not a measurement, it is a record of how the team is feeling.
Re-score the residual side at every review and date it. The inherent score is a fixture, the residual score is the live one, and the pair only earns its place if the second half is genuinely revisited. A residual column that has not changed in four reviews is telling you either that nothing is happening or that nobody is looking, and both are worth surfacing before the risk surfaces them.
When the residual score is wrong
Four failure modes, and the first is by far the most common.
Residual scored as though the mitigation works perfectly. The response is written, and the residual score is set to what that response would deliver if it landed on time, in full and fully resourced. That is a target wearing the residual score’s clothes, and it produces a register where everything is green in the future. Score the residual side against the response as it is resourced today, not as it was written.
Residual scored before the response exists. A residual score is a claim about a specific piece of work, so with no owner, no date and no funding behind it there is nothing to score. The honest entry there is a residual equal to the inherent score and a note saying the response is unfunded, which is uncomfortable in exactly the way it should be.
Residual above inherent, netted off rather than recorded. Responses introduce exposure: a manual workaround adds a step somebody can miss, a second supplier adds an interface, an accelerated schedule adds fatigue. When the residual score comes out higher than the inherent one, record it that way and raise the new exposure as its own risk with its own owner. Averaging the two into a comfortable middle hides the only thing on the row that changed.
A residual score with no date on it is an opinion about the past, formatted as a fact about the present.
Both scores frozen and quietly inherited. Registers are copied between reporting packs, and scores travel with them long after the assessment behind them has expired. Date every score, name who set it, and treat an undated residual figure as absent rather than as current.
The gap is a measurement, not a target. Teams asked to show risk reduction will produce risk reduction, and the cheapest way to produce it is to move the residual score rather than the risk. Review the movement, not the number: what specifically changed, who did it, and what would have to be true for the new score to be wrong.
None of which makes the pair difficult. Two scores, one scale, one date, and the subtraction done in public. What it makes is uncomfortable, because a register carrying both numbers can no longer describe a project where everything is being managed and nothing is getting better. That discomfort is the point. The single score was never protecting the project, only the report.
Score a risk before any response, then again assuming the response works. The reduction between the two is the number worth taking to the board.
Common questions
- What is the difference between inherent and residual risk?
- Inherent risk is the score before any mitigation, residual risk is the score after it. The distance between the two is what the mitigation actually bought you, and it is the number that justifies its cost.
- Should a risk register record inherent or residual risk?
- Both, in adjacent columns. A register holding only residual scores cannot show whether a control is working, because there is nothing to compare against. A register holding only inherent scores describes a world you do not live in.
- What does it mean if inherent and residual risk are the same?
- It means the mitigation is not earning its cost, or it has not happened yet. Identical scores are the most useful signal in a register: they say the money spent on that control has bought no measurable reduction, and the control is worth challenging.
- Can residual risk be higher than inherent risk?
- Yes, and it should be recorded when it happens. A mitigation can introduce its own risk, such as a workaround that adds a manual step. Log the new risk separately rather than netting it off, or the register hides the thing that changed.
Filed under RAID
The exposure a risk carries before any action has been taken to manage it, scored on the same likelihood and impact scale as the residual score it is compared against.
The list of events that have already occurred and are affecting the work, each with an owner and a resolution date. Likelihood no longer applies.
A single register holding risks, assumptions, issues and dependencies, and usually decisions, with the type recorded on every line.
Read next