What's the Real Risk After Controls? — The Critical Distinction Every GRC Pro Must Understand
The Two Risk States
Risk assessment must consider both inherent and residual risk:
|
Type |
Definition |
|
Inherent Risk |
The level of risk that exists before any risk treatment or controls are applied |
|
Residual Risk |
The level of risk that remains after risk treatment and controls have been applied |
Why the Distinction Matters
The distinction is important because:
- It shows the value of controls
- It enables informed risk acceptance decisions
- It helps prioritize risk treatment
- It demonstrates control effectiveness
Calculating Inherent Risk
Inherent risk is assessed by considering:
- The potential impact of a risk event
- The likelihood of occurrence
- The vulnerability of the asset
No controls are considered in inherent risk assessment.
Calculating Residual Risk
Residual risk is assessed by:
- Starting with inherent risk
- Subtracting the effect of controls
- Considering the remaining risk
Residual risk = Inherent risk × (1 - Control Effectiveness)
Example: If inherent risk is $1,000,000 and controls reduce it by 60%, residual risk is $400,000.
Accepting Residual Risk
Risk acceptance should be the least preferred option over risk mitigation through implementation of primary controls .
When risk is accepted:
- Risk acceptance should be formally documented, approved, and signed-off by the business owner
- Risk acceptance should be provided with detail justification including impact of not implementing controls and compensating controls in place
- The accepted risk should be within the risk appetite
- Risk acceptance should be renewed periodically
- Risk acceptance should be presented and reported to the risk committee
The Risk Treatment Continuum
1. Risk Avoidance
Eliminate the activity or asset that creates the risk entirely.
2. Risk Reduction (Mitigation)
Apply controls to reduce likelihood or impact.
3. Risk Transfer
Shift financial exposure through insurance or contractual terms.
4. Risk Acceptance
Consciously tolerate residual risk within defined appetite.
Why Organizations Avoid Formal Acceptance
Many organizations avoid formal risk acceptance because:
- It requires executive visibility
- It creates accountability
- It exposes control gaps
But formal risk acceptance is essential for effective risk management. Without it, risk is accepted informally—with no documentation, no accountability, and no visibility.
Conclusion
Understanding inherent and residual risk is essential for effective risk management. Organizations that calculate both will know the value of their controls and make better decisions about risk treatment.
Action Items for Your Organization
- Calculate inherent risk for key risks
- Assess control effectiveness
- Calculate residual risk
- Document risk acceptance decisions
- Report risk acceptance to the risk committee
- Review risk acceptance periodically