Learn

Inherent risk vs. residual risk

Inherent risk is the level of risk before controls are applied; residual risk is what remains after them. Here is how they are measured and used.

In short

Inherent risk is the level of risk that exists before any controls are applied, based on the nature of the activity, system, or vendor. Residual risk is the level of risk that remains after controls and treatments are in place. The difference shows how much the controls are doing; residual risk is compared with the organization's risk appetite to decide whether more treatment is needed.

This page is for you if
  • You are trying to get a straight answer before you sit through a sales call
  • You need language you can take to a CISO, auditor, or procurement

An example

A vendor that processes production customer data has high inherent risk. If it has strong encryption, access controls, and a clean SOC 2 Type II report, the residual risk may be moderate. If a control fails, residual risk rises even though inherent risk has not changed.

Using both

  • Inherent risk decides how deeply to assess something, such as vendor tiering.
  • Residual risk decides whether to accept, mitigate further, transfer, or avoid.
  • Tracking both shows the value of controls to leadership.

When this becomes a buying decision

If vendor tiering uses residual language on day one, the program is guessing. Inherent first, residual after evidence: that is the operational split to look for.

If that is the situation you are in, see the product pages linked below, or ask us for a 30-minute demo on one real document.

Questions

What is risk appetite?

The amount and type of risk an organization is willing to accept in pursuit of its objectives; residual risk is compared against it.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.