Residual Fraud Risk
Definition
The level of fraud risk that remains after existing controls are applied and operating. If residual risk exceeds the organisation's risk appetite for a given scheme, a risk response is required to reduce it further.
- Domain
- Fraud risk management
- Calculated after
- Existing controls applied
- Compared to
- Organisation's risk appetite
- If exceeded
- Requires a risk response
Common questions
How does residual fraud risk differ from inherent fraud risk?+
Inherent risk is the exposure before any controls are considered, while residual risk is what remains after the organisation's actual controls are factored in, showing the real gap still needing attention.
What happens when residual fraud risk exceeds the risk appetite?+
The organisation must design and implement additional controls or other risk responses to bring the exposure down to an acceptable level, rather than simply accepting it.
Related terms
- Control Gap
- A deficiency in the design or operation of a control that leaves a fraud scheme inadequately mitigated. Design gaps exist where no...
- COSO Fraud Risk Management Guide
- A framework published by the Committee of Sponsoring Organizations of the Treadway Commission that provides a methodology for identifying, assessing, and responding...
- Inherent Fraud Risk
- The level of fraud risk present in a business process or transaction type before any controls are applied. Scored on likelihood and...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Scheme Mapping
- The step in a fraud risk assessment that connects each identified fraud scheme to the specific business process, sub-process, and control environment...