Residual fraud risk
Definition
The level of fraud risk that remains after existing controls are applied and operating. If residual risk exceeds the organisation's risk appetite for a given scheme, a risk response is required to reduce it further.
Related terms
- Control gap
- A deficiency in the design or operation of a control that leaves a fraud scheme inadequately mitigated. Design gaps exist where no...
- COSO Fraud Risk Management Guide
- A framework published by the Committee of Sponsoring Organizations of the Treadway Commission that provides a methodology for identifying, assessing, and responding...
- Inherent fraud risk
- The level of fraud risk present in a business process or transaction type before any controls are applied. Scored on likelihood and...
- Risk appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Scheme mapping
- The step in a fraud risk assessment that connects each identified fraud scheme to the specific business process, sub-process, and control environment...
Explained in
- The Fraud Risk Assessment ProcessThe level of fraud risk that remains after existing controls are applied and operating. If residual risk exceeds the organisation's risk appetite for a given s...