Skip to content

Residual Risk

Definition

The risk that remains after controls are applied. If residual risk exceeds the organisation's risk appetite, further treatment is required or management must formally accept the elevated exposure.

Domain
Risk management
Calculated after
Controls applied
Compared against
Risk appetite
If exceeded
Further treatment or formal acceptance

Common questions

Who decides whether residual risk is acceptable?+

Typically management or a designated risk owner reviews it against the organisation's stated risk appetite, and formally accepts or rejects the remaining exposure rather than leaving it undocumented.

Can residual risk ever be zero?+

Rarely, since almost all controls reduce rather than eliminate risk entirely, so some level of residual exposure is expected and managed rather than eliminated outright.

Related terms

Risk Appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
Risk Owner
The individual or role accountable for ensuring a risk is treated appropriately and that the treatment remains effective. Owners should control the...
Risk Register
A structured record of all identified risks, each with its description, inherent risk score, owner, treatment decision, controls selected, residual risk score,...
Risk Treatment
The process of selecting and implementing options to modify risk. ISO/IEC 27005 defines four treatment options: accept, avoid, mitigate (reduce), and transfer...
Statement of Applicability (SoA)
A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.