Inherent vs Residual Risk
Inherent risk is the exposure a risk carries before any controls — likelihood times impact in the raw. Residual risk is what remains after your controls operate. Every credible risk register scores both, because the gap between them is a claim: “our controls reduce this risk by this much.”
Why both numbers matter
Auditors and examiners test the claim. A risk scored inherent-high and residual-low invites the obvious question — which controls, and are they operating? If the linked controls are aspirational, the residual score is fiction and the register loses credibility wholesale. Conversely, scoring everything residual-high suggests your controls do nothing, which raises different questions.
The practical method
Score inherent risk first, ignoring controls entirely (this feels artificial; do it anyway — it preserves the register’s logic when a control fails). Then map the specific controls that reduce it, and score what honestly remains. The residual score is what gets compared against your risk appetite to drive treatment decisions: accept, mitigate further, transfer, or avoid.
The audit tell
Registers where inherent and residual columns are identical, or where residual scores have no linked controls, read as paperwork rather than process. The two-column discipline is cheap and it’s the difference between a register that survives sampling and one that doesn’t.
Compensating Control — A compensating control mitigates a risk when the standard control isn't feasible — accepted by auditors when documented, justified, and genuinely equivalent.
Risk Appetite — Risk appetite is the level of risk leadership has decided to accept — the threshold that turns a risk register from a list into a decision system.
Risk Register — A risk register is the living record of identified risks, their scores, owners, and treatments — sampled in every SOC 2 and ISO 27001 audit.