Ask two people to rate the same risk and you will often get two very different answers — not because they disagree about the danger, but because they are quietly rating two different things. One is picturing the risk as if nothing were being done about it. The other is picturing it as it stands today, with the firewall running, the backups taken, and the contract signed. Both are correct. They are simply describing the risk at two different moments in its life.
Those two moments have names. Inherent risk is the exposure before your controls. Residual risk is what remains after they do their job. Recording both is a staple of internal-audit and enterprise-risk practice — the COSO framework builds the gross-and-net distinction in explicitly. (ISO 31000 is lighter here: it uses the term residual risk but not inherent risk, and does not require you to rate the pair.) However you arrive at it, the discipline is far more than bookkeeping. Handled well, the pair tells you things a single rating never can: what your controls are actually worth, whether a risk needs more treatment, and where you are exposed without knowing it.
The two definitions, precisely
Inherent risk (also called gross risk) is the likelihood and impact of a risk with no controls in place. Imagine the safeguards switched off: no access restrictions, no review process, no insurance, no backups. How likely is the event then, and how severe?
Residual risk (also called net risk) is the same risk rated with your current controls operating as they actually operate today. Not as they are described in a policy — as they truly function, including the ones that are only half implemented.
The difference between them is the measure of your controls. If a risk scores 20 inherent and 6 residual, your controls are carrying a great deal of weight. If it scores 20 inherent and 18 residual, you have documented a risk you are barely touching — and that gap, or the lack of it, is exactly the insight the two-rating discipline exists to surface.
Why rate both, when one number seems simpler
A single residual rating tells you where a risk sits. The pair tells you four things instead of one.
What your controls are worth. The gap between inherent and residual is the return on every euro and every hour you have already spent on prevention. This is unusually persuasive in budget conversations: "this control moves the risk from 20 to 6" is a far stronger argument than "this control is important."
Whether more treatment is needed. The residual rating — not the inherent one — is what you compare against your risk appetite. If residual risk still exceeds the level you are willing to accept, you need more treatment. If it sits comfortably below, you can stop and monitor.
Where you are not really in control. A residual rating that sits close to its inherent value is a warning light. It means that for all the activity around this risk, almost nothing is actually reducing it — a common and dangerous pattern with risks everyone "manages" but no control genuinely touches.
What good would look like. Introducing a third rating — target residual risk, the level you are aiming for once planned measures are in place — turns the pair into a plan. Inherent shows the raw danger, current residual shows today, and target residual shows the destination. The distance between today and target is your treatment backlog.
How to rate inherent risk without exaggerating
Rating inherent risk sounds simple — "just remove the controls" — but it hides a genuine trap, and it is the reason inherent ratings are so often useless. If you strip away every control, including the locks on the doors and the existence of a competent staff, every risk becomes a catastrophe and every inherent rating reads 25. That is not information; it is theatre.
The workable convention is to imagine the reasonable absence of the controls you deliberately put in place for this risk, not the absence of civilization. For a data-breach risk, remove the access controls, the encryption, and the monitoring you introduced — but assume the building still has doors and the staff can still read. You are asking: how bad would this be if we had simply never got around to managing it? That question has a meaningful answer. "How bad if nothing on Earth existed to stop it?" does not.
Rate inherent risk once, and revisit it rarely. It changes only when the underlying business changes — a new product, a new dependency, a new market — not when you add or remove a control. Controls move residual risk, not inherent risk.
How to rate residual risk honestly
Residual risk has the opposite trap: taking credit for controls that do not really work.
A control reduces residual risk only to the extent that it actually operates. A backup policy that has never been tested by restoring from it does not reduce residual risk — it reduces it on paper, which is worse than nothing because it buys false comfort. The same applies to the access review that happens "in principle," the incident plan that has never been rehearsed, and the training everyone clicked through without reading. When you rate residual risk, count only the control effectiveness you could defend to an auditor with evidence.
This is why residual risk must be re-rated regularly while inherent risk can sit still. Controls decay. People leave, tools drift out of date, exceptions accumulate, and a control that genuinely worked last year may be quietly failing this year. A residual rating is a statement about the present, and the present keeps moving — which is precisely what monitoring and review exists to catch.
Recording the pair — and showing the movement
In the risk register, the two ratings sit side by side: inherent likelihood and impact, then residual likelihood and impact, ideally with the target beside them. On the 5×5 matrix, they become an arrow — the risk plotted at its inherent position, an arrow pointing to where it sits after controls, and sometimes a second arrow to the target. That arrow is one of the most eloquent objects in all of risk reporting: it shows a decision-maker, in a single glance, both the size of the danger and the value of the work already done against it.
A register full of these arrows tells a story a column of single numbers cannot. Long arrows mean controls that earn their keep. Short arrows mean risks you are watching but not reducing. No arrow at all — inherent and residual identical — means a risk you have described but never treated.
The common mistakes, collected
Rating them identical for everything. If every risk shows the same inherent and residual score, either you are taking no credit for real controls, or you have not thought about controls at all. Both are worth fixing.
Rating inherent risk as the apocalypse. Every inherent score reading 25 means the "remove all controls" thought experiment was taken too literally. Anchor it to the reasonable absence of your own deliberate controls.
Claiming reductions you cannot evidence. A dramatic gap between inherent and residual is only credible if the controls behind it are real and tested. An impressive arrow drawn on faith is a liability, not an achievement.
Freezing residual risk. Rate it once and never again, and it slowly becomes fiction as controls decay. Residual risk is a present-tense statement and needs re-checking on your review cadence.
The distinction in one line
Inherent risk is the size of the problem. Residual risk is the size of the problem after you have done something about it. The space between them is the value of your risk management — and making that space visible, honestly, is most of what good risk analysis is for. A tool built for the job keeps both ratings, the target, and the full history of how they moved, so the arrow is always current rather than reconstructed once a year; EasyRisk.io does exactly that, and it is free to start.
Frequently asked questions
What is the difference between inherent and residual risk? Inherent risk is the exposure before any controls — the likelihood and impact of the event if nothing were being done about it. Residual risk is what remains after your current controls operate as they actually operate today. The gap between the two measures how much your controls reduce the risk.
Which rating do you compare against risk appetite? The residual rating. Appetite is about the risk you are willing to live with after controls, so residual risk is the number that decides whether a risk is acceptable or needs more treatment. Inherent risk tells you how big the underlying problem is, not whether you can live with today's exposure.
How do you calculate inherent risk? Rate likelihood and impact while imagining the reasonable absence of the controls you deliberately introduced for that risk — not the absence of every safeguard in existence. The goal is a meaningful "how bad if we had never managed this" figure, which is why stripping away doors, locks, and competent staff produces a useless answer.
What is target residual risk? It is the residual risk level you are aiming for once planned treatments are in place — a third rating alongside inherent and current residual. It turns the pair into a plan: the distance between today's residual risk and the target is your treatment backlog.