Inherent and Residual Risk Score

Last updated: November 20, 2025

This document aims to clearly define the difference between inherent risk scores and residual risk scores, helping you determine the appropriate level for each.


Inherent Risk

Inherent risk is the level of risk that exists before any controls, safeguards, or mitigation efforts are applied. It reflects the natural exposure based on the activity, process, or environment itself.


Example: Storing customer data in a cloud environment naturally carries confidentiality and availability risks, even if you haven’t added protections yet.

Residual Risk

Mitigated risk—often called residual risk—is the level of risk that remains after you’ve implemented controls, protections, and mitigation measures. It shows how effective your security or operational controls are in reducing the inherent risk.


Example: After adding encryption, access controls, monitoring, and backups, the initial risk of storing customer data is reduced to a more acceptable level.