Residual risk is the risk that remains after the measures intended to reduce it have been applied. Inherent risk is the level before those measures. The difference between the two is the value the security programme claims to be delivering.
That claim is almost never evidenced.
In most risk registers, both ratings are assigned in a workshop. Inherent is rated high because the scenario is alarming when described without any defences. Residual is rated medium or low because controls exist.
Nothing measured the reduction. The delta was argued, agreed and written down, and it will be carried forward largely unchanged for years.
This is not dishonest. It is what happens when the only available inputs are judgement, and it produces a specific pathology: the residual rating reflects how much effort the organization believes it has put in, rather than how much exposure it actually carries.
The measures relied on to move a risk from inherent to residual should be named individually in the register, not summarised.
Each of those measures should have an indicator showing whether it is operating across the full population. See control effectiveness.
When those indicators degrade, the residual rating should move without anyone having to argue for it. That is the mechanism most registers lack, and its absence is why ratings sit still for years.
Systematically, and in predictable places.
Where a control is credited at design rather than at operation. The reduction assumes the control works everywhere it is meant to.
Where population coverage is unmeasured. A measure operating on 70 percent of the estate was rated as though it operated on all of it.
Where compensating measures are counted twice, once for the risk they were introduced for and again for an adjacent one.
Where the residual rating was set before an acquisition, a cloud migration or a workforce change altered the exposure underneath it.
Residual risk is the number that gets compared against risk appetite. If residual sits within appetite, no action is required.
Which means an understated residual rating produces exactly the wrong outcome: a risk that appears to be within tolerance and is not. The rating is doing real work, and it deserves better evidence than a workshop from three years ago.
From the blog