· Guide · 2 min read

Inherent vs Residual Risk in ISO 27001: Examples and Scoring Guide

Learn how inherent and residual risk differ, how controls affect scoring, and how to document treatment and acceptance with practical examples.

Risk scenario progressing through likelihood, impact, treatment and residual risk.

Inherent risk and residual risk answer different questions. Inherent risk asks: what would exposure look like before selected controls are taken into account? Residual risk asks: what exposure remains after relevant controls are considered? The distinction helps teams explain why they invested in safeguards and whether the remaining risk is acceptable.

Example: privileged access

Scenario: A privileged account is compromised and used to alter production systems. Possible inherent assessment:

  • Likelihood: 4
  • Impact: 5
  • Score: 20 Relevant controls might include phishing-resistant authentication, privileged access management, restricted administration paths, alerting and periodic access review. Residual assessment after controls:
  • Likelihood: 2
  • Impact: 5
  • Score: 10 Why may impact remain high? Controls can reduce probability without changing the consequence if compromise still occurs. The numbers are illustrative. The evidence matters: configuration, access-review records, alert tests and incident exercises support the residual judgement.

You can model the same before-and-after relationship in the free ISO 27001 Risk Score Calculator, which keeps calculations in the browser and can export a session register for further review.

Example: backup failure

Scenario: Production data is lost and cannot be restored within business requirements. Controls include redundant backups, separation, monitoring and restore testing. A successful scheduled backup does not by itself prove recovery. Residual likelihood should consider restore-test results, failures, corrective actions and changes since the test.

Common scoring errors

  • Reducing both likelihood and impact automatically.
  • Treating every listed control as fully effective.
  • Hiding assumptions behind a single number.
  • Comparing scores created with different scales.
  • Accepting high residual risk without named authority.
  • Failing to review risk after material change.

A defensible risk record

Keep:

  • scenario;
  • asset or process;
  • threat and vulnerability;
  • existing controls;
  • inherent likelihood and impact;
  • rationale;
  • planned treatment;
  • residual likelihood and impact;
  • evidence;
  • owner;
  • acceptance decision;
  • review date; and
  • uncertainty or assumptions. Review the practical risk-register guide: information security risk register guide Explore Clause 6.1.2 and 6.1.3 context: ISO 27001 Clause Explainer