Auditen
Home / Glossary / Residual risk

Residual risk

Also known as: Net risk, Remaining risk

Residual risk is the level of risk that remains after security controls and mitigation strategies have been implemented. It represents the actual exposure an organization faces once its defenses are in place. If this remaining risk exceeds a company's defined risk appetite, further controls must be added or the risk must be formally accepted by management.

In practice

During an audit, a practitioner assesses residual risk by testing existing controls to see if they effectively reduce inherent risk to an acceptable level. For example, while encryption reduces the risk of data theft, the remaining possibility that an authorized user might leak data is the residual risk.

More terms