Inherent Risk
What is Inherent Risk?
The level of risk present in an activity or process before any controls or mitigating actions are applied, representing the natural risk exposure.
Terms that appear alongside inherent risk
Each of these is named in at least one of the same controls as inherent risk. The number is how many controls name both.
- remediation 5 shared controls
- risk assessment 4 shared controls
- cybersecurity 3 shared controls
- resilience 2 shared controls
- policy 2 shared controls
- security officer 2 shared controls
- maturity assessment 2 shared controls
- risk acceptance 2 shared controls
Frameworks that govern inherent risk
What the standards actually require on inherent risk
Requirements naming inherent risk across 6 standards, quoted from the control text.
HKMA C-RAF Inherent Risk Assessment (IRA) + Maturity Assessment (MA) methodology + assessment cycle. INHERENT RISK ASSESSMENT (IRA): scoring AI inherent cyber risk based on multiple factors including (a) TECHNOLOGY FOOTPRINT - on-premise + cloud + hybrid + com...
HKMA-CRAF-IRA-Maturity-TargetLevel-Cycle · HKMA C-RAF Inherent Risk Assessment (IRA), Cyber Maturity Assessment (MA), Target Maturity Level, Assessment Cycle →Score inherent risk arising from online and mobile delivery channels including ATM operations and number of customers served.
FFIEC-CAT-IRP-2 · Inherent Risk Profile - Delivery Channels →Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
NIST-CSF-ID.RA-05 · Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization →Classify service providers. Classification consideration may include one or more characteristics, such as data sensitivity, data volume, availability requirements, applicable regulations, inherent risk, and mitigated risk.
CIS-15.3 · Classify Service Providers →The FATF Methodology for Assessing Technical Compliance with the FATF Recommendations + Effectiveness of AML/CFT Systems is the assessment framework for Mutual Evaluations (currently 5th round 2020-2027 + 6th round in development for post-2027).
FATF-Methodology · FATF Methodology - Technical Compliance and Effectiveness (Immediate Outcomes) →The IRM Risk Management Process is a 5-stage continuous cycle aligned closely with ISO 31000:2018 + COSO ERM 2017. (1) Risk Identification: systematic identification of risks through workshops + interviews + SWOT/PESTLE analysis + scenario analysis + bow-tie a...
IRM-Process-Identification-Analysis-Evaluation-Treatment-Monitoring-Review-ISO31000-Aligned · IRM Risk Management Process - 5-Stage Cycle + Identification + Analysis (Inherent/Residual) + Evaluation + Treatment (4Ts Tolerate/Treat/Transfer/Terminate) + Monitoring + Review + Communication + Risk Register →Questions people ask about inherent risk
What is Inherent Risk?
Why is Inherent Risk important for compliance?
Which compliance frameworks address Inherent Risk?
Where can I learn more about Inherent Risk?
See how Inherent Risk applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.