Residual Risk
What is Residual Risk?
The risk that remains after controls have been applied. If residual risk exceeds the organisation's risk appetite, additional controls or risk treatment is required.
Related terms
Frameworks that govern residual risk
What the standards actually require on residual risk
Requirements naming residual risk across 6 standards, quoted from the control text.
Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented.
AIRMF-MN-1.4 · Negative residual risks, defined as the sum of all unmitigated risks, to both downstream acquirers of AI systems and end users are documented →Recalculate and document residual risks after planned treatment measures with formal acceptance.
ISO29134-8.2 · Residual Risk Documentation →Assess residual risk remaining after controls and have management formally assess and accept it through a risk acceptance process.
ADMF-5.5 · Manage and accept residual risk →The FSA expects financial institutions to implement a comprehensive cybersecurity risk management framework + aligned with NIST CSF 2.0 + FFIEC IT Examination Handbook + ISO/IEC 27001 ISMS + integrated into Enterprise Risk Management (ERM).
JP-FSA-CYB-Risk-Management-NIST-CSF-FFIEC-Aligned-Identify-Protect-Detect-Respond-Recover-Govern-Plan-Do-Check-Act · Japan FSA Cybersecurity Risk Management Framework + NIST CSF 2.0 Aligned + FFIEC Crosswalk + Identify Protect Detect Respond Recover Govern + ISO 27001 ISMS + Plan-Do-Check-Act + Inherent vs Residual Risk + Risk Appetite + Cyber Risk in ERM →Route every deviation from security policies, instructions and the related controls through the risk management process, secure risk owner approval and residual risk acceptance, record each deviation with a defined expiry, and have risk owners reconfirm its ap...
C5-SP-03 · Exceptions from Existing Policies and Instructions →The assessment informs the system owner's authorisation to operate (ATO) decision; findings and residual risk support the authorising officer.
IRAP-OUT-2 · Authority to Operate decision support →Questions people ask about residual risk
What is Residual Risk?
Why is Residual Risk important for compliance?
What concepts are related to Residual Risk?
Which compliance frameworks address Residual Risk?
Where can I learn more about Residual Risk?
See how Residual Risk applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.