Glossary · Foundations
Inherent Risk
The level of risk before any control is applied. Compared against residual risk, it shows how much a set of controls actually removes.
What inherent risk is
Inherent risk is the raw exposure of an activity or asset, assessed as if no controls were in place. It provides a baseline against which the effect of controls can be measured. Comparing inherent risk with residual risk shows how much a set of controls actually reduces exposure, which helps justify investment in those controls. German practice uses Bruttorisiko for the same idea and Nettorisiko for the residual value.
How it is assessed
Likelihood and impact are rated for the scenario with the existing safeguards thought away: what would a phishing campaign do if there were no filtering, no awareness training and no multi-factor authentication? The result is a point on the risk matrix. The same scenario is then rated a second time with the controls in place, and the distance between the two points is the effect the controls are credited with.
Where it helps and where it misleads
- It makes the value of controls visible: a control that moves a risk from very high to low is worth its cost, one that moves nothing is a candidate for removal.
- It shows dependence on a single control: a large gap between inherent and residual risk that rests on one safeguard is a concentration risk in itself.
- It is hypothetical. Rating a world without any controls is difficult, and neither ISO/IEC 27001 nor ISO 31000 requires it. Many organisations rate only the current risk and record the controls that the rating relies on.
Whichever approach is chosen, the risk register should state which one it uses, so that two ratings of the same scenario can be compared.