Residual Risk
Residual risk is the risk that remains after an organization has put security measures in place to address a threat or vulnerability. Because no set of controls eliminates risk entirely, some portion generally persists and must be recognized and accepted by decision-makers. It reflects what is left over once risk responses have been documented and carried out.
Residual risk is the portion of risk remaining after security measures or risk responses have been documented and performed, as defined in the NIST CSRC glossary. In practice, it is distinguished from inherent risk, which represents exposure before controls are applied; residual risk represents the exposure that persists after risk treatment and remediation efforts have been implemented. Authorizing officials and risk owners generally evaluate residual risk when deciding whether to accept, transfer, or further mitigate remaining exposure, though specific tolerance thresholds and treatment decisions depend on organizational and agency-specific risk management processes not covered here.
Why it matters
Residual risk is central to the authorization and risk acceptance decisions that govern whether a system may operate. Because no combination of controls eliminates exposure entirely, some portion of risk generally persists after security measures are applied, and someone with the appropriate authority must formally recognize and accept it. In defense and federal environments, this is where the concept connects directly to the role of the authorizing official, who evaluates the remaining exposure before granting an Authority to Operate (ATO). Treating residual risk as though it can be driven to zero, or ignoring it because controls have been implemented, misrepresents the actual risk posture that decision-makers are responsible for owning.
A common expert correction is to distinguish residual risk from inherent risk. Inherent risk represents exposure before controls are applied; residual risk is what remains after risk treatment and remediation efforts have been carried out. Conflating the two, or reporting inherent risk as if it were the accepted exposure, can lead leadership to believe a system is either more or less protected than it actually is. Equally important is recognizing that documenting residual risk is not the same as eliminating it, and that accepting residual risk is a deliberate decision that carries accountability.
Residual risk also reinforces why authorization is time-bound rather than permanent. Because the threat environment, system configuration, and control effectiveness change over time, the residual risk evaluated at the moment of authorization can shift. Continuous monitoring exists in part to detect changes that alter residual risk, prompting reassessment and, where warranted, additional mitigation or a revised acceptance decision. Verify specific tolerance thresholds and treatment obligations against your organization's or agency's current risk management process, as these are not defined by the general concept.
Who it's relevant to
Inside Residual Risk
Common questions
Answers to the questions practitioners most commonly ask about Residual Risk.