Skip to main content
Category: Risk Assessment & Analysis

Residual Risk

Simply put

Residual risk is the risk that remains after an organization has put security measures in place to address a threat or vulnerability. Because no set of controls eliminates risk entirely, some portion generally persists and must be recognized and accepted by decision-makers. It reflects what is left over once risk responses have been documented and carried out.

Formal definition

Residual risk is the portion of risk remaining after security measures or risk responses have been documented and performed, as defined in the NIST CSRC glossary. In practice, it is distinguished from inherent risk, which represents exposure before controls are applied; residual risk represents the exposure that persists after risk treatment and remediation efforts have been implemented. Authorizing officials and risk owners generally evaluate residual risk when deciding whether to accept, transfer, or further mitigate remaining exposure, though specific tolerance thresholds and treatment decisions depend on organizational and agency-specific risk management processes not covered here.

Why it matters

Residual risk is central to the authorization and risk acceptance decisions that govern whether a system may operate. Because no combination of controls eliminates exposure entirely, some portion of risk generally persists after security measures are applied, and someone with the appropriate authority must formally recognize and accept it. In defense and federal environments, this is where the concept connects directly to the role of the authorizing official, who evaluates the remaining exposure before granting an Authority to Operate (ATO). Treating residual risk as though it can be driven to zero, or ignoring it because controls have been implemented, misrepresents the actual risk posture that decision-makers are responsible for owning.

A common expert correction is to distinguish residual risk from inherent risk. Inherent risk represents exposure before controls are applied; residual risk is what remains after risk treatment and remediation efforts have been carried out. Conflating the two, or reporting inherent risk as if it were the accepted exposure, can lead leadership to believe a system is either more or less protected than it actually is. Equally important is recognizing that documenting residual risk is not the same as eliminating it, and that accepting residual risk is a deliberate decision that carries accountability.

Residual risk also reinforces why authorization is time-bound rather than permanent. Because the threat environment, system configuration, and control effectiveness change over time, the residual risk evaluated at the moment of authorization can shift. Continuous monitoring exists in part to detect changes that alter residual risk, prompting reassessment and, where warranted, additional mitigation or a revised acceptance decision. Verify specific tolerance thresholds and treatment obligations against your organization's or agency's current risk management process, as these are not defined by the general concept.

Who it's relevant to

Authorizing Officials
Authorizing officials evaluate residual risk when deciding whether to accept remaining exposure and grant or maintain an authorization. Because an ATO is time-bound and subject to continuous monitoring, they must treat residual risk as a value that can change and warrant reassessment rather than a one-time determination.
Information System Security Managers and Risk Owners
Those responsible for a system's security posture must clearly distinguish residual risk from inherent risk when documenting and communicating exposure, so that decision-makers understand what remains after controls and remediation efforts have been implemented rather than the exposure that existed beforehand.
Compliance Officers and Auditors
Compliance and audit personnel assess whether residual risk has been properly identified, documented, and accepted by the appropriate authority. They should confirm that documenting residual risk is not treated as equivalent to eliminating it, and verify treatment and acceptance decisions against the applicable organizational or agency-specific risk management process.
Government Contractors
Contractors operating systems on behalf of, or in support of, government customers should understand how residual risk is evaluated and accepted, and confirm the specific tolerance thresholds and treatment obligations that apply, as these depend on organizational and agency-specific processes not covered by the general concept.

Inside Residual Risk

Definition of Residual Risk
The risk that remains after security and privacy controls have been implemented and other risk responses (such as mitigation, transfer, or avoidance) have been applied. In the NIST RMF context, it reflects the exposure an organization continues to carry once selected safeguards are in place, as distinct from the initial or inherent risk assessed before controls.
Relationship to Risk Response
Residual risk is the outcome of the risk response step in a risk management process. After an organization decides how to treat identified risks, whatever remains is characterized as residual and must be evaluated for acceptability.
Role of the Authorizing Official (AO)
In RMF-governed systems, the authorizing official (or a designated representative) generally reviews and formally accepts residual risk as part of the authorization decision. Acceptance is a risk-based judgment that the remaining exposure is tolerable in light of mission needs; it should be documented rather than assumed.
Documentation and Traceability
Residual risk is typically captured in authorization package artifacts, which may include the security assessment report, plan of action and milestones (POA&M), and the risk determination narrative. These records tie remaining exposure to specific unmitigated or partially mitigated weaknesses. Practitioners should verify the exact required artifacts against current agency and RMF guidance.
Dynamic Nature Under Continuous Monitoring
Residual risk is not static. Because control effectiveness, threats, and system configurations change over time, residual risk is reassessed through continuous monitoring, and its acceptability may need to be revisited during the authorization period.

Common questions

Answers to the questions practitioners most commonly ask about Residual Risk.

Does accepting residual risk mean the system is now considered secure?
No. Accepting residual risk is a risk management decision, not a declaration that a system is secure. Residual risk is the risk that remains after security controls and other mitigations have been applied, and its formal acceptance by an authorizing official reflects a judgment that the remaining risk is tolerable for a defined period and mission context. Compliance and formal acceptance should not be equated with the absence of vulnerabilities or with security in an absolute sense; residual risk can and generally does change as threats, configurations, and mitigations evolve.
Once an authorizing official accepts residual risk at authorization, is that acceptance permanent?
No. Acceptance of residual risk is tied to a time-bound authorization decision and is subject to continuous monitoring. As threats emerge, controls degrade, or the system changes, the residual risk may shift and warrant reassessment. An Authority to Operate (ATO) is not permanent, and the residual risk accepted at one point may need to be re-evaluated and re-accepted as conditions change or at the point of reauthorization. Readers should confirm specific monitoring and reassessment expectations against current authoritative guidance and their organization's policies.
Where is residual risk typically documented in an RMF authorization package?
Residual risk is generally documented in the risk-related artifacts supporting the authorization decision, which in many implementations include the security assessment report, the plan of action and milestones (POA&M) for unremediated findings, and the authorizing official's authorization decision documentation. The specific document names, structure, and required content can vary by agency tailoring and applicable revision, so readers should verify the required artifacts against the current governing guidance and their organization's process.
Who has the authority to formally accept residual risk?
In most RMF implementations, formal acceptance of residual risk is a responsibility of the authorizing official, who makes the risk-based authorization decision on behalf of the organization. Other roles, such as information system security managers, system owners, and assessors, typically inform this decision by characterizing and documenting the risk, but the accountable acceptance decision rests with the designated authorizing official. Specific delegation and role definitions may differ by agency and should be confirmed against applicable policy.
How does a POA&M relate to residual risk?
A plan of action and milestones generally captures known deficiencies and the planned actions and timelines to address them, and the risk associated with those open items commonly contributes to the overall residual risk considered at authorization. Tracking items on a POA&M does not by itself reduce residual risk until the planned mitigations are implemented and validated. The precise handling of POA&M items and their effect on the risk determination can vary by agency tailoring, so readers should confirm current expectations against authoritative sources.
How should changes in residual risk be handled after authorization?
Changes in residual risk are generally addressed through continuous monitoring and configuration or change management processes. When monitoring, an incident, a new vulnerability, or a significant system change alters the residual risk, the change is typically evaluated to determine whether it remains within the previously accepted tolerance or whether it requires escalation, additional mitigation, or a reauthorization decision. The thresholds and procedures for such escalation are set by organizational policy and applicable guidance, which readers should verify against current authoritative text.

Common misconceptions

Residual risk means the system is insecure or that controls failed.
Residual risk is an expected and normal condition; no system eliminates all risk. Its presence reflects the reality that controls reduce but rarely remove exposure entirely. The relevant question is whether the remaining risk is understood, documented, and formally accepted at an appropriate level, not whether it exists at all.
Once residual risk is accepted, the decision holds for the life of the system.
Acceptance of residual risk is generally tied to a time-bound authorization and is subject to continuous monitoring. An ATO is not permanent, and changes in threats, controls, or the environment can alter residual risk, requiring reassessment and potentially a new acceptance decision.
Accepting residual risk is the same as being compliant.
Compliance and risk acceptance are distinct. Meeting a control baseline does not by itself mean the remaining risk has been formally evaluated and accepted, and formally accepting residual risk does not substitute for demonstrating that required controls and assessment steps were performed. Both the risk decision and the underlying compliance requirements must be addressed.

Best practices

Document residual risk explicitly in the authorization package, linking each remaining exposure to the specific unmitigated or partially mitigated weaknesses recorded in the assessment results and POA&M.
Ensure that acceptance of residual risk is a deliberate, documented decision made by the authorizing official or designated representative, rather than an implicit or undocumented assumption.
Reassess residual risk through continuous monitoring, and treat significant changes in threats, control effectiveness, or system configuration as triggers to revisit whether the accepted level remains valid.
Distinguish residual risk decisions from compliance status, confirming both that required controls and assessment steps were completed and that the remaining exposure was formally evaluated.
Verify the specific required artifacts, formats, and approval authorities for documenting and accepting residual risk against current RMF and applicable agency guidance, since these can vary by revision and organization.
Track residual risk against the authorization period, recognizing that acceptance is time-bound and may require renewed evaluation before or upon reauthorization.