Scoring & the Matrix

How to calculate residual risk on Mac

RiskOS works the residual score out from the controls you link, and shows the arithmetic behind every point it takes off.

Every risk in a register carries more than one score, and only one of them describes the situation you are in this morning. Inherent risk is the exposure with nothing standing in its way. Residual risk is what is left once your controls are taken into account, and it is the figure that should drive the sort order, the board slide and the argument about budget. Arriving at it is less a matter of arithmetic than of being honest about the controls.

Note

Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine.

Where residual risk lives

Choose Risks in the sidebar. The table carries a Residual column beside Inherent and Target, so the whole register can be sorted on it in one click. Select a row and the panel on the right opens on the risk itself.

Two sections of that panel do the work. Assessment holds the inherent steppers, the control effectiveness picker, the matrix with its inherent, residual and target markers, and the comparison grid that puts the three numbers and the gap side by side. Controls holds the switch that decides where the effectiveness figure comes from, the linked controls with their status and strength, and a picker for linking or creating more.

The residual figure is never typed into a box of its own. It is produced, and both sections exist so that you can see what produced it.

Calculate a residual score, step by step

  1. Open the risk and confirm its inherent rating

    Choose Risks, select the row, and open Assessment in the panel. Check that the inherent likelihood and impact describe the exposure with nothing standing in its way. Residual is calculated down from that pair, so an inherent rating with your controls already baked into it understates the risk twice over.

  2. Open the Controls section of the panel

    Scroll to Controls in the panel. It holds the toggle that derives effectiveness from linked controls, the list of controls already attached to this risk with their status and strength, and a picker for linking or creating more. An empty list is itself a finding: a risk with no linked controls has a residual score equal to its inherent one.

  3. Use the picker to link an existing control or create one on the spot. Link what genuinely stands between this risk and the event, not every control that sounds related. A register linking twelve controls to every risk can no longer tell you which one is carrying the weight.

  4. Check that each control is implemented or operating

    The linked list shows each control's status and effectiveness. Only controls that are implemented or operating reduce a risk. A planned control, however strong it will be once running, reduces nothing yet, and RiskOS says so rather than quietly counting it. Open a control from Controls in the sidebar to set its status once it is in place.

  5. Let the residual follow your controls

    Switch on the derive-from-controls toggle in the Controls section. The risk then takes its effectiveness from its strongest operating control, and the residual score is recalculated from that. Leave this on wherever you can: it means the register answers on its own when a control is improved, retired or its status changes.

  6. Read the residual score and the matrix

    Back in Assessment, the residual figure appears with its band named beside it — Low 1–4, Medium 5–9, High 10–16, Critical 17–25 — and the matrix gains a second marker. The markers glide from cell to cell when a rating changes, so the distance your controls are buying you is visible rather than asserted.

  7. Set effectiveness by hand only when you must

    Turn the derive switch off and you can choose an effectiveness value yourself, which is worth doing when the control catalogue has not caught up with reality. If that value disagrees with the controls you have linked, the panel points out the divergence instead of picking a side. Treat the warning as a task: either the control record is wrong, or your judgement needs writing down.

  8. Set a target and read the gap

    Set the target likelihood and impact you intend to reach. The comparison grid then shows inherent, residual, target and the gap between them, with a line telling you what strength of control would reach the target. Changes save as you type, and every assessment is kept in History, so the path from one number to the next stays readable a year later.

What the calculation will never do

The arithmetic is constrained on purpose, and those constraints are what let you compare two rows and trust the comparison.

The rules the residual calculation always obeys
RuleWhat it prevents
Residual never exceeds inherentA control cannot leave you worse off than having none. The residual marker can sit on the inherent one, never beyond it.
Residual never falls below 1No combination of controls removes a risk entirely. The floor is 1, which keeps a treated risk on the register rather than letting it vanish.
A stronger control never raises a scoreImproving a control can only move the residual down or leave it where it is, so nobody is punished by the register for strengthening something.
Scores are never read from a fileRiskOS recalculates every score itself, so an imported register obeys exactly the same rules as one you typed.

The practical effect is that a residual score is always defensible: point at the inherent rating, point at the controls, and the number between them follows from both.

Where the effectiveness figure comes from

The calculation rests on one input: how effective the controls on this risk are. That figure can arrive two ways, and the panel always says which is in force.

Derived from the linked controls

With the derive switch on, the risk takes its effectiveness from the strongest control that is actually operating. Prefer this setting: it keeps the register consistent with the control catalogue without anyone remembering to keep the two in step. Edit a control's status or effectiveness in Controls and every risk deriving from it re-scores at once.

Set by hand, with a divergence warning

Sometimes the catalogue lags behind what you know. Turn the switch off and the effectiveness picker is yours to set. RiskOS still watches the linked controls, and when your value disagrees with them it shows a divergence warning. It does not overrule you and it does not hide the disagreement. Use the description to say why you overrode it, so the next person reads a reason rather than a mystery.

How control status decides what counts

Status is the gate. Effectiveness enters the calculation only once the control is in place, which is the commonest reason a residual score refuses to move.

Which control statuses reduce a residual score
Control statusReduces the score?What it means
PlannedNoAgreed, funded, scheduled — and not yet doing anything. Track the work as an action on the control.
ImplementedYesIn place. Its effectiveness now counts towards every risk it is linked to.
OperatingYesIn place and running as intended. The strongest operating control is the one a derived risk follows, and the evidence notes on the control record what you would show for it.
RetiredNoWithdrawn. Risks that relied on it re-score upwards, which is exactly the signal you want.

CTL-0003 Quarterly restore rehearsal is the classic case: a strong control that is still planned. Until its status changes, RSK-0007 Backup restoration has never been tested end to end keeps a residual of 15 against an inherent of 20, and the register is right to hold the line.

Whether controls reduce likelihood, impact or both

One choice in Settings ▸ Methodology decides which half of the multiplication your controls are allowed to touch, and it changes the shape of every residual score in the register.

The three ways controls can reduce a score
SettingWhat the controls moveWhere it suits
Reduce likelihoodThe likelihood rating falls; impact stays where it was.Registers dominated by preventive work, where the event is as bad as ever but far less probable.
Reduce impactThe impact rating falls; likelihood stays where it was.Continuity and recovery work, where you expect the event and have shortened what it costs you.
Reduce bothBoth ratings fall together.Mixed registers, and the choice most organisations settle on when controls do a bit of each.

Changing this setting re-scores every risk immediately, rather than leaving older rows rated under the old rule. That is the behaviour you want, and it is also a reason to make the decision once, early. A register where half the rows were scored one way and half the other cannot be compared with itself.

Reading residual risk across the register

The number earns its keep outside the panel it was calculated in.

The register table and appetite

Sort the table on Residual to see where you stand rather than how bad the world is. Set an organisation-wide appetite in Settings ▸ Appetite and any risk above it is flagged everywhere it appears — the table, the panel header, the dashboard and the report. The filter bar carries an over-appetite-only switch for the pass where that is all you want.

Assets, vendors and coverage

Each asset shows its worst residual risk, so Assets answers "what is our most exposed system" without anyone building a view for it. Frameworks applies the same honesty rule from the other direction: a requirement counts as covered only when a mapped control is implemented or operating.

History and movement

History keeps every assessment with its reason and draws a residual score chart, so a risk's direction of travel is a line rather than a memory. The Trend column carries the same story into the table.

Troubleshooting

The residual score is the same as the inherent score

That is the correct answer when nothing is reducing the risk. Open Controls on the risk: either no controls are linked, or the ones that are linked are planned or retired. Link what you rely on, and set the status of anything that is genuinely in place.

I linked a control and nothing moved

Check three things in order. The control's status must be implemented or operating. The derive switch must be on, or the risk is using a value you set by hand. And a control weaker than the one already carrying the risk changes nothing, because a derived risk follows its strongest operating control rather than adding them up.

The panel says my value disagrees with the controls

You have set effectiveness by hand and the linked controls imply something different. Nothing is broken. Decide which record is out of date: update the control's status or effectiveness, or leave your value in place and write the reason into the risk's description. Switching the derive toggle back on clears the divergence by handing the decision to the controls.

The residual dropped further than I expected

Look at what the methodology allows controls to move. With reduce both selected, the reduction lands on likelihood and on impact together. Because the score is likelihood multiplied by impact rather than the two added up, moving both sides at once takes the figure down further than moving one of them would.

Every residual score changed at once

Two things do that by design. Changing whether controls reduce likelihood, impact or both re-scores the whole register immediately. And an import that changes a control's status or effectiveness re-scores every risk relying on it — an import shows you line by line what it will do before anything is written.

Habits that keep residual scores honest

  • Derive by default. Leave the derive switch on unless you have a specific reason not to, so the register keeps itself in step with the control catalogue rather than relying on somebody's memory.
  • Treat status as a promise. Move a control to implemented on the day it is genuinely in place, not the day it is approved. Every residual score in the register is downstream of that date.
  • Clear divergence warnings weekly. Each one is a disagreement between what you believe and what the register records. They are quick to resolve and expensive to ignore.
  • Sort on residual, scan the gap. A Critical risk with a credible plan and a closing gap is in better shape than a Medium one nobody has revisited since March.
  • Let indicators and events test the number. A breached threshold on a risk with a comfortable residual is the most useful contradiction a register can give you, and when a risk materialises more often than its rating implies, RiskOS suggests what the observed frequency would justify.
  • Re-score in one pass. Review walks the risks that are due, worst first, with the controls and actions beside the scoring inputs.

Frequently asked questions

What is residual risk?

Residual risk is what remains after the controls you have in place are taken into account. Inherent risk is the same exposure with nothing standing in its way. The difference between the two is the value your controls are delivering, which is why RiskOS shows both numbers rather than collapsing them into one.

How is residual risk calculated?

From the inherent likelihood and impact you rate, reduced by the effectiveness of the controls linked to the risk. RiskOS takes that effectiveness from the strongest control that is actually operating, or from a value you set by hand, and the methodology decides whether the reduction lands on likelihood, on impact, or on both.

Can residual risk be higher than inherent risk?

No. Residual can equal inherent when nothing is reducing the risk, but it can never exceed it, because a control cannot leave you worse off than having none. The score also never falls below 1. Those two limits hold whatever effectiveness values and methodology settings are in force.

Why has my residual score not gone down after adding a control?

Usually the control is still planned. Only controls that are implemented or operating reduce a risk, and RiskOS says so rather than counting work that has not started. Check also that the derive switch is on, and that the new control is genuinely stronger than the one already carrying the risk.

Should I enter a residual risk score manually?

There is no box for one, and that is deliberate. You can set control effectiveness by hand when the catalogue has not caught up, but the score itself is always calculated. A typed residual is a number with no argument behind it, and it is the first figure an auditor will pull on.

What is the difference between residual risk and target risk?

Residual is where you are now, given the controls in place. Target is where you intend to be, stated as a likelihood and an impact you choose. The comparison grid shows both along with the gap, and a line telling you what strength of control would close it.

Do controls reduce likelihood or impact?

Whichever you decide, in Settings ▸ Methodology. Preventive registers often reduce likelihood, continuity-led ones reduce impact, and many organisations choose both. Changing the setting re-scores every risk in the register at once, so nothing is left rated under the previous rule.

What happens to residual scores when I import controls?

Every risk relying on a control whose status or effectiveness changed is re-scored. Scores themselves are never read from the file. The import shows you line by line what will be created, updated or skipped, along with the projected score and any problems, and nothing is written until you confirm.