What inherent, residual and target risk mean
Three scores sit on every risk in RiskOS, a risk register for macOS. What each one is for, who sets it, and what the distance between them is telling you.
Every risk in a register carries three scores, and they are not three opinions about the same thing. Inherent says how exposed you would be with nothing standing in the way; residual says where you stand this morning, given the controls you actually run. Target says where you have decided to get to, and the distance between the last two is a treatment plan written as a number.
Only two of the three are yours to set. The residual score is worked out from the controls you link, and the panel always shows how it got there.
Where the three numbers live
Choose Risks in the sidebar. The register table carries Inherent, Residual and Target as three adjacent columns, so a register reads as movement across a row rather than a single verdict at the end of it. Sort on whichever the pass calls for, and right-click the header to hide the ones you are not using; RiskOS remembers the arrangement.
Select a risk and the panel on the right opens. Under Assessment the three are set and shown together: the inherent likelihood and impact steppers near the top, the control effectiveness that produces the residual in the middle, and the target ratings below. Beneath them sits a matrix carrying three markers with a legend naming each one, and under that a comparison grid laying out inherent, residual, target and the gap. Change any rating and the markers glide to their new cells.
| Score | The question it answers | Who sets it | What moves it |
|---|---|---|---|
| Inherent | How bad would this be with nothing in the way? | You, on the two steppers | Re-rating the likelihood or the impact |
| Residual | Where does it stand given what we run today? | RiskOS, from the linked controls | A control's status or effectiveness changing |
| Target | Where have we decided to get to? | You, on the target steppers | A decision, not an event |
Set all three on one risk
The order matters more than people expect. Rate the exposure first, record the controls second and state the intention last, because each step depends on the honesty of the one before it.
-
Open the risk and its Assessment section
Choose Risks in the sidebar and click the row you want, or press ⌘N to create one. The panel on the right opens on Summary, with Assessment beneath it. Every rating that produces the three numbers is set in that one section.
-
Rate the inherent exposure
The two steppers at the top of Assessment are always inherent. Pick a likelihood from Rare, Unlikely, Possible, Likely and Almost Certain, and an impact from Insignificant, Minor, Moderate, Major and Severe, rating the risk as though none of your controls existed. Each stepper shows its scale label, so you can see you are choosing Likely rather than an abstract four.
-
Read the inherent score and its band
The score appears at once: likelihood multiplied by impact, from 1 to 25, with its band named beside it — Low 1–4, Medium 5–9, High 10–16, Critical 17–25. The matrix moves its inherent marker into the cell you chose, and it will not move again until you re-rate the exposure.
-
Link the controls you rely on
Open Controls in the same panel and use the picker to link an existing control or create one on the spot. With the derive-from-controls toggle switched on, the residual follows your strongest operating control automatically, so the second number stops being a matter of opinion.
-
Check the status of each linked control
The linked list shows every control with its status and its effectiveness. Only controls that are implemented or operating reduce a risk: a planned control, however strong it will be once it runs, reduces nothing yet, and the panel says so rather than quietly counting it. Fix any wrong status before you read the residual.
-
Read the residual score and the reason beside it
A second marker appears on the matrix and the comparison grid fills in its residual row. Alongside it the panel states how it got from the first number to the second: which control carried the reduction, and how strong that control is. You can set effectiveness by hand instead, and the panel will tell you when your value disagrees with the controls you have linked.
-
Set the target likelihood and impact
Lower in Assessment, set the likelihood and impact you intend to reach and a third marker joins the matrix. Put the target where the treatment plan can credibly land it, not where you would like the world to be: a target nobody believes is a target nobody works towards.
-
Read the gap, and what would close it
The comparison grid now shows inherent, residual, target and the gap on rows of their own, followed by a line naming what strength of control would reach the target from where you stand. Changes save as you type, and the assessment is kept in History with the reason you gave.
Inherent risk: the exposure with nothing in the way
Inherent is the honest starting point. It asks what this risk would do to the organisation if every safeguard you rely on were withdrawn tomorrow: no monitoring, no backups, no contract clause, no second supplier. That is an uncomfortable question, which is why it is worth answering. It is also the only rating on the risk that does not move when the world around it changes.
The temptation is to rate "how bad is it now", because that feels more realistic. It is also the quickest way to make a register unreadable: a number that bakes today's controls into today's rating cannot be unpicked later. Rate the exposure, record the controls separately, and RiskOS can always show its working, including what would happen if a control were retired.
Inherent ratings should be stable. If one moves every quarter, either the risk is being re-described at each review or the controls are leaking into the rating. History makes both easy to catch: every assessment is kept with its reason and the score it produced.
Residual risk: what the controls actually leave
Residual is the number you manage against day to day. It is the exposure after the controls you genuinely run have taken effect, and it is what the appetite threshold, the dashboard and a report's top-risks section all read. RiskOS calculates it rather than accepting it, because a residual typed in by hand is a claim with no argument behind it.
The arithmetic follows one choice you make once, in Settings ▸ Methodology: whether controls reduce likelihood, impact or both. Everything else follows from the controls themselves, and because the rule is applied consistently the residual column can be compared across the whole register.
| Rule | What it means in practice |
|---|---|
| Residual never exceeds inherent | A control cannot make a risk worse than it would have been untreated. |
| Residual never falls below 1 | No amount of control takes a live risk to zero. Something always remains. |
| A stronger control never raises a score | Improving a control can only hold the residual steady or bring it down. |
| Only implemented or operating controls count | A planned control changes the residual the day its status changes, not before. |
When you set effectiveness by hand
There are honest reasons to override. A control might be operating well below its design strength for this particular risk, or a compensating arrangement might not be written up as a control yet. Switch the derive-from-controls toggle off and set the value yourself. What you do not get is silence: when a hand-set value disagrees with the linked controls, the panel raises a divergence warning and shows both.
Target risk: the number you are aiming at
Target is a decision, not a measurement. It says where the organisation has agreed this risk should sit once the treatment plan has done its work, and it is the only one of the three about the future. Setting it turns a strategy from a sentence into something you can hold a date against.
Not every risk needs an ambitious target. Where the strategy is Accept, the target is often the residual you already have, and the plan records why that is tolerable. Where it is Mitigate, the target should sit at or below your appetite threshold, because a plan that lands a risk still over appetite has not finished. Transfer and Avoid imply the steepest drops, and those need the most credible plans.
A useful discipline: set the target with the treatment plan open beside it. If you cannot name the control that will carry the risk from where it is to where the target sits, the target is a wish. Under the comparison grid, RiskOS names what strength of control would reach it from the current position.
The gap between them, and what it is for
The gap is residual minus target: the work the treatment plan has agreed to do, and the most useful number on the risk once the ratings settle. A Critical risk with a credible plan and a closing gap is in better shape than a Medium one nobody has touched since March.
Take RSK-0007, Backup restoration has never been tested end to end, owned by M. Halvorsen under Business Continuity. Untreated the inherent score is 20. One control is operating — CTL-0002, immutable offsite backups, at moderate effectiveness — bringing the residual to 15. A second, CTL-0003, a quarterly restore rehearsal, is rated high but still planned, so today it contributes nothing. The target is 4.
| Score | Value | Band | What it is telling you |
|---|---|---|---|
| Inherent | 20 | Critical | Untested recovery, with nothing standing in the way. |
| Residual | 15 | High | One moderate control operating. Six points over an appetite of 9. |
| Target | 4 | Low | Where a rehearsed, evidenced restore would land it. |
| Gap | 11 | — | The work the treatment plan has committed to. |
Read across the row and the whole story is there. Inherent justifies the attention, residual explains the appetite breach, and a gap of eleven points says the plan is substantial. The day CTL-0003 moves to operating, the residual falls without anyone re-rating the risk, and the gap closes itself.
Where appetite sits among the three
Appetite is measured against the residual score, never the inherent one. The threshold is the highest residual you are willing to live with, and any risk above it is flagged wherever it appears. RiskOS resolves it in a fixed order: an override on the risk itself, then the category's threshold, then the organisation's, then none. That ordering matters when you read a breach, because the number a risk is judged against may not be the organisation-wide one.
How the three appear in a report
Residual is the score to lead with when you report, because that is where the organisation stands today. Keep inherent beside it so the reduction your controls deliver stays visible, and carry the target so a high-scoring row arrives with an intention rather than only a number.
What reaches the document is yours to choose. The executive summary, the risk matrix, top risks, the full register and per-risk detail pages are each a section toggle, and one scope switch decides whether closed and accepted risks are included. Every output is drawn from the same snapshot, so the PDF, the self-contained HTML file and the workbook always agree with one another.
Troubleshooting
Inherent and residual show the same number
Nothing is reducing the risk yet. Either no control is linked, or every linked control is still planned. Open Controls in the panel and check the status beside each one; if a control really is running, set it to operating and the residual answers immediately. A risk with no controls is worth knowing about, and an identical pair of numbers is how the register tells you.
The residual will not drop however strong the control is
Strength is not the lever until status is right. Check the control's status first, then its effectiveness, then whether the risk is linked to it rather than to a similar one. If the risk has effectiveness set by hand, the linked controls are not driving the number at all: switch the derive-from-controls toggle back on, or raise the hand-set value yourself.
A residual score changed and I did not touch that risk
Something it depends on moved. Editing a control's status or effectiveness re-scores every risk deriving from it, and so does changing whether controls reduce likelihood, impact or both. Open History on the risk: every assessment is recorded with the score it produced, so you can see when the number moved.
My target is higher than my residual
Then the risk has already arrived and the gap is closed. It happens legitimately: a control turned out stronger than expected, or the exposure was re-rated downwards at a review. Either lower the target to something that still represents an intention, or change the strategy to Accept and record why the current position is tolerable.
The whole register re-scored after an import
That is the intended behaviour when a control catalogue comes in. An import updates any control whose reference matches an existing one, and when that changes a control's status or effectiveness, every risk relying on it re-scores. The preview says line by line what will be created, updated or skipped, and nothing is written until you confirm.
Habits that keep the three honest
The three numbers stay useful for years if a few things are true of the way they are kept.
- Treat inherent as stable. Re-rate it when the exposure genuinely changes, not at every review. A drifting inherent score usually means controls are leaking into the rating.
- Never type a residual. Link the controls and let the arithmetic run. Where you set effectiveness by hand, write the reason into the risk.
- Give every High and Critical risk a target. Without one there is no gap, and without a gap there is nothing to hold a treatment plan to.
- Sort by residual, read the gap second. Residual ranks the register; the gap tells you which of those rows is actually being worked.
- Review with all three on screen. Review brings risks one at a time, worst first, with the scoring inputs beside the owner, actions and controls.
- Let reality challenge the ratings. When a risk materialises more often than its likelihood implies, the register says so and suggests what the observed frequency would justify.
Frequently asked questions
What is the difference between inherent and residual risk?
Inherent risk is the exposure with nothing standing in its way — the rating you would give if every safeguard were withdrawn. Residual risk is what remains once the controls you actually run have taken effect. You set the inherent rating yourself; RiskOS calculates the residual from the controls you link and shows how it reached the number.
What does target risk mean?
Target risk is where you have decided the risk should sit once the treatment plan has done its work. It is a commitment rather than a measurement, and it is the only one of the three scores that is about the future. Set it with the plan open beside you, so the number has a named control behind it.
Can residual risk be higher than inherent risk?
No. A residual score can never exceed the inherent score, because a control cannot leave a risk worse than it would have been untreated. It also never falls below 1, since no control takes a live risk to zero, and strengthening a control can only hold a score steady or bring it down.
How is residual risk calculated?
From the effectiveness of the controls linked to the risk, or from an effectiveness value you set by hand. Only controls that are implemented or operating count towards it. Whether that reduction applies to likelihood, impact or both is chosen once in Settings, and RiskOS always shows which control carried the reduction.
Should a board report show inherent or residual risk?
Lead with residual, because that is where the organisation stands today. Keep inherent beside it so the reduction your controls deliver is visible, and include the target so every high-scoring row comes with an intention. Top risks, the full register and per-risk detail pages are each a section toggle, so you decide how much of the assessment travels into the document.
What is the gap between residual and target for?
It is the amount of work the treatment plan has agreed to do, stated as a number. A large gap with a credible plan and a date is healthier than a small one nobody owns. Under the comparison grid, RiskOS names what strength of control would close the gap from the current position.
Does risk appetite apply to inherent or residual risk?
Residual. An appetite threshold is the highest residual score you are willing to tolerate, and any risk above it is flagged everywhere it appears. The threshold is resolved in order: an override on the risk itself, then the risk's category, then the organisation-wide setting, then none at all if none has been set.
Where are my risk scores stored?
On your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except when you export or back it up yourself. RiskOS keeps every assessment you have ever made, with the reason and the score it produced, so the reasoning behind all three numbers stays readable years later.