Side-by-sideGlobalISO/IEC 27005

ISO/IEC 27005 FAQ Inherent vs Residual Risk

ISO/IEC 27005:2022 describes inherent risk as the level of risk without considering any controls, current risk as the level allowing for controls already implemented, and residual risk as risk remaining after treatment. State which basis each rating uses.

The standard supplies guidance rather than a mandatory scoring model, legal rule, or standalone certification scheme.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use only when a no-controls baseline helps the decision. ISO/IEC 27005:2022 says organizations can consider inherent risk or when determining risk levels, and notes that information security methods most commonly assess current risk. is what remains after treatment and is the basis for the risk owner's acceptance decision.

Side-by-side comparison

Inherent vs residual risk: define the baseline before comparing

ISO/IEC 27005 describes an inherent level without controls, a current level that credits effective existing controls, and after treatment. Compare them only when the scenario, criteria, units, time horizon, and control assumptions are explicit.

Review all sources
First framework
Inherent

The level of risk without considering any controls. Use this no-controls baseline only when it helps the decision and the hypothetical assumptions can be explained.

Second framework
Residual Risk

Risk remaining after treatment. Determine it through a follow-up assessment that considers proposed or implemented controls and their effectiveness.

Comparison row 1

Scope and covered activity

Inherent

Assess the defined scenario without crediting any controls. State where this is a hypothetical condition because the activity has embedded controls.

Residual Risk

Assess the same scenario after the relevant treatment, proposed controls, and expected or verified effectiveness are considered.

Operational implication

Use for a no-controls comparison when useful. Use for today's operating exposure and for the remaining exposure after treatment.

Comparison row 2

Who must act

Inherent

The method owner defines the no-controls convention; analysts apply it; the risk owner confirms that the comparison supports the decision.

Residual Risk

The same accountable risk owner approves treatment and accepts or escalates the remaining exposure under authorized criteria.

Operational implication

Keep ownership of the same risk consistent across stages. Separate the risk owner from analysts, treatment owners, and control owners.

Comparison row 3

Trigger or threshold

Inherent

Use an inherent baseline when the approved method needs a no-controls comparison for prioritization, design, or reporting.

Residual Risk

Assess after a treatment decision or control change to determine what remains and whether further treatment is required.

Operational implication

Assess for today's treatment decision and for acceptance after treatment. An inherent baseline does not replace either assessment.

Comparison row 4

Core obligations

Inherent

Describe the scenario, no-controls assumptions, consequence, likelihood, method, and rationale. ISO/IEC 27005 recommends considering inherent or depending on the situation.

Residual Risk

Consider treatment and , reassess likelihood and consequence, compare the result with acceptance criteria, and record acceptance or further treatment.

Operational implication

Treat inherent, current, and residual ratings as labeled views of one risk workflow, not interchangeable scores.

Comparison row 5

Evidence and records

Inherent

Evidence should show the scenario, no-controls assumptions, threat and vulnerability inputs, time horizon, likelihood, consequence, and uncertainty.

Residual Risk

Evidence should show the approved treatment, controls credited, expected or tested effectiveness, follow-up assessment, acceptance decision, conditions, and review date.

Operational implication

A planned control supports an expected residual estimate. Only implementation and effectiveness evidence can support a verified post-treatment rating.

Comparison row 6

Timing and cadence

Inherent

Review when the underlying no-controls scenario, scope, objectives, criteria, or time horizon changes.

Residual Risk

Review as treatment progresses, after control tests or incidents, and at scheduled or event-driven acceptance reviews.

Operational implication

Set separate triggers for the underlying scenario, current control operation, treatment progress, and residual-risk acceptance.

Comparison row 7

Assurance limits

Inherent

An inherent-risk rating is one method option under ISO/IEC 27005, not proof of certification, compliance, or .

Residual Risk

Residual-risk evidence supports ISO/IEC 27001 treatment and acceptance decisions, but ISO/IEC 27005 is guidance rather than a standalone certification standard.

Operational implication

Use the approved criteria and authority model for decisions; neither rating creates legal permission to retain a risk.

Comparison row 8

Overlap and reuse

Inherent

can supply the scenario, threats, vulnerabilities, likelihood, consequence, and assumptions for later analysis.

Residual Risk

can reuse unchanged scenario facts but must add treatment, controls, effectiveness, and current evidence.

Operational implication

Preserve the baseline and version later assessments so reviewers can see which facts and controls changed.

Comparison row 9

Practical decision rule

Inherent

Use when a no-controls view improves prioritization and its assumptions can be supported.

Residual Risk

Use to determine whether treatment is sufficient and whether the remaining exposure can be accepted.

Operational implication

If the no-controls state is too artificial to support, assess instead and document the effective existing controls.

Practical decision rule

When should teams use inherent and residual risk?

  • Define inherent, current, and and their control assumptions in the approved method.
  • Use the same scenario, time horizon, units, and criteria when comparing stages.
  • Record whether residual is expected or verified before the risk owner decides on acceptance.
Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How should teams distinguish inherent risk from residual risk under ISO/IEC 27005?

ISO/IEC 27005:2022 describes as the level without considering any controls and as the level allowing for the effectiveness of controls already implemented. It defines as risk remaining after treatment. These are different assessment bases, so label the basis and control assumptions on every rating.

A no-controls inherent baseline can be useful for prioritization or comparing gross exposure, but it can be unrealistic for a process that has never operated without embedded controls. is often the more decision-useful starting point for information security treatment. After selecting or implementing treatment, reassess likelihood and consequence with the proposed controls and their effectiveness to determine .

  • Use the same scenario, scope, time horizon, consequence and likelihood criteria, and units when comparing stages.
  • List the controls excluded from , credited in , and proposed or implemented for .
  • Do not claim risk reduction from a control merely because it exists; consider whether it is necessary, implemented, operating, and effective.
  • Example: an inherent assessment of laptop data disclosure excludes disk encryption and access controls. The current assessment credits only controls operating now. A planned encryption deployment supports an expected residual estimate; implementation and effectiveness evidence are needed before treating that estimate as verified.

What is the difference between and in ISO/IEC 27005?

is the level assessed without considering any controls. is what remains after treatment. Between them, is today's exposure after crediting the effectiveness of controls already implemented. Keep the scenario, time horizon, criteria, and units constant and label which controls are excluded, credited, proposed, or verified.

Does ISO/IEC 27005 require an inherent-risk assessment?

No. ISO/IEC 27005:2022 recommends considering or depending on the situation and says information security methods most commonly use current risk. Use a no-controls baseline only when it supports the decision and its hypothetical assumptions can be explained.

Can planned controls be used to report ?

Planned controls can support an expected residual-risk estimate for treatment planning. They do not support a verified post-treatment rating until the controls are implemented and evidence shows how effectively they modify likelihood or consequence. Label the estimate accordingly and perform the follow-up assessment.

Who accepts ?

The risk owner decides whether is acceptable under the organization's approved acceptance criteria and delegated authority. If the remaining risk exceeds that authority or normal criteria, the decision should be escalated or explicitly justified and approved as the authority model requires.

Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 6.4.3.4 and 6.5 distinguish inherent and current risk; the residual-risk definition and Clause 8.6.3 explain risk remaining after treatment.

Question 2

What evidence should support the inherent vs residual risk decision?

Keep the scenario, scope, criteria, time horizon, consequence and likelihood evidence, rating basis, included and excluded controls, , uncertainty, owner, date, and rationale together. For , add the approved treatment plan, follow-up assessment, acceptance decision, conditions, and review trigger.

  • For an inherent rating, explain how the no-controls state was estimated and where it is hypothetical.
  • For a current rating, identify existing controls and evidence of their actual effectiveness.
  • For a residual rating, distinguish proposed effectiveness from verified effectiveness and update the rating after implementation testing.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 6.5, 8.3, and 8.6.3 support documented methods, evidence-based control credit, and follow-up assessment of residual likelihood and consequence.

Question 3

Who owns and approves inherent vs residual risk decisions?

Keep one accountable risk owner for the same risk across its inherent, current, and residual views unless the risk itself moves to a different organizational owner. Analysts can calculate the ratings and treatment owners can implement controls, but the risk owner approves the plan and decides whether is acceptable.

  • Name the method owner who defines the rating convention and the risk owner who makes the decision.
  • Assign control implementation and effectiveness evidence to treatment and control owners.
  • Escalate residual-risk acceptance when it exceeds the risk owner's delegated threshold or class.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 7.2.2 and 8.6 assign risk management, treatment-plan approval, and residual-risk acceptance to accountable risk owners.

Question 4

When should inherent vs residual risk be reviewed?

Reassess the relevant view when the scenario, criteria, evidence, controls, or treatment changes. changes when the underlying no-controls scenario changes; changes when the operating environment or existing- changes; changes as treatment is implemented, tested, changed, or fails.

  • Review after incidents, material changes, new threats or vulnerabilities, unexpected control tests, treatment delays, or changed acceptance criteria.
  • Do not carry a planned residual rating forward as though it were verified after implementation.
  • Record the previous basis, changed controls or evidence, new rating, and new acceptance or treatment decision.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 5.2, 8.6.3, and 10.8 support follow-up assessment and regular and change-driven review of risk, controls, treatment, and criteria.

Primary sources

References and citations

iso.org
Referenced sections
  • Official listing for ISO/IEC 27001:2022, whose risk-treatment requirements include risk-owner approval and acceptance of residual information security risks.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 Clauses 6.4.3.4, 6.5, and 8.6.3 support the choice of inherent or current risk, documented methods, and follow-up assessment and acceptance of residual risk.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.