ISO/IEC 27005:2022 describes inherent risk as the level of risk without considering any controls, current risk as the level allowing for controls already implemented, and residual risk as risk remaining after treatment. State which basis each rating uses.
The standard supplies guidance rather than a mandatory scoring model, legal rule, or standalone certification scheme.
Use only when a no-controls baseline helps the decision. ISO/IEC 27005:2022 says organizations can consider inherent risk or when determining risk levels, and notes that information security methods most commonly assess current risk. is what remains after treatment and is the basis for the risk owner's acceptance decision.
Side-by-side comparison
Inherent vs residual risk: define the baseline before comparing
ISO/IEC 27005 describes an inherent level without controls, a current level that credits effective existing controls, and after treatment. Compare them only when the scenario, criteria, units, time horizon, and control assumptions are explicit.
The level of risk without considering any controls. Use this no-controls baseline only when it helps the decision and the hypothetical assumptions can be explained.
Second framework
Residual Risk
Risk remaining after treatment. Determine it through a follow-up assessment that considers proposed or implemented controls and their effectiveness.
Inherent vs residual risk: define the baseline before comparing
Describe the scenario, no-controls assumptions, consequence, likelihood, method, and rationale. ISO/IEC 27005 recommends considering inherent or depending on the situation.
Evidence should show the approved treatment, controls credited, expected or tested effectiveness, follow-up assessment, acceptance decision, conditions, and review date.
Residual-risk evidence supports ISO/IEC 27001 treatment and acceptance decisions, but ISO/IEC 27005 is guidance rather than a standalone certification standard.
Describe the scenario, no-controls assumptions, consequence, likelihood, method, and rationale. ISO/IEC 27005 recommends considering inherent or depending on the situation.
Evidence should show the approved treatment, controls credited, expected or tested effectiveness, follow-up assessment, acceptance decision, conditions, and review date.
Residual-risk evidence supports ISO/IEC 27001 treatment and acceptance decisions, but ISO/IEC 27005 is guidance rather than a standalone certification standard.
How should teams distinguish inherent risk from residual risk under ISO/IEC 27005?
ISO/IEC 27005:2022 describes as the level without considering any controls and as the level allowing for the effectiveness of controls already implemented. It defines as risk remaining after treatment. These are different assessment bases, so label the basis and control assumptions on every rating.
A no-controls inherent baseline can be useful for prioritization or comparing gross exposure, but it can be unrealistic for a process that has never operated without embedded controls. is often the more decision-useful starting point for information security treatment. After selecting or implementing treatment, reassess likelihood and consequence with the proposed controls and their effectiveness to determine .
Use the same scenario, scope, time horizon, consequence and likelihood criteria, and units when comparing stages.
List the controls excluded from , credited in , and proposed or implemented for .
Do not claim risk reduction from a control merely because it exists; consider whether it is necessary, implemented, operating, and effective.
Example: an inherent assessment of laptop data disclosure excludes disk encryption and access controls. The current assessment credits only controls operating now. A planned encryption deployment supports an expected residual estimate; implementation and effectiveness evidence are needed before treating that estimate as verified.
What is the difference between and in ISO/IEC 27005?
is the level assessed without considering any controls. is what remains after treatment. Between them, is today's exposure after crediting the effectiveness of controls already implemented. Keep the scenario, time horizon, criteria, and units constant and label which controls are excluded, credited, proposed, or verified.
Does ISO/IEC 27005 require an inherent-risk assessment?
No. ISO/IEC 27005:2022 recommends considering or depending on the situation and says information security methods most commonly use current risk. Use a no-controls baseline only when it supports the decision and its hypothetical assumptions can be explained.
Can planned controls be used to report ?
Planned controls can support an expected residual-risk estimate for treatment planning. They do not support a verified post-treatment rating until the controls are implemented and evidence shows how effectively they modify likelihood or consequence. Label the estimate accordingly and perform the follow-up assessment.
Who accepts ?
The risk owner decides whether is acceptable under the organization's approved acceptance criteria and delegated authority. If the remaining risk exceeds that authority or normal criteria, the decision should be escalated or explicitly justified and approved as the authority model requires.
ISO/IEC 27005:2022 Clauses 6.4.3.4 and 6.5 distinguish inherent and current risk; the residual-risk definition and Clause 8.6.3 explain risk remaining after treatment.
Question 2
What evidence should support the inherent vs residual risk decision?
Keep the scenario, scope, criteria, time horizon, consequence and likelihood evidence, rating basis, included and excluded controls, , uncertainty, owner, date, and rationale together. For , add the approved treatment plan, follow-up assessment, acceptance decision, conditions, and review trigger.
For an inherent rating, explain how the no-controls state was estimated and where it is hypothetical.
For a current rating, identify existing controls and evidence of their actual effectiveness.
For a residual rating, distinguish proposed effectiveness from verified effectiveness and update the rating after implementation testing.
ISO/IEC 27005:2022 Clauses 6.5, 8.3, and 8.6.3 support documented methods, evidence-based control credit, and follow-up assessment of residual likelihood and consequence.
Recommended next step
Document each risk basis
Define owner, evidence requirements, evidence requests, and the next review date before approval.
Who owns and approves inherent vs residual risk decisions?
Keep one accountable risk owner for the same risk across its inherent, current, and residual views unless the risk itself moves to a different organizational owner. Analysts can calculate the ratings and treatment owners can implement controls, but the risk owner approves the plan and decides whether is acceptable.
Name the method owner who defines the rating convention and the risk owner who makes the decision.
Assign control implementation and effectiveness evidence to treatment and control owners.
Escalate residual-risk acceptance when it exceeds the risk owner's delegated threshold or class.
ISO/IEC 27005:2022 Clauses 7.2.2 and 8.6 assign risk management, treatment-plan approval, and residual-risk acceptance to accountable risk owners.
Question 4
When should inherent vs residual risk be reviewed?
Reassess the relevant view when the scenario, criteria, evidence, controls, or treatment changes. changes when the underlying no-controls scenario changes; changes when the operating environment or existing- changes; changes as treatment is implemented, tested, changed, or fails.
Review after incidents, material changes, new threats or vulnerabilities, unexpected control tests, treatment delays, or changed acceptance criteria.
Do not carry a planned residual rating forward as though it were verified after implementation.
Record the previous basis, changed controls or evidence, new rating, and new acceptance or treatment decision.
ISO/IEC 27005:2022 Clauses 5.2, 8.6.3, and 10.8 support follow-up assessment and regular and change-driven review of risk, controls, treatment, and criteria.
Official listing for ISO/IEC 27001:2022, whose risk-treatment requirements include risk-owner approval and acceptance of residual information security risks.
"Information security management systems — Requirements"
ISO/IEC 27005:2022 Clauses 6.4.3.4, 6.5, and 8.6.3 support the choice of inherent or current risk, documented methods, and follow-up assessment and acceptance of residual risk.