Residual Risk
The level of risk that remains after controls and risk responses have been applied.
Residual risk is the risk that remains after an organization has implemented controls and chosen its risk responses.
Not all risk can or should be eliminated. Some level of residual risk is tolerated based on impact, likelihood, and business priorities. Documenting residual risk makes these trade-offs explicit.
Risk registers often track both inherent risk (before controls) and residual risk (after controls) for key scenarios.