Residual Risk Calculator
Calculate residual risk from inherent risk and control effectiveness, the risk that remains after mitigating controls are applied.
Last reviewed by the Radiatus Cloud team
Calculate the residual risk remaining after controls are applied.
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Calculate residual risk
Residual risk is the level of risk that remains after controls have been put in place to reduce the original, or inherent, risk. This calculator computes it by reducing the inherent risk score in proportion to how effective the controls are. If an inherent risk scores sixteen and the controls are sixty percent effective, they remove about ten points, leaving a residual risk of around six. The more effective the controls, the lower the residual risk.
This simple model treats control effectiveness as the percentage reduction it achieves against the inherent risk.
Managing residual risk
No set of controls eliminates risk entirely, so understanding what remains is central to risk management and compliance frameworks. Comparing residual risk against your risk appetite shows whether further controls are needed or whether the remaining risk can be accepted. Documenting inherent risk, the controls, their effectiveness and the resulting residual risk is a common requirement in risk registers and audits.
Estimating control effectiveness is a judgement, often informed by testing, so revisit it as controls mature or threats change. All calculation happens locally in your browser.
Important note
Because the residual risk calculator runs entirely in your browser, nothing you enter is uploaded, so you can use it with your own details safely. The output is a general template or estimate, not legal advice, so review it carefully and have it checked by a qualified professional before relying on it.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
What is residual risk?
It is the risk that remains after mitigating controls are applied, in contrast to inherent risk, which is the risk before any controls.
How is it calculated here?
The inherent risk score is reduced in proportion to the control effectiveness, so sixty percent effective controls leave forty percent of the inherent risk.
Why does residual risk matter?
Comparing it against your risk appetite shows whether further controls are needed or the remaining risk can be formally accepted.
How do I estimate control effectiveness?
It is a judgement, ideally informed by control testing and evidence, and should be revisited as controls mature or the threat landscape changes.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter the inherent risk score and the control effectiveness.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.