Inherent Risk
Inherent risk is the level of risk that comes naturally with a business activity or process before management takes any focused action to reduce it. It reflects how exposed an organization would be in the absence of controls or mitigating measures. It is often contrasted with residual risk, which is the risk that remains after controls are applied.
Inherent risk is the risk to an entity in the absence of any direct or focused actions by management to alter its severity, representing the natural risk associated with a business activity before consideration of the internal control environment. It is typically expressed as the magnitude of untreated risk an organization faces prior to the application of risk controls, and it serves as a baseline against which control effectiveness and residual risk are evaluated. Note that some practitioners characterize inherent risk relative to the existing set of controls rather than a strictly hypothetical absence of all controls, so the operative definition may vary by methodology and should be stated explicitly in a given risk assessment.
Why it matters
Inherent risk gives an organization a baseline understanding of its exposure before control efforts are credited. Without establishing this starting point, security and risk leaders have no meaningful way to demonstrate the value of controls or to measure how much risk they have actually reduced. Residual risk, the risk that remains after controls are applied, only becomes interpretable when it is compared against the inherent risk that preceded it.
Understanding inherent risk also helps organizations prioritize. Business activities and processes carry different natural levels of exposure, and treating every risk as equally urgent wastes limited resources. By identifying where inherent risk is highest, leadership can focus attention and investment on the areas where the potential for harm is greatest, rather than distributing effort evenly across risks of very different magnitudes.
One important caution is that the concept is not applied uniformly. Some practitioners define inherent risk as the risk that would exist in a strict hypothetical absence of all controls, while others, such as those aligned with the FAIR Institute's view, characterize it relative to the existing set of controls rather than a hypothetical no-control state. Because the operative definition changes the numbers and the conclusions drawn from them, any risk assessment should state explicitly which interpretation it is using.
Who it's relevant to
Inside Inherent Risk
Common questions
Answers to the questions practitioners most commonly ask about Inherent Risk.