Risk Strategy

Residual Risk: Your Target Is Not Your Current Exposure

A closed action does not prove lower exposure. Separate current residual risk from the target and ask what the control evidence actually covers.

By Eric Kennedy · Tue Oct 06 2026 · 8 min read

Residual Risk: Your Target Is Not Your Current Exposure

Residual risk is the exposure that remains after the controls operating today have been taken into account. A target residual-risk rating is different: it describes the position management intends to reach. Mixing the two makes a risk register look safer before the business has become safer.

For a CFO or audit leader reviewing an assessment, the practical question is: What evidence supports the credit we are giving this control, for this risk, as of this date?

A funded project, a written procedure and a completed training session may all be useful. None, by itself, establishes how much exposure remains. The assessment needs to explain what can still happen and why management believes the current response is sufficient.

Keep current exposure separate from the target

Use three distinct views. Inherent risk describes the scenario before the controls included in the assessment. State those assumptions explicitly. Current residual risk describes the exposure with the controls operating now. Target residual risk describes the intended future position after specified changes deliver their expected effect.

NIST's glossary distinguishes actual residual risk, which remains after management action, from target residual risk, the position the entity prefers to assume in pursuing its objectives. For an executive register, label the first one “current” if that makes the distinction easier to read.

Current and target may be the same. They should become the same because the evidence supports that conclusion, not because a mitigation deadline has arrived.

Three views of risk: inherent means before the controls assessed; current residual means with controls operating now; target residual means the intended future position. Planned controls belong in the target, not the current assessment.

The distinction matters even when the register uses words instead of numbers. Calling the current position “moderate” and the target “low” is acceptable only if the criteria behind those labels are understood. A color change is a judgment to explain, not proof of control effectiveness or a calculation of return on investment.

Define the failure before debating the rating

“Payment fraud” is too broad to assess a specific control. A more useful scenario identifies how money could leave the business, where the control is expected to intervene and which routes remain open.

For example, a fraudulent request to change a supplier's bank details may pass through vendor maintenance and payment approval before cash leaves the account. An invoice approval can confirm that goods were received while doing little to establish that new bank details belong to the supplier. Two approvals are not necessarily two independent checks of the relevant fact.

This is where the existing enterprise risk assessment process needs a tighter description, not a more elaborate scoring scale. Name the process, the exposed objective, the relevant period and the failure mechanism. Then assess the controls against that mechanism.

The UK Public Sector Fraud Authority's Full Fraud Risk Assessment Practice Note, published January 12, 2026, advises assessors to describe how fraud could still occur despite controls and to explain control limitations. It also separates controls already operating from planned or aspirational controls. This is guidance for UK public-sector fraud assessments, not a requirement imposed on private mid-market companies. Its discipline is useful here without treating it as a universal scoring method.

Ask what the evidence actually covers

Start with the evidence already available. A control description explains the intended activity. A configuration record may establish that a system rule is enabled. Transaction records, observation or a carefully designed test may show how the control operates. These answer different questions.

NIST's Risk Management Framework assessment step examines whether controls are implemented correctly, operating as intended and producing the desired outcome. Its scope is security and privacy controls. The broader management lesson is to avoid collapsing installation, operation and outcome into one “complete” status.

For each control receiving material credit in the assessment, record:

These are working questions, not a new certification standard. A small business process may need a short note and a few linked records. A material exposure with complex dependencies may need more testing and challenge.

An internal audit report can support the judgment, but its title alone does not establish coverage. Read its scope and date. An audit of invoice processing may exclude vendor-master changes. The existing assurance-mapping guide helps distinguish who reviewed a risk from what their work actually established.

A completed action can leave the risk unchanged

Consider this illustrative scenario, constructed to show the assessment decision rather than a KRG client result.

A Controller has introduced independent callback verification for supplier bank-detail changes. The action tracker says the procedure is complete. Routine changes now require a documented callback to a previously verified contact. However, the emergency-payment route still permits a change without that check, and nobody has tested that route since the procedure changed.

The risk owner wants to lower the residual rating because implementation is complete. The defensible response is narrower: the routine route has evidence of a new check; the emergency route remains unverified. The assessment should explain whether the exposed emergency route could still produce a material loss. It should not average that route away because most transactions follow the routine process.

Illustrative scenario: supplier bank-detail changes. Routine route has documented callbacks; emergency route permits a bypass and is untested. Decision: do not lower current residual risk on action closure alone. Test the bypass and reassess the remaining exposure.

The point is not that one exception automatically makes the entire control environment ineffective. A separate, reliable payment-release check might prevent the same loss. If management relies on that compensating control, identify it and examine its evidence. Do not count a second signature as protection against a failure it was never designed to detect.

What the register should say in this scenario

FieldIllustrative entry
Current exposureA fraudulent supplier bank-detail change could still reach an emergency payment without independent callback verification.
Evidence availableRoutine changes have documented callbacks. The changed emergency route has not been tested.
Current judgmentDo not lower current residual risk on action closure alone. Establish whether another operating control covers the bypass.
Target conditionVerification covers the emergency route, or another evidenced control addresses the same failure before payment release.
Next decisionThe Controller proposes an authorized interim response and tests the bypass. The risk owner reassesses the remaining exposure and escalates any acceptance decision beyond their authority.

This example contains no estimated fraud frequency, control-effectiveness percentage or expected loss. Those would need their own evidence. The scenario is enough to identify a decision without inventing a financial model.

Do not manufacture precision by subtracting scores

A likelihood score of four is not necessarily twice the probability represented by a score of two. If the scale merely ranks categories, multiplying or subtracting its labels does not turn them into financial quantities.

Use ordinal ratings to organize discussion if they help. Keep their criteria stable and explain the judgment. Do not present “inherent score minus control score” as measured residual exposure, or a reduction in heat-map score as cash saved.

Where a decision warrants financial analysis, work with a defined scenario: the cash or earnings consequence, a specified time horizon and explicit assumptions about probability, recovery and control performance. Distinguish the amount exposed in one event from expected loss across possible events. If the inputs are weak, show a range and the uncertainty instead of choosing a precise number that the evidence cannot support.

Nor does an absence of recent incidents settle the question. Management still needs to understand whether the relevant failure was possible, detectable and within the observation period. A quiet period may be reassuring; it does not validate every assumption in the register.

Keep the review proportionate to the decision

The fair objection is that management cannot commission a new audit every time it updates a risk rating. It should not have to.

Use existing operational evidence where it is relevant and credible. Give more scrutiny to controls that carry a large share of the risk-reduction claim, operate through exceptions or have changed since the last review. Explain uncertainty where further testing would cost more than the decision warrants.

You can also decide to carry an exposure. That is a management choice within delegated authority, not an assessment failure. The important distinction is between knowingly accepting an evidenced limitation and reporting an improvement that has not occurred. If the response remains overdue, use the existing risk-acceptance approach to document the decision, review date and escalation trigger.

For the next executive review, take a risk whose rating recently improved. Ask the owner to show the evidence, the boundary of that evidence and the route by which a material outcome could still occur. If that conversation changes the current rating, the review has done useful work.

Where the issue belongs with the board, the board-ready risk reporting resource provides a place to explain the remaining exposure and requested decision. Keep current and target separate so the committee can see what management has achieved and what still depends on future work.

If your register records action completion more clearly than the evidence behind current exposure, review how the wider program supports decisions. KRG's scorecard offers a starting point for that discussion.

Take the ERM Scorecard

Frequently Asked Questions

What is the difference between inherent and residual risk?

Inherent risk describes a scenario before the controls included in the assessment. Current residual risk describes what remains with controls operating now. State the assumptions and scope for both so the comparison has meaning.

How is current residual risk different from target residual risk?

Current residual risk reflects the controls and evidence available today. Target residual risk is the intended future position after specified changes deliver their expected effect. A planned control should not receive credit in the current assessment merely because it is approved or funded.

Can you calculate residual risk by subtracting a control score?

Subtracting ordinal rating labels does not measure remaining exposure. Use defined criteria and evidence to explain a qualitative judgment. If financial analysis is needed, specify the scenario, time horizon, probability assumptions and consequences rather than treating rating arithmetic as expected loss.