Prepare For the Worst with the Best in the Business
Experience capable, consistent, and easy-to-use business continuity management software.
Residual risk should be recalculated when new evidence changes what your team knows about a control. A completed test may support a lower likelihood rating. A failed exercise, missing supplier evidence, or incomplete remediation may justify a higher one.
There is no universal residual risk calculation. These hypothetical examples use a simple likelihood and impact model to show the reasoning. They are not customer records, recommended thresholds, or benchmarks.
In short
- Reassess the same disruption scenario before and after current controls.
- Give each control only the credit its evidence can support.
- Explain whether the control changes likelihood, impact, duration, or the team’s confidence in the rating.
- Record the evidence, rationale, decision, owner, and next review trigger.
Use Evidence to Reassess Likelihood and Impact
NIST defines residual risk as risk remaining after controls or risk responses are applied. The practical question is how much those controls change the original exposure.
An Illustrative Calculation Method
The examples use this model:
Residual risk score = reassessed likelihood × reassessed impact
Likelihood and impact are each scored from 1 to 5. Use the same scenario and scale for the inherent and residual assessments. Your organization must define its rating bands, tolerance levels, and approval authority.
This is an illustration, not a standard formula. NIST SP 800-30 Rev. 1, published in September 2012, discusses likelihood, impact, and uncertainty but does not require this multiplication model. For more background, read the BCMMetrics guide to residual risk meaning and calculation.
How Much Credit Should a Control Receive?
Evidence is not a number to subtract from inherent risk. It tells you how much confidence you can place in the control when you reassess likelihood and impact.
- Current test evidence: Credit the control for the part of the scenario it covered.
- Partial evidence: Keep uncovered processes, locations, periods, and dependencies visible.
- Outdated evidence: Consider what changed before carrying the old rating forward.
- Contradictory evidence: A failure or missed objective should change the assumptions behind the rating.
- No retrievable evidence: Do not assume failure, but do not credit the control as though it were demonstrated.
Five Residual Risk Calculation Examples
The numbers illustrate the logic. Do not copy them into a risk register without the organization’s approved definitions and criteria.
1. A Control That Works but Does Not Remove the Impact
Scenario: A payment platform becomes unavailable during a daily settlement window.
Inherent risk: Likelihood 5 × impact 5 = 25.
Evidence: A recent failover test restored processing within the required time. The test covered the internal platform and external settlement connection.
Residual risk: Likelihood 2 × impact 5 = 10.
Why it changed: The test supports a lower likelihood of prolonged interruption. Missing the settlement window would still have a severe impact.
2. A Recovery Test That Exposes a Capability Gap
Scenario: A critical application must be recovered within four hours.
Previous residual risk: Likelihood 2 × impact 5 = 10, based on a documented procedure and assumed four-hour capability.
New evidence: The latest test took seven hours. Data validation added two hours that were not included in the procedure.
Revised residual risk: Likelihood 3 × impact 5 = 15.
Why it changed: The test contradicts the earlier likelihood assumption. The business impact has not changed.
3. A Third-Party Control Without Sufficient Evidence
Scenario: A single-source supplier is disrupted for more than ten business days.
Inherent risk: Likelihood 4 × impact 4 = 16.
Claimed control: The supplier says it can move production to another facility.
Evidence: The contract mentions alternate production, but there is no current capacity confirmation, test result, or recovery commitment for the required volume.
Residual risk: Likelihood 4 × impact 4 = 16.
Why it did not change: The control may exist, but the evidence does not support reducing likelihood or impact. The next step is to obtain evidence, not assume success or failure.
4. An Exercise Finding That Changes the Rating
Scenario: An electronic health-record outage disrupts clinical workflows.
Previous residual risk: Likelihood 2 × impact 4 = 8, based on documented downtime procedures and completed training.
Evidence: An exercise found that two outpatient departments could not access current forms or reconcile records after restoration.
Revised residual risk: Likelihood 3 × impact 4 = 12.
Why it changed: The control did not operate consistently across the defined scope. Reassess after the forms, training, and reconciliation steps are corrected and tested.
5. A Compliance Gap With Partial Remediation
Scenario: The BCM program cannot show current approval and exercise evidence for all critical plans.
Inherent risk: Likelihood 4 × impact 3 = 12.
Evidence: A new review process is documented, and 70 percent of critical plans have current approvals. Exercise evidence is complete for half of those plans.
Residual risk: Likelihood 3 × impact 3 = 9.
Why it changed: Completed approvals support some reduction, but implementation and exercise evidence remain incomplete. Reassess after the remaining work is verified.
Document Why the Rating Changed
A recalculated score without its reasoning is difficult to defend. Keep this information with each reassessment:
- The exact scenario and the likelihood and impact definitions used
- The previous rating and date
- The control being credited
- The evidence reviewed, including its date and scope
- The new likelihood and impact ratings
- A short explanation of what changed and what did not
- The treatment or acceptance decision
- The owner, approver, open action, and next review trigger
The rating and the decision remain separate. Residual risk describes the exposure after controls. Acceptance is the authorized decision to retain that exposure. MHA Consulting’s guide to risk acceptance versus residual risk addresses that governance decision in more depth.
For the audit record behind the calculation, see Residual Risk Documentation for Audit.
Keep the Assessment and Evidence Connected
A spreadsheet can hold two scores and a formula. The harder job is keeping evidence, actions, and assessment history connected as conditions change.
BCMMetrics Compliance Confidence supports standards-based assessments, supporting documents, assigned actions, assessment history, and reporting. It does not decide how much risk the organization should accept. It gives the team a more consistent place to maintain the information behind that decision.
Frequently Asked Questions
What is a residual risk calculation?
It estimates the exposure remaining after current controls are considered. One illustrative method reassesses likelihood and impact, then multiplies the scores. Organizations still need their own definitions and criteria.
Does missing evidence automatically mean a control is ineffective?
No. Missing evidence creates uncertainty. Give the control only the credit that can be supported, then obtain current evidence through testing, document review, or supplier validation.
When should residual risk be recalculated?
Recalculate it when new evidence could change the assumptions behind the rating. Common triggers include tests, exercises, incidents, control changes, overdue actions, supplier changes, new requirements, and material changes to the affected process or technology.
Michael Herrera
Michael Herrera is the Chief Executive Officer (CEO) of MHA. In his role, Michael provides global leadership to the entire set of industry practices and horizontal capabilities within MHA. Under his leadership, MHA has become a leading provider of Business Continuity and Disaster Recovery services to organizations on a global level. He is also the founder of BCMMETRICS, a leading cloud based tool designed to assess business continuity compliance and residual risk. Michael is a well-known and sought after speaker on Business Continuity issues at local and national contingency planner chapter meetings and conferences. Prior to founding MHA, he was a Regional VP for Bank of America, where he was responsible for Business Continuity across the southwest region.