Residual risk should be recalculated when new evidence changes what your team knows about a control. A completed test may support a lower likelihood rating. A failed exercise, missing supplier evidence, or incomplete remediation may justify a higher one.
There is no universal residual risk calculation. These hypothetical examples use a simple likelihood and impact model to show the reasoning. They are not customer records, recommended thresholds, or benchmarks.
In short
NIST defines residual risk as risk remaining after controls or risk responses are applied. The practical question is how much those controls change the original exposure.
The examples use this model:
Residual risk score = reassessed likelihood × reassessed impact
Likelihood and impact are each scored from 1 to 5. Use the same scenario and scale for the inherent and residual assessments. Your organization must define its rating bands, tolerance levels, and approval authority.
This is an illustration, not a standard formula. NIST SP 800-30 Rev. 1, published in September 2012, discusses likelihood, impact, and uncertainty but does not require this multiplication model. For more background, read the BCMMetrics guide to residual risk meaning and calculation.
Evidence is not a number to subtract from inherent risk. It tells you how much confidence you can place in the control when you reassess likelihood and impact.
The numbers illustrate the logic. Do not copy them into a risk register without the organization’s approved definitions and criteria.
Scenario: A payment platform becomes unavailable during a daily settlement window.
Inherent risk: Likelihood 5 × impact 5 = 25.
Evidence: A recent failover test restored processing within the required time. The test covered the internal platform and external settlement connection.
Residual risk: Likelihood 2 × impact 5 = 10.
Why it changed: The test supports a lower likelihood of prolonged interruption. Missing the settlement window would still have a severe impact.
Scenario: A critical application must be recovered within four hours.
Previous residual risk: Likelihood 2 × impact 5 = 10, based on a documented procedure and assumed four-hour capability.
New evidence: The latest test took seven hours. Data validation added two hours that were not included in the procedure.
Revised residual risk: Likelihood 3 × impact 5 = 15.
Why it changed: The test contradicts the earlier likelihood assumption. The business impact has not changed.
Scenario: A single-source supplier is disrupted for more than ten business days.
Inherent risk: Likelihood 4 × impact 4 = 16.
Claimed control: The supplier says it can move production to another facility.
Evidence: The contract mentions alternate production, but there is no current capacity confirmation, test result, or recovery commitment for the required volume.
Residual risk: Likelihood 4 × impact 4 = 16.
Why it did not change: The control may exist, but the evidence does not support reducing likelihood or impact. The next step is to obtain evidence, not assume success or failure.
Scenario: An electronic health-record outage disrupts clinical workflows.
Previous residual risk: Likelihood 2 × impact 4 = 8, based on documented downtime procedures and completed training.
Evidence: An exercise found that two outpatient departments could not access current forms or reconcile records after restoration.
Revised residual risk: Likelihood 3 × impact 4 = 12.
Why it changed: The control did not operate consistently across the defined scope. Reassess after the forms, training, and reconciliation steps are corrected and tested.
Scenario: The BCM program cannot show current approval and exercise evidence for all critical plans.
Inherent risk: Likelihood 4 × impact 3 = 12.
Evidence: A new review process is documented, and 70 percent of critical plans have current approvals. Exercise evidence is complete for half of those plans.
Residual risk: Likelihood 3 × impact 3 = 9.
Why it changed: Completed approvals support some reduction, but implementation and exercise evidence remain incomplete. Reassess after the remaining work is verified.
A recalculated score without its reasoning is difficult to defend. Keep this information with each reassessment:
The rating and the decision remain separate. Residual risk describes the exposure after controls. Acceptance is the authorized decision to retain that exposure. MHA Consulting’s guide to risk acceptance versus residual risk addresses that governance decision in more depth.
For the audit record behind the calculation, see Residual Risk Documentation for Audit.
A spreadsheet can hold two scores and a formula. The harder job is keeping evidence, actions, and assessment history connected as conditions change.
BCMMetrics Compliance Confidence supports standards-based assessments, supporting documents, assigned actions, assessment history, and reporting. It does not decide how much risk the organization should accept. It gives the team a more consistent place to maintain the information behind that decision.
It estimates the exposure remaining after current controls are considered. One illustrative method reassesses likelihood and impact, then multiplies the scores. Organizations still need their own definitions and criteria.
No. Missing evidence creates uncertainty. Give the control only the credit that can be supported, then obtain current evidence through testing, document review, or supplier validation.
Recalculate it when new evidence could change the assumptions behind the rating. Common triggers include tests, exercises, incidents, control changes, overdue actions, supplier changes, new requirements, and material changes to the affected process or technology.