Inherent Risk Calculator
Score inherent risk before any control credit from threat, exposure and vulnerability against asset value, data sensitivity and regulatory reach.
Inputs
Inherent Risk Score
18.04of 25
Likelihood Component
4.10of 5
Impact Component
4.40of 5
Share of the Maximum Score
72.2%
Single Loss Expectancy
$875,000
Inherent Annualised Loss Expectancy
$1,312,500
Control Effectiveness Needed
67%
Inherent Risk Level
Critical — before any control credit
Treatment Note
Controls must remove roughly 67% of this exposure to land inside a typical medium appetite of 6 on the 25-point scale
Step by step
Values used
Threat actor capability and intent = 4 — Targeted criminal or competitor interest; Attack surface exposure = 5 — Internet-facing and anonymously reachable; Prevalence of known weaknesses in this technology = 3 — Supported but patched on a slow cycle; Asset replacement and revenue value = 2,500,000 $; Data sensitivity = 5 — Special category, payment or credential data; Regulatory and contractual exposure = 4 — Statutory regime with fining powers; Expected loss as a share of asset value if realised = 35 %; Annual rate of occurrence with no controls = 1.50 per year
Inherent Risk
Inherent risk = likelihood × impact, where likelihood = 0.40 × threat + 0.35 × exposure + 0.25 × vulnerability and impact = 0.40 × sensitivity + 0.25 × regulatory exposure + 0.35 × asset value band.
Monetary inherent risk
SLE = asset value × expected loss share; inherent ALE = SLE × uncontrolled annual rate of occurrence.
Inherent Risk Score
= 18.04 of 25
Likelihood Component
= 4.10 of 5
Impact Component
= 4.40 of 5
Share of the Maximum Score
= 72.2
Single Loss Expectancy
= 875,000
Inherent Annualised Loss Expectancy
= 1,312,500
How it works
Inherent risk deliberately ignores your controls: exposure is scored on where the asset sits, threat on who would want it, and vulnerability on how maintainable the technology is. The impact side leans hardest on data sensitivity because that is what drives both regulatory consequence and attacker motivation, and asset value enters as a band rather than a raw figure so a rounding error in the valuation cannot swing the score. You cannot demonstrate that a control is worth its cost without a credible before figure, and inherent risk is also what an auditor asks for when they want to know why a control exists at all. It is a management estimate, not a measured probability.
Formulas
Inherent Risk
Inherent risk = likelihood × impact, where likelihood = 0.40 × threat + 0.35 × exposure + 0.25 × vulnerability and impact = 0.40 × sensitivity + 0.25 × regulatory exposure + 0.35 × asset value band.
- likelihood
- Weighted 1–5 likelihood before controls
- impactScore
- Weighted 1–5 impact before controls
- valueScore
- Asset value mapped to a 1–5 band on decade boundaries
Monetary inherent risk
SLE = asset value × expected loss share; inherent ALE = SLE × uncontrolled annual rate of occurrence.
- SLE
- Single loss expectancy — the cost of one occurrence
- ARO
- Annual rate of occurrence assuming no controls are in place
Frequently Asked Questions
How is Inherent Risk calculated?
Inherent risk = likelihood × impact, where likelihood = 0.40 × threat + 0.35 × exposure + 0.25 × vulnerability and impact = 0.40 × sensitivity + 0.25 × regulatory exposure + 0.35 × asset value band. Inherent risk deliberately ignores your controls: exposure is scored on where the asset sits, threat on who would want it, and vulnerability on how maintainable the technology is. The impact side leans hardest on data sensitivity because that is what drives both regulatory consequence and attacker motivation, and asset value enters as a band rather than a raw figure so a rounding error in the valuation cannot swing the score.
Why does Inherent Risk matter?
You cannot demonstrate that a control is worth its cost without a credible before figure, and inherent risk is also what an auditor asks for when they want to know why a control exists at all. It is a management estimate, not a measured probability.
What values do I need to enter?
This calculator takes 8 inputs: Threat actor capability and intent, Attack surface exposure, Prevalence of known weaknesses in this technology, Asset replacement and revenue value, Data sensitivity, Regulatory and contractual exposure, Expected loss as a share of asset value if realised, Annual rate of occurrence with no controls. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is inherent risk a real thing if controls already exist?
It is a modelling convention: risk as it would be if the controls were removed. Some frameworks skip it and score current risk directly, which is defensible but makes it impossible to show what the control estate is buying you. Where inherent risk gets abused is when it is inflated to make a control programme look successful.
Why band the asset value instead of using it directly?
Because valuations are rough and a 5×5 matrix cannot carry that precision. Decade bands keep the score stable when someone revises the number from £900k to £1.1m, and the monetary ALE output is there for when you do want the currency figure.
You might also need
- Residual Risk CalculatorCommonly used together
- Risk Heatmap CalculatorCommonly used together
- Enterprise Risk Score CalculatorCommonly used together
- Security Investment ROI CalculatorAlso in Compliance & GRC
- Risk Appetite CalculatorAlso in Compliance & GRC
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC