Skip to content
Calcrivo

Inherent Risk Calculator

Score inherent risk before any control credit from threat, exposure and vulnerability against asset value, data sensitivity and regulatory reach.

Inputs

$
%
per year

Inherent Risk Score

18.04of 25

Likelihood Component

4.10of 5

Impact Component

4.40of 5

Share of the Maximum Score

72.2%

Single Loss Expectancy

$875,000

Inherent Annualised Loss Expectancy

$1,312,500

Control Effectiveness Needed

67%

Inherent Risk Level

Critical — before any control credit

Treatment Note

Controls must remove roughly 67% of this exposure to land inside a typical medium appetite of 6 on the 25-point scale

Step by step

  1. Values used

    Threat actor capability and intent = 4 — Targeted criminal or competitor interest; Attack surface exposure = 5 — Internet-facing and anonymously reachable; Prevalence of known weaknesses in this technology = 3 — Supported but patched on a slow cycle; Asset replacement and revenue value = 2,500,000 $; Data sensitivity = 5 — Special category, payment or credential data; Regulatory and contractual exposure = 4 — Statutory regime with fining powers; Expected loss as a share of asset value if realised = 35 %; Annual rate of occurrence with no controls = 1.50 per year

  2. Inherent Risk

    Inherent risk = likelihood × impact, where likelihood = 0.40 × threat + 0.35 × exposure + 0.25 × vulnerability and impact = 0.40 × sensitivity + 0.25 × regulatory exposure + 0.35 × asset value band.

  3. Monetary inherent risk

    SLE = asset value × expected loss share; inherent ALE = SLE × uncontrolled annual rate of occurrence.

  4. Inherent Risk Score

    = 18.04 of 25

  5. Likelihood Component

    = 4.10 of 5

  6. Impact Component

    = 4.40 of 5

  7. Share of the Maximum Score

    = 72.2

  8. Single Loss Expectancy

    = 875,000

  9. Inherent Annualised Loss Expectancy

    = 1,312,500

How it works

Inherent risk deliberately ignores your controls: exposure is scored on where the asset sits, threat on who would want it, and vulnerability on how maintainable the technology is. The impact side leans hardest on data sensitivity because that is what drives both regulatory consequence and attacker motivation, and asset value enters as a band rather than a raw figure so a rounding error in the valuation cannot swing the score. You cannot demonstrate that a control is worth its cost without a credible before figure, and inherent risk is also what an auditor asks for when they want to know why a control exists at all. It is a management estimate, not a measured probability.

Formulas

Inherent Risk

Inherent risk = likelihood × impact, where likelihood = 0.40 × threat + 0.35 × exposure + 0.25 × vulnerability and impact = 0.40 × sensitivity + 0.25 × regulatory exposure + 0.35 × asset value band.

likelihood
Weighted 1–5 likelihood before controls
impactScore
Weighted 1–5 impact before controls
valueScore
Asset value mapped to a 1–5 band on decade boundaries

Monetary inherent risk

SLE = asset value × expected loss share; inherent ALE = SLE × uncontrolled annual rate of occurrence.

SLE
Single loss expectancy — the cost of one occurrence
ARO
Annual rate of occurrence assuming no controls are in place

Frequently Asked Questions

How is Inherent Risk calculated?

Inherent risk = likelihood × impact, where likelihood = 0.40 × threat + 0.35 × exposure + 0.25 × vulnerability and impact = 0.40 × sensitivity + 0.25 × regulatory exposure + 0.35 × asset value band. Inherent risk deliberately ignores your controls: exposure is scored on where the asset sits, threat on who would want it, and vulnerability on how maintainable the technology is. The impact side leans hardest on data sensitivity because that is what drives both regulatory consequence and attacker motivation, and asset value enters as a band rather than a raw figure so a rounding error in the valuation cannot swing the score.

Why does Inherent Risk matter?

You cannot demonstrate that a control is worth its cost without a credible before figure, and inherent risk is also what an auditor asks for when they want to know why a control exists at all. It is a management estimate, not a measured probability.

What values do I need to enter?

This calculator takes 8 inputs: Threat actor capability and intent, Attack surface exposure, Prevalence of known weaknesses in this technology, Asset replacement and revenue value, Data sensitivity, Regulatory and contractual exposure, Expected loss as a share of asset value if realised, Annual rate of occurrence with no controls. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is inherent risk a real thing if controls already exist?

It is a modelling convention: risk as it would be if the controls were removed. Some frameworks skip it and score current risk directly, which is defensible but makes it impossible to show what the control estate is buying you. Where inherent risk gets abused is when it is inflated to make a control programme look successful.

Why band the asset value instead of using it directly?

Because valuations are rough and a 5×5 matrix cannot carry that precision. Decade bands keep the score stable when someone revises the number from £900k to £1.1m, and the monetary ALE output is there for when you do want the currency figure.

You might also need