Work out residual risk from inherent risk and layered control effectiveness, on both the 25-point scale and in annualised loss expectancy.
Control layers are combined multiplicatively on their failure probabilities rather than added, because two 50% controls in series leave 25% of the risk, not zero. Effectiveness is capped at 99% — no control set eliminates a risk — and a design-only discount is applied because a control that has never been tested in operation is a plan, not a control. Residual risk is the number that decides whether you treat, transfer or accept, and adding control percentages together is the fastest way to talk yourself into believing a risk is gone. This is a management estimate for prioritisation, not an assurance conclusion about the controls.
Residual Risk
Residual risk = inherent risk × (1 − combined control effectiveness), where inherent risk = likelihood × impact on the 5×5 scale.
Layered controls and ALE
Combined effectiveness = 1 − (1 − preventive)(1 − detective)(1 − corrective), then discounted for design-only controls. ALE = SLE × ARO, and residual ALE applies the same effectiveness factor.
Residual risk = inherent risk × (1 − combined control effectiveness), where inherent risk = likelihood × impact on the 5×5 scale. Control layers are combined multiplicatively on their failure probabilities rather than added, because two 50% controls in series leave 25% of the risk, not zero. Effectiveness is capped at 99% — no control set eliminates a risk — and a design-only discount is applied because a control that has never been tested in operation is a plan, not a control.
Residual risk is the number that decides whether you treat, transfer or accept, and adding control percentages together is the fastest way to talk yourself into believing a risk is gone. This is a management estimate for prioritisation, not an assurance conclusion about the controls.
This calculator takes 8 inputs: Inherent likelihood, Inherent impact, Preventive control effectiveness, Detective control effectiveness, Corrective and recovery control effectiveness, Discount for design-only controls not yet proven in operation, Single loss expectancy, Annual rate of occurrence. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because a residual of exactly zero is always wrong and it stops the conversation. Something can still fail — the control can be bypassed, misconfigured or turned off during a change — and leaving a sliver of residual keeps the risk on the register where someone reviews it.
Rarely. A detective control does not stop the event, it shortens it, so it mainly reduces impact rather than likelihood. Enter it honestly and you will usually find that a stack of detective controls produces a modest combined effectiveness, which is the correct answer.