Residual Risk Calculator
Work out residual risk from inherent risk and layered control effectiveness, on both the 25-point scale and in annualised loss expectancy.
Inputs
Residual Risk Score
4.87of 25
Inherent Risk Score
20of 25
Combined Control Effectiveness
75.7%
Inherent Annualised Loss Expectancy
$180,000
Residual Annualised Loss Expectancy
$43,830
Annual Loss Avoided
$136,170
Residual Band
Low — accept with periodic review
Verdict
Controls roughly halve the exposure — the residual still needs a named owner and a review date
Step by step
Values used
Inherent likelihood = 4 — Likely; Inherent impact = 5 — Severe; Preventive control effectiveness = 60 %; Detective control effectiveness = 45 %; Corrective and recovery control effectiveness = 50 %; Discount for design-only controls not yet proven in operation = 15 %; Single loss expectancy = 450,000 $; Annual rate of occurrence = 0.4000 per year
Residual Risk
Residual risk = inherent risk × (1 − combined control effectiveness), where inherent risk = likelihood × impact on the 5×5 scale.
Layered controls and ALE
Combined effectiveness = 1 − (1 − preventive)(1 − detective)(1 − corrective), then discounted for design-only controls. ALE = SLE × ARO, and residual ALE applies the same effectiveness factor.
Residual Risk Score
= 4.87 of 25
Inherent Risk Score
= 20 of 25
Combined Control Effectiveness
= 75.7
Inherent Annualised Loss Expectancy
= 180,000
Residual Annualised Loss Expectancy
= 43,830
Annual Loss Avoided
= 136,170
How it works
Control layers are combined multiplicatively on their failure probabilities rather than added, because two 50% controls in series leave 25% of the risk, not zero. Effectiveness is capped at 99% — no control set eliminates a risk — and a design-only discount is applied because a control that has never been tested in operation is a plan, not a control. Residual risk is the number that decides whether you treat, transfer or accept, and adding control percentages together is the fastest way to talk yourself into believing a risk is gone. This is a management estimate for prioritisation, not an assurance conclusion about the controls.
Formulas
Residual Risk
Residual risk = inherent risk × (1 − combined control effectiveness), where inherent risk = likelihood × impact on the 5×5 scale.
- inherentScore
- Likelihood × impact, 1–25
- effectiveness
- Combined effectiveness of the control layers, 0–0.99
- residualScore
- What is left after the controls do their job
Layered controls and ALE
Combined effectiveness = 1 − (1 − preventive)(1 − detective)(1 − corrective), then discounted for design-only controls. ALE = SLE × ARO, and residual ALE applies the same effectiveness factor.
- (1 − e)
- Failure probability of each control layer
- designGap
- Haircut for controls that are designed but not yet evidenced in operation
- ALE
- Annualised loss expectancy = single loss expectancy × annual rate of occurrence
Frequently Asked Questions
How is Residual Risk calculated?
Residual risk = inherent risk × (1 − combined control effectiveness), where inherent risk = likelihood × impact on the 5×5 scale. Control layers are combined multiplicatively on their failure probabilities rather than added, because two 50% controls in series leave 25% of the risk, not zero. Effectiveness is capped at 99% — no control set eliminates a risk — and a design-only discount is applied because a control that has never been tested in operation is a plan, not a control.
Why does Residual Risk matter?
Residual risk is the number that decides whether you treat, transfer or accept, and adding control percentages together is the fastest way to talk yourself into believing a risk is gone. This is a management estimate for prioritisation, not an assurance conclusion about the controls.
What values do I need to enter?
This calculator takes 8 inputs: Inherent likelihood, Inherent impact, Preventive control effectiveness, Detective control effectiveness, Corrective and recovery control effectiveness, Discount for design-only controls not yet proven in operation, Single loss expectancy, Annual rate of occurrence. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why cap effectiveness at 99%?
Because a residual of exactly zero is always wrong and it stops the conversation. Something can still fail — the control can be bypassed, misconfigured or turned off during a change — and leaving a sliver of residual keeps the risk on the register where someone reviews it.
Should detective controls count as much as preventive ones?
Rarely. A detective control does not stop the event, it shortens it, so it mainly reduces impact rather than likelihood. Enter it honestly and you will usually find that a stack of detective controls produces a modest combined effectiveness, which is the correct answer.