Method and management system

What is residual risk?

The level of risk remaining once the identified controls have been implemented. It is written separately for two reasons: it shows whether the control actually brought the level to where it was meant to go, and it settles who monitors what remains. An assessment that never records residual risk never asked whether the control worked.

Two scores, one line

A good risk assessment line carries two values: the risk before controls and the residual risk after them. The gap between them shows how much the control achieved. A table carrying only one of them hides either optimism or helplessness.

Residual risk is never zero

No control reduces risk to zero; the aim is to bring it to an acceptable level. So as well as what the residual risk is, how it will be monitored is written: which indicator, how often, by whom.

Who scores it, and when

A common error is to mark the residual risk as low the moment a control is written down. Risk does not fall until the control is implemented. The right arrangement: when the control is complete, the line is reassessed and the residual risk recorded then. That is why due dates and closure records are inseparable from the assessment.

Telling people what remains

Residual risk is explained to the person doing the work. A worker must know which risk persists and what to do about it; residual risk that is never communicated has been managed only on paper.

Using it as a decision threshold

In mature systems residual risk is a threshold: work that stays above a defined level does not start without additional authorisation. That turns what remains from a note into an operating decision.

Manage this in Optifora

Optifora is not a single program but a compliance platform assembled from modules. The catalogue states which module is ready today and which is on the roadmap.

See what Optifora is