Residual risk
Also known as: Net risk, Remaining risk
Residual risk is the level of risk that remains after security controls and mitigation strategies have been implemented. It represents the actual exposure an organization faces once its defenses are in place. If this remaining risk exceeds a company's defined risk appetite, further controls must be added or the risk must be formally accepted by management.
In practice
During an audit, a practitioner assesses residual risk by testing existing controls to see if they effectively reduce inherent risk to an acceptable level. For example, while encryption reduces the risk of data theft, the remaining possibility that an authorized user might leak data is the residual risk.