Residual Risk
Residual risk is the risk that remains after controls have been applied. It is assessed for a particular use and set of conditions, not inferred merely from the number of controls in place.
Fresh documents can still produce wrong advice
Imagine a refund assistant whose obsolete documents have been removed. It can still misunderstand a current exception. The source-refresh control addresses one cause of error, while interpretation failures remain relevant.
A planned routing fix is not an operating control. Until it is implemented and checked, the team should not report its expected benefit as an achieved reduction.
Record what remains unresolved
Describe the remaining scenario, supporting evidence, uncertainty, and the authority responsible for deciding whether it is acceptable. Acceptance can have conditions or require a narrower use. It does not make the risk disappear or override applicable requirements. A material system change may require a new assessment.
Reference: NIST CSRC: Residual Risk.
Discover more from Insightful Data Lab
Subscribe to get the latest posts sent to your email.
