Every project manager knows how to log a risk. You give it a probability, an impact score, and you assign someone to do something about it.
But here is the question most risk registers never answer: once you have done something about it, how much risk is left?
That is what residual risk is. And it turns out that not measuring it creates a surprisingly large blind spot — even for experienced PMs who run tight registers.
What residual risk actually means
Residual risk is the level of risk that remains after your planned controls and mitigations have been applied.
Every mitigation you put in place reduces your exposure — but almost never to zero. A mitigation is not a cure. It is a control. And controls have limits.
Think of it this way. You identify a risk: a key supplier might fail to deliver on time. Your mitigation is to identify a backup supplier and hold a two-week buffer in your schedule. That is a solid response. But the risk has not disappeared. Your backup supplier could also be delayed. Your buffer might get consumed by something else. The probability has dropped, and so has the potential impact — but neither is zero.
The score that reflects your position after those controls are in place is your residual risk score.
In a standard probability × impact scoring framework, you might start with a risk scored at P4 × I4 = 16. After your mitigations, the realistic residual position might be P2 × I3 = 6. That reduction — from 16 to 6 — is the actual value your mitigation work has delivered. But if your risk register only ever shows the original score, nobody can see that value.
Inherent risk vs. residual risk
It helps to be precise about terminology, because these two concepts are often conflated.
- Inherent risk
- The raw, uncontrolled exposure — the risk as it would exist if you did nothing about it. No mitigations, no controls, no monitoring. Just the bare threat.
- Residual risk
- What remains after your controls are applied and working as intended.
The gap between the two is the value of your risk management activity. If your inherent score is 16 and your residual score is 6, your mitigations are delivering 10 points of reduction. If your inherent score is 12 and your residual score is 10, your controls are barely moving the needle and you probably need a different approach.
Most project risk registers only record the inherent score — or, more often, a score that is somewhere between the two without being clearly labelled as either. That ambiguity makes it hard to have honest conversations with stakeholders about where things actually stand.
Why residual risk is rarely measured in practice
If residual risk is this important, why do so many teams skip it? A few reasons.
- It requires a second round of thinking. Scoring the original risk is already effort. Scoring it again, post-mitigation, with the cognitive overhead of imagining a future state where controls are fully implemented, is harder. Most teams run out of time or energy before they get there.
- The tools don't prompt for it. Spreadsheet-based risk registers have a probability column and an impact column. They rarely have a "residual probability" column sitting alongside. If the template does not ask for it, it does not get filled in.
- It feels premature. Many PMs feel uncomfortable predicting a residual score before the mitigations are actually in place. "How do I know what the score will be if we haven't done it yet?" is a common objection. But that is precisely the point — making a considered, documented prediction before you invest in the work is what separates proactive risk management from reactive firefighting.
- Mitigations are tracked separately. Action logs, task lists, and mitigation plans often live in a different place from the risk register. There is no automatic connection between "all actions complete" and "go back and update the risk score." So the update never happens.
What you lose by not tracking it
- You cannot show stakeholders what their money bought. Risk mitigation work costs time and money. If your risk register only ever shows one score, you have no way to demonstrate that the investment reduced exposure. "We spent three weeks on this and look, the score went from 16 to 6" is a clear story. "We spent three weeks on this" is not.
- You cannot prioritise mitigation effort. Not all mitigations are created equal. Some will move the needle dramatically; others will barely register. If you cannot forecast the residual score, you are making prioritisation decisions in the dark. You might spend significant effort on a low-value mitigation while a high-value one sits unactioned.
- You cannot close the loop. Risk management is a cycle: identify, assess, respond, review. Residual risk is the "review" part. Without it, the cycle never completes. You respond to risks, move on, and never formally confirm whether the response worked.
You also lose the governance trail. Good risk governance requires that you can show, at any point in time, what your controlled risk position looks like — not just your raw exposure. Boards and auditors increasingly want to see both. A register that only shows inherent scores does not give them that picture.
How to calculate a residual risk score
The mechanics are straightforward. You use the same scoring scale as your original assessment — typically probability and impact on a 1–5 scale — but you apply it to the post-mitigation state.
Ask yourself: if our planned controls are fully implemented and working as intended, what would the probability of this risk materialising be? And if it did materialise, what would the impact be?
Score conservatively. Mitigations rarely eliminate a risk entirely. A probability of 1 does not mean "impossible" — it means "very unlikely." If your mitigation genuinely reduces a risk to near-impossible, a score of 1 might be appropriate. But if there is any meaningful residual exposure, that needs to be reflected in the score.
A few principles that help:
- Score the controls, not the intention. Do not score the residual risk based on what your mitigations are supposed to do in theory. Score them based on how reliably your controls will work in practice, given your team, your timeline, and your environment.
- Revisit as mitigations complete. Your initial residual forecast is a prediction. As mitigations are actually implemented, update the score to reflect what you have learned. The forecast and the actual residual may differ — and that difference is worth understanding.
- Do not confuse target risk with residual risk. Some frameworks include a "target risk" — the level you are aiming for. Residual risk is where you will realistically land. Both are useful, but they are not the same thing.
Want to skip the spreadsheet?
KinetiRisk calculates your residual risk forecast automatically as part of every AI analysis. Start free — no credit card required →
Start freeResidual risk and your risk register
Incorporating residual risk into your register does not require a complete overhaul of how you work. The key is to add it as a deliberate second step in the scoring process.
For each risk that has a mitigation plan:
- Score the inherent probability and impact as usual
- Document your planned mitigations
- Add a residual probability and impact score, with a brief note on the assumptions behind it
- As mitigation actions are completed, update the residual score to reflect actual progress
- When all actions are complete, formally confirm the residual score and record it as the active position
Done consistently, this gives you a register that tells a complete story: where you started, what you did about it, and where you ended up.
This is also the information that makes board-level risk reporting genuinely useful. A risk report that shows inherent and residual scores side by side, with a clear line of sight to the mitigation activity that explains the difference, is a fundamentally more honest document than one that shows a single static score.
How AI can help with residual risk forecasting
One of the practical barriers to residual risk scoring is the cognitive effort required — particularly when you are managing a large register. Predicting a realistic post-mitigation score requires you to hold two states in mind simultaneously: the current risk and the future controlled state.
This is exactly the kind of structured reasoning that AI is well suited to support. When an AI analyses a risk and generates a mitigation plan, it already has everything it needs to estimate the residual position: the risk description, the project context, and the proposed controls. It can produce a residual forecast as part of the same analysis, making it a natural byproduct of the work rather than an additional manual step.
The key — and this is important — is that the forecast should be conservative. AI-generated residual scores should reflect a realistic controlled position, not an optimistic one. Mitigations that work exactly as planned in ideal conditions are rare. A good residual score acknowledges that controls have limits, implementation takes time, and the world does not always cooperate.
KinetiRisk includes residual risk forecasting as part of its AI analysis. When you run an analysis on a risk, the AI returns not just a suggested probability and impact score for the current state, but a forecast of where the risk will sit once your mitigation actions are complete. As you work through those actions and mark them complete, your progress toward the residual score is tracked — and when everything is done, you can apply the forecast as the new active score with a single click.
It is not a guarantee. It is a well-reasoned starting point that you can accept, override, or adjust based on what you have learned along the way.
Where residual risk fits in your wider risk process
Your RAID log should reflect residual risk positions as actions complete, not just the initial scores from when risks were first logged. If your RAID log is showing P4 × I4 on a risk where the PM has completed three of four mitigations, that is misleading.
Your escalation thresholds should be applied to residual risk as well as inherent risk. A risk that starts above the escalation threshold but drops below it once controls are in place should be de-escalated accordingly. Similarly, a risk where the residual score is still above threshold despite mitigations tells you that more work is needed — or that the risk needs to be escalated to a different level of governance.
And your risk reporting should be explicit about whether the scores being shown are inherent or residual. This is a small discipline that makes a large difference to how stakeholders interpret what they are reading.
The bottom line
Residual risk is not a complicated concept. It is simply the honest answer to the question: after we have done the work, how much risk is left?
Most risk registers do not answer that question. They show you where you started and trust that the work got done. The best ones — and the teams that manage to the best ones — close the loop properly.
If you are managing risks across multiple projects and want a register that tracks both your current position and your post-mitigation forecast, KinetiRisk's free tier is a straightforward place to start. No credit card required.
Related reading
Probability × Impact Matrix Explained