Method

Residual Risk Is a Judgment Everywhere Except Here

The title is deliberate shorthand, not a claim that IO removes judgement from risk. Judgement remains in scope, likelihood and impact definitions, appetite, measure design, noise thresholds and treatment decisions. What IO removes is a specific…

Public method overviewDocument v3.14 min read

The title is deliberate shorthand, not a claim that IO removes judgement from risk. Judgement remains in scope, likelihood and impact definitions, appetite, measure design, noise thresholds and treatment decisions. What IO removes is a specific hidden substitution: lowering an observed residual solely because someone believes an implemented control worked.

Open a conventional enterprise risk register and find a risk whose residual score is lower than its inherent score. Then ask: what evidence moved it?

The answer is often a workshop. Someone with authority formed a view that the controls were working, and the number came down. It was recorded, dated and approved. It was an informed judgement, not a measurement, a legitimate object as long as the register labels it that way.

The mechanism nobody defends but everybody uses

This is not a criticism of risk practitioners. The workshop exists because the alternative, measuring whether the control actually changed anything, requires a baseline captured before the work, a measurement taken after it, and a population stable enough to compare. Most organisations have none of those, so a judgement is substituted, and the substitution becomes the method.

The trouble is that the substitution is invisible in the output. A residual score derived from measurement and a residual score derived from opinion look identical on the page. Both are integers in a coloured cell. A board cannot tell them apart, and neither can an auditor.

The answer is not to prohibit judgement. It is to label the basis. A complete risk view may show an expert-assessed residual, a quantitatively modelled loss distribution and IO's evidence-supported observed residual beside one another. They answer different questions and should not be silently blended.

What changes when residual can only move on evidence

Three things, and the third is the one people find uncomfortable.

A verified intervention lowers residual by one band, attributably. The movement carries the specific verification that caused it, with the measure, the before, the after, and the date. Anyone can reconstruct it.

An unmeasured control reduces nothing. The intervention may have been excellent. It may have been expensive. If nobody measured whether it changed the signal the risk was raised against, no observed residual is produced and the risk reads not yet measured. The absence of a measured residual must never be implemented as an automatic copy of inherent.

A regressed intervention raises residual, and it may end up worse than inherent. This is the part that provokes an argument, because it contradicts a convention: that residual is bounded above by inherent, since treatment cannot make things worse.

Treatment absolutely can make things worse. A migration that expands an attack surface. A control that pushes people to a workaround. A supplier change that introduces a weaker one. If the measure moved the wrong way, the register should say so, and capping residual at inherent means the register cannot represent one of the more important things that happens in practice.

The boundary that makes this workable

Organisations must be able to define their own scales. Impact is denominated in their currency and their operating reality; a loss that ends one company is a rounding error at another. Appetite is a board's decision. ISO 31000 and COSO both hold that the organisation sets its own criteria, and a vendor-fixed matrix would be less credible, not more.

So: the organisation defines the scale. It does not define the evidence.

Matrix dimensions, band labels, impact definitions, likelihood definitions, the mapping between them including asymmetric mappings, and the appetite ceiling, all configurable. How residual derives from verification, that an unmeasured control reduces nothing, that a regression raises the number, that every movement is attributable, all fixed.

If both were configurable, an organisation could define its way to green. If neither were, the model would describe an organisation nobody recognises.

The third state

The consequence of all this is that most risks, in most registers, on day one, have no measured residual at all.

They are therefore neither within appetite nor in breach. They are unassessable against appetite, and that is reported as its own state with its own count and its own reason.

This is the single most argued-with output of the model, because the number is large and it looks bad. One register reports roughly three-quarters of its risks in that state.

The alternative is to let a risk sitting below an unmeasured ceiling read as compliant, which is what most registers do implicitly, and thereby allow an organisation to claim tolerance compliance across a population it has never measured. Between a large uncomfortable number and a small false one, the model takes the first.

What to ask your own register

Pick three risks whose residual is below inherent. For each, ask what specific measurement moved it, when it was taken, and against what baseline.

If the answer is a workshop date and a set of initials, that is worth knowing. It does not make the register worthless. It makes it a record of informed opinion, which is a legitimate thing to have, as long as nobody in the room believes it is a record of measurement.

Industry basis and point of disagreement

ISO 31000, NIST SP 800-30 and common enterprise-risk practice appropriately treat risk as uncertainty informed by analysis and judgement. IO agrees with that foundation. Its narrower rule applies only to how the product moves the observed residual after treatment. It is an evidence-accounting convention, not a universal redefinition of residual risk.

References: ISO 31000 (opens in a new tab) · NIST SP 800-30 Rev. 1 (opens in a new tab)

Next step

See it before you talk to anyone.

Two quarters of recorded activity across sixteen seats. One click, no install.