This is pre-normative material. Values and definitions here are working values, they are published so the reasoning is inspectable, not because they are settled.
Status: pre-normative · model version 0.1 · implemented across register phases 1–4. Companion to the IO Maturity Model specification: that one governs whether a practice is repeatable, this one governs whether an exposure is tolerable. Nothing changes without a version increment.
1. The one rule that differs
Conventional risk registers commonly treat residual risk as a judgement. Someone asserts that the controls are working and re-scores the risk in a workshop. The number moves because a person decided it should.
Here, residual moves on evidence or it does not move.
- A verified intervention that measurably changed the signal the risk was raised against lowers it.
- A regressed intervention raises it, and residual may end up worse than inherent.
- An unmeasured control reduces nothing.
Everything else in this document, scales, treatment decisions, review cadence, appetite, is table stakes that established governance platforms already do competently. This is the part that is different.
The accepted position, and where IO departs
ISO 31000, ISO/IEC 27005 and NIST SP 800-30 treat risk analysis as a structured judgement made under uncertainty. They support organisation-specific context, risk criteria, likelihood, impact, treatment and monitoring. IO agrees: risk is not a universal number, and the board owns appetite.
IO departs at one narrow point. Conventional programmes often allow residual risk to be re-estimated because a control was implemented or an expert believes it is effective. IO requires an attributable measurement before its observed residual moves. This is intentionally more conservative. It does not make the industry method wrong; it prevents a treatment decision from being mistaken for evidence of treatment effectiveness.
The word observed is therefore essential. IO's residual is not a complete forecast of remaining loss. It is the position supported by the verified interventions in scope. Scenario analysis, threat intelligence, expert judgement and quantitative loss modelling remain valid inputs to broader enterprise risk decisions and should be shown alongside, not silently absorbed into, this value.
Primary references: ISO 31000 (opens in a new tab) · NIST SP 800-30 Rev. 1 (opens in a new tab) · NIST CSF 2.0 (opens in a new tab)
2. The boundary: scale versus evidence
The organisation defines its own scale. It does not define its own evidence.
| Configurable by the organisation | Fixed |
|---|---|
| Matrix dimensions, 3×3 to 6×6 | How residual derives from verification evidence |
| Band labels and their order | That an unmeasured control cannot reduce residual |
| Impact definitions, in its own currency | That a regressed verification raises residual |
| Likelihood definitions, frequency or probability | That an unmeasured risk cannot be declared within appetite |
| The likelihood/impact → rating mapping, including asymmetric matrices | That every movement is attributable to a named verification |
| Appetite ceiling per domain |
Why the scale is theirs. Impact bands are denominated in the organisation's own currency and operating reality. A loss that is catastrophic for one company is a rounding error for another, and appetite is a board decision rather than a vendor determination. ISO 31000 and COSO both hold that the organisation defines its own criteria. A fixed matrix would be less credible, not more.
Why the evidence is not. If both the scale and the measurement were configurable, an organisation could define its way to green.
3. Scoring model
One active versioned model per organisation: ordered likelihood bands with written definitions and optional frequency anchors; ordered impact bands with definitions across financial, operational, regulatory and reputational consequence; an output rating scale; a matrix; and an appetite ceiling per domain.
The matrix may be asymmetric. An organisation may hold a rare severe event to be worse than a near-certain trivial one, and the model must permit that rather than assuming a product of ordinals.
4. Inherent rating
The position before treatment, scored against the active model and recording the version under which it was computed. Superseded scores are retained, never overwritten, so history displays under its original model.
Within the IO model, inherent is not used to determine appetite status. Appetite status governs what is tolerable after treatment and is therefore computed from observed residual. An organisation may display inherent against a planning threshold, but that comparison must be labelled separately and must never be reported as within appetite, in breach or cannot be assessed.
5. Observed residual
| Verification result | Effect |
|---|---|
| Verified, measured in the intended direction | Lowers the affected dimension by one band |
| Regressed, measured worse | Raises it by one band. May exceed inherent. |
| Unverified | No movement. The work ran and could not be shown to have worked. |
| Inconclusive | No movement. |
| Pending | No movement. |
| No verification at all | Residual stays null and reads not yet measured |
Bands never move below the lowest or above the highest on the scale. Multiple verifications may move a dimension more than one band, but every step must be attributable to a specific verification.
Which dimension moves. Most treatments reduce likelihood. Some reduce impact segmentation, backup and recovery, blast-radius controls. The playbook declares which dimension its verification addresses. Where none is declared, residual does not move. Inferring the dimension from a unit of measure would be an inference presented as a measurement, and an unattributable reduction is not a reduction.
Verifications predating the score are already reflected in it and must not be counted twice. Double-counting deflates residual across a register and is invisible in aggregate.
The basis is recorded. Every residual carries its derivation: each verification considered, its result, measured before and after, unit, date, the dimension it moved and in which direction, including those considered and not counted, with the reason. A reader must be able to reconstruct the number without trusting it.
Never asserted. There is no manual residual entry and no override. If the evidence does not support a number, there is no number.
No proportional movement is implied. The current implemented rule moves one declared dimension by one band for each eligible verification. A large measured delta does not automatically justify two or more bands; that remains an open calibration question. Product copy must not say residual moves "by the amount the measurement supports" until such a rule is defined, versioned and implemented.
6. Appetite has three states
A risk is in breach when measured residual exceeds the ceiling for its domain. A risk with no measured residual is neither compliant nor breaching, it is unassessable against appetite, and that is its own reported state with its own count and reason.
- Within appetite, residual measured, at or below the ceiling
- In breach, residual measured, above the ceiling
- Cannot be assessed, no measured residual
Reporting an unmeasured risk as within appetite is exactly the assertion this model exists to replace, and it would let an organisation claim tolerance compliance across a register it has never measured. Most registers do this implicitly, because a risk sitting below a ceiling looks compliant whether or not anyone checked.
Never fall back to inherent when residual is unmeasured.
Evidence age is reported beside the appetite state. Until the evidence-decay policy is decided, an old verification does not automatically change residual or remove an appetite state. Product copy must not describe a result as "current" merely because a residual value exists.
7. Versioning, and the language rule
Both the scoring model and the appetite ceilings are versioned. Every score records the version it was computed under. Changes create a new version and apply prospectively; historical scores are never restated. A change-impact preview runs before applying, for both matrix and appetite: how many risks would be stated in a different band, in which direction, named.
Relaxing a matrix cell or raising a ceiling makes risks read lower and breaches disappear. That is the ruler moving, not the exposure changing. Required wording, in both directions:
"9 findings resolve because the threshold moved, not because anything changed. The same records behave exactly as they did before."
Never colour a loosened scale as improvement. A product that congratulates a customer for moving the bar teaches them to move it again.
8. Ownership and review
The risk owner is accountable for the risk and is distinct from whoever owns any task raised against it. Unowned risks are counted and reported, nobody can review a risk that belongs to no one. Treatment decisions, accept, mitigate, transfer, avoid, carry rationale, decided-by and decided-at. Review cadence is per risk. A risk both in breach and overdue for review is the sharpest condition in the register and is reported explicitly.
9. Board rollup
Three figures, always together:
- Position against appetite, within, in breach, cannot be assessed, as counts and shares. The third figure belongs in the headline.
- Coverage, the share of the register with any measured residual. This states how much everything else can be relied on.
- What moved, and why, residuals that changed, both directions, each attributed to the verification that moved it. A residual that rose because an intervention regressed is the most valuable line in the pack.
Rank by measured residual only. An unmeasured risk has no established position and placing it in a ranking implies one. List measured exposures ranked, then the unassessable separately with their count and reason. Consolidate by verification, one intervention affecting several records is one entry naming the count, not several identical entries.
10. What this does not do
It does not predict. It does not establish causation, a post-intervention measurement shows what changed after the intervention, and attributing that change to it requires a measurement design that supports the claim. It does not score people; effectiveness attaches to playbooks, never to whoever executed them. It does not replace a register held elsewhere.
11. Open
| # | Item |
|---|---|
| 1 | Evidence decay. Age is surfaced; automatic decay toward inherent is not implemented and needs a decision rather than a default. |
| 2 | Multi-step movement. Whether a large measured delta should move more than one band is unresolved. |
| 3 | Impact-reducing treatments are under-represented in the playbook library; most declare likelihood. |
| 4 | Recurring conditions must reopen an existing risk rather than create a sibling, or the register inflates with duplicates of one exposure. |
| 5 | Appetite is set per domain only, not per business unit. |