Inherent Risk: You May Not Need to Calculate It, But You Do Need to Understand It
There is an argument that inherent risk is based on a misunderstanding and is, at best, an unnecessary concept.
The argument is not without merit. Some organisations do calculate inherent risk simply because their risk-management software or methodology gives them a box to fill in. Worse, they sometimes do so by imagining that every control has somehow disappeared and then estimating what catastrophe might follow. I don’t find that particularly useful either.
Where I part company with the argument is the leap from “calculating inherent risk can be misleading” to “inherent risk is not a useful concept”. Those are very different propositions.

I don’t think we always need to calculate inherent risk. In many situations, assigning it a numerical likelihood and consequence produces little more than spurious precision.
But we absolutely need to understand it.
What are the controls controlling?
At its simplest, current risk is a function of two broad things:
the underlying risk and
the controls that modify it.
We can call the first of these inherent risk, underlying risk, gross risk, context (my personal favorite), or something else. I am less interested in defending the terminology than the concept.
Before we consider the effect of specific controls, there is an activity, asset, objective or exposure operating within a particular environment. There may be threats, hazards, vulnerabilities, dependencies and potential consequences. Those things create the underlying conditions to which our controls respond.
This leads to what I think is the most fundamental problem with dispensing with inherent risk:
How can we assess the effectiveness of a control without understanding what it is intended to control?
A control is not effective in the abstract.
A firewall is effective against particular cyber threats and attack pathways. A fire suppression system is effective against particular fire scenarios. Segregation of duties addresses particular opportunities for fraud and error. A military capability is effective against particular threats under particular circumstances.
Whenever someone tells me that a control is “effective”, there is an obvious follow-up question:
Effective against what?
That question takes us directly back to the underlying risk.
Inherent risk is not current risk with the controls deleted
I suspect some of the disagreement comes from an unhelpful way of defining inherent risk.
If we define it as taking the organisation exactly as it exists today and then mentally removing every control, we quickly end up with an artificial exercise.
What exactly are we removing?
Building codes? Locks? Laws? Staff competence? Fire brigades? Basic engineering principles? Social norms? At some point we are no longer analysing the organisation. We are inventing a different universe. But none of that is necessary.
Inherent risk is better understood as the risk arising from the underlying activity, exposure and context before considering the effect of the specific controls we are assessing.
We do not have to mentally “remove” anything. We need to understand what the controls are acting upon. That distinction is particularly important for one reason that is sometimes overlooked. Inherent risk changes.
When the environment changes but the controls don’t
Imagine a nation during a long period of peace. Its borders, intelligence services, defence forces, alliances and diplomatic arrangements may remain broadly unchanged for years. Then a neighbouring country becomes hostile, starts mobilising forces and conducts increasingly aggressive operations.
Initially, the controls may be exactly the same as they were six months earlier. The underlying risk clearly is not. The same thing happens in organisations every day.
A factory ages. Equipment deteriorates. Production volumes increase. A workforce becomes less experienced. A business starts holding more valuable information. A new criminal methodology emerges. A cyber threat actor develops a new capability. Climate conditions change. A supply chain becomes more concentrated. Demographics change.
Any of these may alter the underlying risk without changing a single control. This is why treating current risk as though it were a self-contained property of an organisation is problematic.
Suppose our assessment says that current risk has increased. Why is that? Has the environment become more hazardous? Have our controls deteriorated? Or have both things happened? Those questions lead to very different management responses.
Controls change too
The reverse is equally important. The underlying risk may remain broadly stable while the controls change. Controls can be strengthened, weakened, bypassed, removed or allowed to deteriorate. Their effectiveness can change because of maintenance, staffing, technology, workload, organisational culture or simple ageing.
We also introduce new treatments.
Suppose an assessment identifies an unacceptable current risk. We propose additional treatments and estimate that, once implemented, they will produce an acceptable residual risk.
Once those treatments are implemented and operating, they cease to be proposed treatments. They are now existing controls. And yesterday’s residual risk becomes today’s current risk.
The terminology describes different states in a continuing process.
This is also why risk assessment is not a one-off exercise. Both the underlying risk and the controls acting upon it can change. The same current risk can tell two very different stories
Consider two organisations that both assess a particular current risk as Low.
For the first organisation, the underlying exposure is modest. Serious harm is unlikely and relatively few controls are required to maintain the Low risk.
The second organisation operates in an environment where the underlying risk is extremely high, perhaps with potentially catastrophic consequences. Its current risk is Low only because several critical controls are operating effectively.
On a risk register, both might appear simply as:
Current risk: Low.
From a management perspective, they are nothing alike. The second organisation has substantial control dependency. Failure or degradation of one critical control might cause risk to rise rapidly. That should influence assurance, maintenance, testing, monitoring, redundancy and management attention.
The current-risk rating alone does not tell us that. Understanding the inherent risk does. It tells us, among other things, how much work our controls are doing.
Control effectiveness needs a reference point
This becomes even more obvious when we consider assurance and audit. Auditors, assurance practitioners and risk managers routinely examine whether controls are appropriately designed, implemented and operating effectively.
But effectiveness requires a reference point. We cannot meaningfully say that a control reduces likelihood, consequence, exposure or vulnerability unless we understand the underlying condition it is intended to modify.
Otherwise we risk creating a circular argument. We assess current risk using an implicit understanding of our controls, then use the resulting current-risk assessment to reason about whether those same controls are adequate.
What independent understanding do we have of the risk they are supposed to manage? Understanding inherent risk breaks that circle.
Understanding does not mean scoring
None of this means that every risk register needs another column. Indeed, one legitimate criticism of traditional risk management is our tendency to turn every useful concept into another number.
There may be very little value in deciding that inherent likelihood is 4, inherent consequence is 5 and inherent risk is therefore 20. The apparent precision may add nothing to the decision.
Often a clear description is considerably more valuable.
What creates the risk?
What are we exposed to?
What could change that exposure?
What threats, hazards and vulnerabilities matter?
What consequences could reasonably arise?
What assumptions are we making?
Which controls are critical to keeping the current risk where it is?
These questions give us something useful to manage. I've written many times about the CASE method, where a single sentence to describe a risk should articulate, identify, and define the risk by describing the consequence, asset, source, and event.
The objective should not therefore be to calculate inherent risk for its own sake. It should be to understand the underlying risk well enough to understand both current risk and our dependence on the controls modifying it.
Three risk states and two interventions
For practical purposes, I use a simple model.

Inherent Risk → Existing Controls → Current Risk → Proposed Treatments → Residual Risk
Inherent, current and residual risk are states of risk.
Existing controls and proposed treatments are interventions that modify risk.
Once proposed treatments are implemented and demonstrated to be effective, they become existing controls. The anticipated residual risk becomes the new current risk. I've written more about this in an A4 infographic and the SRMBOK Guide to the Risk Management Process with a core model that aligns this concept with the ISO 31000 risk management process.
Meanwhile, the inherent risk may also have changed because the environment itself has changed so the cycle continues. That is why understanding all three states is useful even if we never assign an inherent-risk score.

The problem isn’t inherent risk
There is a legitimate debate about how inherent risk should be defined and used. There is also a perfectly legitimate criticism of organisations that mechanically calculate an inherent-risk score without understanding why they are doing it.
But neither argument makes the underlying concept redundant. We don’t necessarily need to calculate inherent risk. We do need to understand and contextualise it.
Current risk emerges from the relationship between the underlying risk environment and the controls operating within it. Either can change independently. If we understand the controls but not the risk they are controlling, we cannot properly assess control effectiveness.
If we understand the underlying risk but ignore the controls, we cannot properly assess current risk. Good risk management requires both. So rather than debating whether inherent risk “exists” in some philosophical sense, I think there are three much more useful questions:
What is driving this risk?
What is shaping or controlling it?
And how might either of those things change?
For more thinking, models and practical guidance on risk management, visit the Risk Management Body of Knowledge at RMBOK.com.



