The inherent assessment establishes the scenario before the mitigating controls included in your assessment method. State that boundary explicitly so the baseline can be compared fairly with current and target risk.

Explain the scenario

In Inherent risk, describe the event, affected asset or objective, and consequence in Risk statement. Use Strength, Weakness, Opportunity and Threat to explain the circumstances and assumptions.

For example, assess unauthorised access to a customer file-transfer service under a stated assumption that the relevant access-control safeguards are absent. An existing MFA or segmentation control belongs in the current assessment rather than being silently credited in that baseline.

Select likelihood and impact

Choose the appropriate cell in Likelihood level, using the threat and vulnerability levels. The selected cell supplies the configured likelihood value. Then select Impact and the relevant Impact types.

Risk exposure displays the resulting matrix position and band. Its numeric exposure is the selected likelihood level multiplied by the impact level. These are configured assessment scores, not a measured probability or financial loss estimate.

An unset assessment is different from a low score. Save the risk and verify the displayed result before moving on to the current assessment.

Use the matrix labels and definitions associated with this risk. Do not assume that every workspace uses five levels or identical thresholds.