Inherent risk is the level of risk that exists in the absence of any mitigating controls or measures: the natural level of risk arising from the characteristics of an activity, process or system before any effort to reduce it. It is assessed in the Inherent Risk tab of the risk.

1. Inherent Risk Statement

A concise summary of the risk scenario in its raw state, without considering existing or planned controls. It sets the baseline for comparison once controls are applied.

Example: "The financial system is vulnerable to cyberattacks due to outdated security protocols, potentially leading to data breaches and financial losses."

2. Inherent Risk Strength

Existing capabilities or factors that naturally limit the risk's impact or likelihood, even before dedicated controls.

Example: "Network segmentation already isolates the financial system from general office traffic."

3. Inherent Risk Weakness

The vulnerabilities, gaps or deficiencies that let the risk exist or escalate: weak points in processes, systems or human factors that guide the identification of appropriate controls.

Example: "The absence of multi-factor authentication (MFA) on user accounts increases the susceptibility to unauthorised access."

4. Inherent Risk Opportunity

The potential benefits of addressing the risk effectively: how managing it might create value, enhance capabilities or improve resilience.

Example: "Implementing an advanced cybersecurity framework could enhance the company's reputation and attract security-conscious clients."

5. Summary

FieldFocusPurpose
Inherent Risk StatementThe risk scenario in its raw stateUnderstand and baseline the untreated risk
Inherent Risk StrengthFactors already limiting the riskRecognise natural protections
Inherent Risk WeaknessVulnerabilities causing the riskIdentify gaps and flaws to control
Inherent Risk OpportunityPositive outcomes from addressing itTurn the risk into strategic advantage

6. Impact Type

Select the relevant Impact Type(s) from your predefined catalogue: financial loss, operational disruption, legal implications, reputational damage, data breach and any other dimension your workspace defines. Categorising the impact clarifies the potential consequences, helps prioritise responses, and aligns the assessment with your organisation's strategic objectives and risk appetite.

7. Risk matrix

After defining the Impact Type, determine the Inherent Risk level using the risk matrix.

1. Likelihood Level

Begin by defining the likelihood of the risk materialising.

Note: Likelihood = Threat x Vulnerability. Select the threat level and the vulnerability level; the matrix derives the likelihood score.

Likelihood Level Matrix

2. Risk Exposure

Note: Risk = Likelihood x Impact. Select the impact; the risk level is placed automatically on the matrix.

Risk Level Matrix

The likelihood and risk exposure model is taken from NIST 800-161r1, section D.4.1.7 "Risk Response Analysis", page 227, extended from 4 to 5 levels. Your workspace's matrix dimensions are configurable in Settings, Risk Matrix.