Inherent risk is the level of risk that exists in the absence of any mitigating controls or measures: the natural level of risk arising from the characteristics of an activity, process or system before any effort to reduce it. It is assessed in the Inherent Risk tab of the risk.
1. Inherent Risk Statement
A concise summary of the risk scenario in its raw state, without considering existing or planned controls. It sets the baseline for comparison once controls are applied.
Example: "The financial system is vulnerable to cyberattacks due to outdated security protocols, potentially leading to data breaches and financial losses."
2. Inherent Risk Strength
Existing capabilities or factors that naturally limit the risk's impact or likelihood, even before dedicated controls.
Example: "Network segmentation already isolates the financial system from general office traffic."
3. Inherent Risk Weakness
The vulnerabilities, gaps or deficiencies that let the risk exist or escalate: weak points in processes, systems or human factors that guide the identification of appropriate controls.
Example: "The absence of multi-factor authentication (MFA) on user accounts increases the susceptibility to unauthorised access."
4. Inherent Risk Opportunity
The potential benefits of addressing the risk effectively: how managing it might create value, enhance capabilities or improve resilience.
Example: "Implementing an advanced cybersecurity framework could enhance the company's reputation and attract security-conscious clients."
5. Summary
| Field | Focus | Purpose |
|---|---|---|
| Inherent Risk Statement | The risk scenario in its raw state | Understand and baseline the untreated risk |
| Inherent Risk Strength | Factors already limiting the risk | Recognise natural protections |
| Inherent Risk Weakness | Vulnerabilities causing the risk | Identify gaps and flaws to control |
| Inherent Risk Opportunity | Positive outcomes from addressing it | Turn the risk into strategic advantage |
6. Impact Type
Select the relevant Impact Type(s) from your predefined catalogue: financial loss, operational disruption, legal implications, reputational damage, data breach and any other dimension your workspace defines. Categorising the impact clarifies the potential consequences, helps prioritise responses, and aligns the assessment with your organisation's strategic objectives and risk appetite.
7. Risk matrix
After defining the Impact Type, determine the Inherent Risk level using the risk matrix.
1. Likelihood Level
Begin by defining the likelihood of the risk materialising.
Note: Likelihood = Threat x Vulnerability. Select the threat level and the vulnerability level; the matrix derives the likelihood score.
2. Risk Exposure
Note: Risk = Likelihood x Impact. Select the impact; the risk level is placed automatically on the matrix.
The likelihood and risk exposure model is taken from NIST 800-161r1, section D.4.1.7 "Risk Response Analysis", page 227, extended from 4 to 5 levels. Your workspace's matrix dimensions are configurable in Settings, Risk Matrix.