← ArticlesInherent, Current and Residual RiskProject Delivery · RiskLesson 3/8← PrevNext →
GuidePublished 13 Aug 202613 min readBy Kevin Jogininherent riskcurrent riskresidual riskcontrol effectiveness

Project Delivery · Project Risk Management

Inherent, Current and Residual Risk

How to distinguish uncontrolled exposure, exposure with current controls and forecast exposure after treatment without double-counting control benefit.

13 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

How to distinguish uncontrolled exposure, exposure with current controls and forecast exposure after treatment without double-counting control benefit. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Define the assessment states
  • Estimate inherent exposure
  • Verify current controls
  • Assess current exposure
  • Forecast and verify residual exposure
  1. Define the assessment states
  2. Estimate inherent exposure
  3. Verify current controls
  4. Assess current exposure
  5. Forecast and verify residual exposure

Why Assessment Determines Where You Spend Your Resources

Risk identification tells you what risks you face. Risk assessment tells you which ones matter most. With finite resources available for managing risk, the Orange Book is clear that the aim is to achieve an optimum response to risk, prioritised in accordance with an evaluation of the risks. Assessment is the mechanism that transforms a flat list of identified risks into a prioritised, actionable risk profile — separating the critical few from the trivial many.

In defence and heavy engineering environments, this prioritisation is existential. A submarine programme may identify 400+ individual risks. Treating them all with equal intensity would be impossible and wasteful. The assessment process must reliably surface the 15–20 risks that genuinely threaten programme success, while confirming that the remaining risks are within acceptable bounds. Get the prioritisation wrong, and resources are consumed managing tolerable risks while catastrophic exposures develop unchecked.

What the Orange Book Establishes About Risk Assessment

Three Principles for Assessing Risk

The Orange Book establishes three non-negotiable principles for risk assessment:

These three principles address the most common assessment failures: subjective, undocumented judgements; assessments that cannot be compared or prioritised; and the conflation of raw exposure with controlled exposure.

The Two Dimensions: Likelihood and Impact

Every risk assessment must evaluate two dimensions:

Risk Exposure=f(Likelihood,Impact)\text{Risk Exposure} = f(\text{Likelihood}, \text{Impact})

Likelihood measures how probable it is that the risk event will occur. Impact measures the severity of the consequence if the risk does materialise. Neither dimension alone is sufficient — a highly likely risk with negligible impact may be less important than an unlikely risk with catastrophic consequences.

The Orange Book acknowledges a critical reality: "Risk assessment is more of an art than a science." Some risks — particularly financial risks — lend themselves to numerical, quantitative assessment. Others — reputational risk, for example — require subjective judgement. The framework accommodates both, but insists on structure regardless of the assessment method used.

This last point is crucial: assessment (how big is this risk?) and acceptability (is this risk tolerable?) are two separate judgements that must not be conflated. Assessing a risk as "low" because you want it to be low — rather than because the evidence supports that evaluation — is one of the most dangerous cognitive traps in risk management.

How Risk Matrices Work: 3×3 and 5×5

The 3×3 Matrix: Minimum Viable Assessment

The Orange Book states that a High / Medium / Low categorisation for both likelihood and impact "may be sufficient, and should be the minimum level of categorisation." This produces a 3×3 risk matrix — nine cells representing the full range of risk exposures.

The 3×3 matrix is effective for rapid, high-level assessment — particularly useful in workshop settings where the goal is initial triage of a large number of risks. Its simplicity is both its strength and its limitation: it cannot discriminate finely between risks that fall near category boundaries.

The 5×5 Matrix: Detailed Analytical Assessment

For more granular analysis, the Orange Book recommends the 5×5 matrix, using standardised scales:

Impact Scale:

Rating Label Cost Impact (Defence Example) Schedule Impact Safety/Compliance
1 Insignificant < AUD 50K < 1 week delay Minor procedural non-conformance
2 Minor AUD 50K – AUD 250K 1–4 weeks delay Non-conformance requiring corrective action
3 Moderate AUD 250K – AUD 1M 1–3 months delay Reportable safety incident, no injury
4 Major AUD 1M – AUD 10M 3–6 months delay Serious injury, regulatory investigation
5 Catastrophic > AUD 10M > 6 months / programme cancellation Fatality, criminal prosecution, loss of licence

Likelihood Scale:

Rating Label Probability Range Frequency Indicator
1 Rare < 5% Has not occurred in similar programmes
2 Unlikely 5–20% Could occur but not expected
3 Possible 20–50% Has occurred in similar programmes
4 Likely 50–80% Will probably occur at some point
5 Almost Certain > 80% Expected to occur, possibly multiple times

The risk score is then calculated as:

Risk Score=Likelihood Rating×Impact Rating\text{Risk Score} = \text{Likelihood Rating} \times \text{Impact Rating}

This produces scores ranging from 1 (Rare × Insignificant) to 25 (Almost Certain × Catastrophic), enabling fine-grained prioritisation and the application of traffic-light colour coding to distinguish zones of tolerability.

Colour-Coded Tolerability Zones

The Orange Book endorses the use of colour ("Traffic Lights") to clarify the significance of risks. The tolerability zones map directly to management action requirements:

Zone Score Range (5×5) Management Action
🟢 Green (Low) 1–4 Managed through routine procedures; monitor for change
🟡 Yellow (Moderate) 5–9 Active management required; specific controls in place and monitored
🟠 Amber (Significant) 10–16 Senior management attention required; enhanced controls and regular reporting
🔴 Red (Intolerable) 17–25 Board-level attention required; immediate action to reduce exposure; escalation mandatory

Inherent vs Residual Risk: Why You Need Both

The Critical Distinction

The Orange Book devotes significant attention to the relationship between inherent and residual risk because understanding both is essential for effective risk management:

Inherent risk = the raw exposure before any controls are applied. Residual risk = the remaining exposure after controls are applied, assuming those controls are effective.

Why Inherent Risk Matters

Many organisations focus exclusively on residual risk — the controlled exposure that represents their day-to-day reality. The Orange Book warns that this is insufficient for three critical reasons:

1. Exposure if controls fail. If the organisation does not know its inherent risk, it cannot evaluate the consequences of control failure. A fire suppression system in a munitions storage facility reduces the risk of catastrophic explosion from inherent "Almost Certain × Catastrophic" to residual "Rare × Catastrophic." But if the suppression system fails, the organisation is immediately back at the inherent level. Without knowing this inherent exposure, contingency planning is uninformed. 2. Identifying over-control. If the inherent risk is already within appetite — say, the uncontrolled risk of minor paint imperfections on non-critical components — then resources spent controlling that risk may be wasted. Knowledge of inherent risk allows identification of areas where controls can be relaxed without breaching appetite, freeing resources for higher-priority risks. 3. Evaluating proposed controls. When designing new controls, the assessment of anticipated residual risk is necessary to evaluate whether the proposed control will actually bring the risk within appetite. This requires knowing both the inherent starting point and the expected residual endpoint.

The Assessment-Control Loop

This creates an important insight: assessment and control are not strictly sequential — they are iterative. You assess inherent risk to determine the extent of control needed, then assess residual risk to verify the control is adequate, potentially adjusting the control and re-assessing in a refinement loop.

Documenting Risk Assessment: The Risk Profile

What Documentation Must Achieve

The Orange Book requires risk assessment to be documented in a way that creates a risk profile for the organisation. This documentation must:

The Orange Book Risk Assessment Template

The Orange Book's Annex A provides a practical documentation format. Adapted for defence engineering:

Risk Inherent Impact Inherent Likelihood Controls in Place Residual Impact Residual Likelihood Action Planned Target Date Owner
Sole-source forging supplier experiences capacity constraint, delaying hull module delivery High Medium Quarterly capacity reviews; 6-month forward order pipeline Medium Low Qualify alternative supplier for critical forgings Q3 FY26 Supply Chain Manager
Classified waste disposal contractor loses security accreditation, halting production waste removal High Low Annual accreditation monitoring; emergency disposal MOU with alternate provider High Low No further action; contingency MOU adequate Security & Compliance Lead

From Assessment to Priorities

Once risks are assessed, the risk priorities for the organisation emerge naturally. The Orange Book's guidance is direct:

It is not the absolute value of the risk score that matters — it is the gap between the assessed risk and the risk appetite that determines priority. A risk scored at 12 is higher priority than a risk scored at 15 if the appetite for the first risk category is 6 (gap of 6) while the appetite for the second is 12 (gap of 3).

Common Pitfalls in Risk Assessment

Conflating assessment with acceptability. Assessing a risk as "low" because you cannot afford it to be high is not assessment — it is wishful thinking. Assessment must be based on evidence, not on desired outcomes. Using only one dimension. Assessing risks by impact alone (ignoring likelihood) or likelihood alone (ignoring impact) produces distorted priorities. Both dimensions must always be evaluated. Inconsistent scales. If different parts of the organisation use different likelihood and impact scales, the resulting risk scores cannot be compared or aggregated. Standardised scales across the organisation are essential. Ignoring inherent risk. Focusing only on residual risk leaves the organisation blind to its true exposure if controls fail and unable to identify over-controlled risks where resources could be redeployed. Static assessment. Risk profiles change. Likelihood and impact shift as programmes progress, as the external environment evolves, and as controls are implemented or degraded. Assessment must be repeated at appropriate intervals. Treating the matrix as precision. A 5×5 matrix produces scores from 1 to 25, but these are ordinal rankings, not cardinal measurements. A risk scored 20 is not "twice as bad" as a risk scored 10. The matrix supports prioritisation and comparison, not mathematical precision.

Key Takeaways

The Risk Analysis Worksheet Template

Section 1: Risk Identification Header

Field Description Example
Unit/Division/Institute The organisational unit conducting the assessment Defence Systems Engineering Division
Risk Number Cross-reference to the risk register R-003
Risk Description Clear, concise statement of the risk event Failure of weld integrity in hull section joints during sea trials
Risk Category Classification from organisational taxonomy Operational
Related Objective Which project objective this risk threatens Deliver hull structure to the applicable classification standard by Q3

Section 2: Causes and Risk Factors

This section forces the analyst to identify all plausible causes that could trigger the risk event. Each risk may have multiple independent or interacting causes.

Causes / Risk Factors
1. Welding personnel not certified to AS/NZS 1554 for structural steel
2. Incoming plate material from new supplier not yet verified against specification
3. Workshop ambient temperature below minimum for the specified welding procedure
4. Non-destructive testing (NDT) backlog creating pressure to proceed without clearance
5. Weld procedure specification (WPS) not updated for revised plate thickness

Section 3: Impacts and Effects

This section documents what would happen if the risk materialised, across multiple impact dimensions.

Impacts / Effects
1. Hull section fails classification survey — rework cost estimated AUD 1.2M–AUD 2.5M
2. Schedule delay of 8–14 weeks for re-welding and re-inspection
3. Reputational damage with prime contractor — risk to future contract awards
4. Potential safety incident if defect not detected before sea trials
5. Warranty claim from customer for latent defect

Section 4: Current Controls and Mitigating Factors

Document what is already in place to prevent or detect this risk.

Current Controls
1. All welders hold current AS/NZS 1554 certification — records maintained by HR
2. Incoming material inspection per quality plan — CoC verified against specification
3. Workshop temperature monitoring system with automatic alarm at < 15°C
4. NDT inspection schedule managed through quality management system
5. WPS controlled document — reviewed and reissued for each design change

Section 5: Current Controlled Risk Level

The risk is assessed across four consequence dimensions using a consistent 1–5 scale:

Consequence Dimension Consequence (1–5) Likelihood (1–5) Total Rating Guide
Revenue, Cost or Liability 4 3 7 2–5 = Low
People (Safety) 3 2 5 6 = Moderate
Reputation and Political 3 3 6 7 = High
Project Performance 4 3 7 8–10 = High+
Overall Rating 7 High

Risk Score per Dimension=Consequence+Likelihood\text{Risk Score per Dimension} = \text{Consequence} + \text{Likelihood}

Overall Rating=max(All Dimension Scores)\text{Overall Rating} = \max(\text{All Dimension Scores})

Section 6: Treatment Planning (Where Risk Is Unacceptable)

Completed only when the risk owner deems the current risk level unacceptable.

Treatment Description Responsible Officer Timeline
Treatment 1 Commission independent third-party weld audit against AS/NZS 1554 Quality Manager 30 days
Treatment 2 Implement hold-point in production schedule — no hull assembly until NDT clearance confirmed Production Manager Immediate
Treatment 3 Procure backup material from verified supplier as contingency Procurement Lead 60 days
Treatment 4 Engage classification surveyor for early-stage in-process inspection rather than end-of-build only Engineering Manager 45 days

Section 7: Post-Treatment Assessment

Field Entry
Expected overall risk level after treatments Moderate
Risk owner acceptance Yes — acceptable with treatments implemented
Date worksheet completed [DD/MM/YYYY]

How to Use the Worksheet in Practice

Step 1: Populate one worksheet per risk for every risk rated Moderate or above in your risk register. Low-rated risks may not require individual worksheets unless they have the potential to escalate. Step 2: Complete sections sequentially. The learning arc matters — understanding causes before impacts ensures your controls and treatments address root causes rather than symptoms. Step 3: Cross-reference to the register. The risk number on the worksheet must match the reference in the risk register exactly. The register is the summary view; the worksheet is the evidence file. Step 4: Review with the risk owner. The worksheet should be completed collaboratively, not by a single analyst in isolation. The risk owner must agree to the risk level assessment and the acceptability determination. Step 5: Update when conditions change. Any change to project scope, schedule, supplier, personnel, or external environment should trigger a review of affected worksheets.

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Define the assessment states is defined, owned, evidenced and linked to the relevant project decision.
Check 02Estimate inherent exposure is defined, owned, evidenced and linked to the relevant project decision.
Check 03Verify current controls is defined, owned, evidenced and linked to the relevant project decision.
Check 04Assess current exposure is defined, owned, evidenced and linked to the relevant project decision.
Check 05Forecast and verify residual exposure is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

Risk Matrix Design and CalibrationGuide · RiskNEXT LESSON →Pareto Prioritisation for Project RiskGuide · RiskQualitative Project Risk AnalysisGuide · RiskSelecting Quantitative Risk Analysis MethodsGuide · Risk