Quick Answer:

Residual risk is the risk that remains after your controls are in place and working. Inherent risk is the exposure before controls. Closing an incident closes the event, not the exposure, because the control that failed usually still leaves something behind. Rate residual risk with the same likelihood and consequence scale you used for inherent risk, record it in your risk register, and review it whenever a control changes or an incident shows a control did not hold.

An incident is investigated. A corrective action is raised, completed and signed off. The file is closed and the matter feels finished.

Six months later something similar happens. Not identical, and not to the same person, but close enough that everyone recognises it. The investigation was sound and the corrective action was real. What nobody wrote down was how much risk was still sitting there after the fix.

That leftover exposure is residual risk, and it is one of the most useful ideas in risk management because it is the one that tells you whether your controls are actually enough. This guide explains what residual risk is, how it differs from inherent risk, how to rate it, and what Australian work health and safety law expects you to do about the risk that remains.

Written by Gavin Altus. Definitions follow ISO 31000, and the regulatory references are drawn from the model Work Health and Safety Regulations. Sources are listed at the end.

Sentrient builds workplace compliance software for Australian organisations, including a risk management system and incident reporting software that link incidents to the risks they relate to.

What Is Residual Risk?

Residual risk is the risk that remains after risk treatment. That is the definition used in ISO 31000 and the associated vocabulary standard, and it is deliberately simple. You identify a risk, you apply controls, and whatever exposure is still there afterwards is residual risk.

Two points follow from that definition and both matter more than the definition itself.

Residual risk is almost never zero: Controls reduce likelihood or consequence. They rarely remove a hazard entirely, and when they do, the correct description is elimination rather than treatment. A guard on a machine, a training module, a two-person lifting rule and a policy all leave something behind.

Residual risk assumes the controls are working: This is the part organisations get wrong. A residual rating calculated on the assumption that a control is in place, understood and followed is a different number from the one you get when the control exists only in a document. If you have not tested the control, you have not measured residual risk. You have estimated it.

Inherent Risk vs Residual Risk

Inherent risk is the exposure before any controls are applied. Residual risk is what is left after them. Recording both is what shows you how much work your controls are doing.

Inherent risk Residual risk
What it measures Exposure with no controls in place Exposure with controls in place and working
When it is set At first assessment of the risk After treatment, then reviewed on a cycle
What it tells you How serious this would be if you did nothing Whether what you are doing is enough
How it changes Only when the nature of the work changes Whenever a control is added, removed or fails
Who usually asks for it Auditors and insurers, to see the raw exposure Boards and regulators, to see the current position
Common mistake Rating it as though some controls already exist Assuming controls work without testing them

The gap between the two numbers is your control effect. A small gap on a high inherent risk is a warning: you have accepted a serious exposure and the treatment is barely moving it.

Why Closing an Incident Does Not Close the Risk

An incident and a risk are different objects. The incident is an event that happened once, with a date, an investigation and an outcome. The risk is a standing condition that will still be there tomorrow. Closing the first does nothing to the second unless someone deliberately connects them.

More than that, an incident is evidence. It tells you that on at least one occasion, the control you were relying on did not hold. That is new information about residual risk, and it should move the number.

In practice the connection breaks for ordinary reasons. The investigation sits in one system and the register sits in another. The person who closed the incident is not the risk owner. The corrective action was specific to the event, such as retraining one team, while the risk applies across the organisation. None of these are failures of diligence. They are gaps between two processes that were never joined up.

The fix is a rule rather than a system: no incident closes until the related register entry has been looked at and either re-rated or explicitly confirmed. Our guide to incident reporting in the workplace covers the reporting side of that loop, and integrated risk management covers what happens after the investigation.

Where an incident is serious enough to be a notifiable incident, the regulator has to be told immediately, before any of this internal work starts. The register review comes afterwards, but it still has to happen.

Where Residual Risk Hides After an Incident

Six patterns account for most of the risk that survives a well run investigation.

Pattern What it looks like Why residual risk stays high
The fix was administrative A new procedure, a toolbox talk, a reminder email Administrative controls sit near the bottom of the hierarchy and depend on people behaving consistently
The fix was local One site, one shift or one team was corrected The same conditions exist elsewhere and were never assessed
The fix was temporary A barrier, a supervisor on the floor, an interim roster Nobody recorded an end date, so the risk returns quietly when the measure lapses
The fix addressed the event, not the cause The immediate trigger was removed, the underlying condition was not The same cause can produce a different event
The control was never tested Marked complete, never verified in practice The residual rating is an assumption rather than a measurement
The rating was never revisited The register still shows the pre-incident numbers Leadership is reading a position that the incident already disproved

How to Rate Residual Risk

There is no separate formula. You use the same likelihood and consequence scale you used for the inherent rating, which is what makes the two numbers comparable. If you do not have a settled scale, the 5×5 risk matrix is a reasonable starting structure.

  1. Rate the inherent risk first: Likelihood and consequence with no controls applied. Do this honestly, because an inflated inherent rating flatters the control effect later.
  2. List the controls that are actually in place: Not planned, not drafted. In place.
  3. Judge each control’s effectiveness: Effective, partially effective or ineffective, with a reason. A control nobody has tested is partially effective at best.
  4. Re-rate likelihood and consequence with those controls working: Most controls move likelihood. Fewer move consequence, and it is worth being sceptical when someone claims a procedure has reduced the severity of an outcome.
  5. Record both numbers, the controls and the date: A residual rating without a date is not evidence of anything.
  6. Compare the result to your tolerance: If it sits above the level your board has agreed to accept, you need further treatment or a documented, senior acceptance.

A Worked Example

A warehouse worker strains their back moving stock from a high shelf. The incident is investigated, the corrective action is a manual handling refresher for the team, and the file is closed. The ratings below use a 5×5 scale and are illustrative.

Stage Likelihood Consequence Rating Basis
Inherent 4, likely 3, moderate High Repetitive lifting above shoulder height with no controls
Residual after training only 3, possible 3, moderate Medium to high Training is administrative, the shelf height and the task have not changed
Residual after re-racking and a lifting aid 2, unlikely 2, minor Low to medium Engineering controls change the task itself rather than the behaviour around it

The investigation was competent and the training was worth doing. It moved likelihood by one step and left the exposure sitting near the top of the tolerable range. Writing that down is what turns an incident into a decision, because now someone has to either fund the re-racking or formally accept a medium to high risk.

The same logic applies to psychosocial risk, where controls are administrative more often than not. A workload complaint answered with a resilience training module usually leaves the residual rating close to where it started, because the work design that produced the complaint has not changed.

What Australian WHS Law Expects

The model Work Health and Safety Regulations do not use the phrase “residual risk”, but the concept is built into the hierarchy of control measures. Regulation 36 requires a duty holder to eliminate risks so far as is reasonably practicable, and where that is not reasonably practicable, to minimise them through substitution, isolation and engineering controls. It then says, in terms, that if a risk then remains the duty holder must minimise the remaining risk so far as is reasonably practicable through administrative controls, and if a risk still remains, through personal protective equipment.

That is residual risk written into a regulation. The sequence is mandatory rather than a menu, which is why a fix that jumps straight to training or PPE leaves a larger remainder than one that changes the task.

Regulation 38 then requires duty holders to review and, as necessary, revise control measures, including where a control measure does not control the risk so far as is reasonably practicable, before a change at the workplace that may give rise to a new or different risk, where a new hazard or risk is identified, where consultation indicates a review is needed, or where a health and safety representative requests one. An incident is direct evidence that a control did not do its job, which puts it squarely inside the first of those circumstances.

The model regulations are applied with variations across states and territories, and duties differ by industry and entity type. This is general information rather than legal advice, and you should confirm your own obligations with your regulator or a qualified adviser.

How Much Residual Risk Is Acceptable?

There is no universal answer, and any vendor who offers one is selling rather than advising. The acceptable level is the one your board has defined and can defend, set out in a risk appetite or tolerance statement, and it will differ by risk type. An organisation may tolerate a moderate financial exposure and almost none on physical safety.

What matters more than the number is that the decision is recorded. If a residual rating sits above tolerance and the organisation decides to live with it for now, that acceptance should have a name against it, a reason and a review date. An accepted risk with no owner is not an accepted risk. It is an unmanaged one.

Two things are worth keeping in view while you set that level. Safe Work Australia’s Key Work Health and Safety Statistics Australia 2025 found that 84% of serious workers compensation claims in 2023-24 came from four mechanisms: body stressing, falls, slips and trips, being hit by moving objects, and mental stress. And the median serious claim involved 7.4 working weeks lost and median compensation of $16,300. Residual risk is the number that sits between a control and those outcomes.

Keeping the Residual Rating Current

A residual rating decays. It was true on the day it was set, with the controls that existed then and the people who were trained on them. Four habits keep it honest:

  • Re-rate on incident closure: Make it a required step rather than a good intention.
  • Re-rate when a control changes: Including when a temporary control ends, which is the one most often missed.
  • Watch the leading signals: Key risk indicators tell you a residual rating is drifting before the next incident proves it.
  • Review on a set cycle: Continuous monitoring beats an annual workshop, because most controls fail quietly rather than visibly.

This is also where the tooling matters. In Sentrient, incidents, hazards and controls are linked to the risks they relate to, every risk carries a named owner, and real-time dashboards show the current position without anyone rebuilding a report. If your register still lives in a spreadsheet, the gap usually shows when risks need named owners, review dates and a link back to the incidents that tested them. For the wider process, start with risk management fundamentals.

Book a free demo to see how an incident closure updates the residual rating on the linked risk.

Frequently Asked Questions

1. What is residual risk in simple terms?

It is the risk left over once your controls are in place and working. If a hazard rated high before you did anything, and your controls bring it down to medium, that medium rating is the residual risk.

2. What is the difference between inherent risk and residual risk?

Inherent risk is the exposure before controls are applied. Residual risk is the exposure after them. Recording both shows how much your controls are actually doing, and a small gap on a high inherent risk is a signal the treatment is too weak.

3. How do you calculate a residual risk rating?

Use the same likelihood and consequence scale as the inherent rating, then re-score with the controls that are genuinely in place and effective. Record both scores, the controls relied on, and the date. There is no separate formula, and using a different scale for the two ratings makes them impossible to compare.

4. Can residual risk ever be zero?

Rarely, and only where the hazard has been eliminated rather than controlled. If a task is removed entirely, the risk goes with it. Where the work continues, some exposure remains, and a register full of zero residual ratings usually points to optimistic scoring rather than excellent controls.

5. Should residual risk be reassessed after every incident?

Yes, for the risk the incident relates to. An incident is evidence a control did not hold, which is new information about the remaining exposure. Reassessing does not always change the rating, but the check should happen and the outcome should be recorded either way.

6. Who decides how much residual risk is acceptable?

The board or the executive, through a risk appetite or tolerance statement, usually with different levels for different risk types. Individual managers apply that standard rather than setting it, and any acceptance above tolerance should carry a name, a reason and a review date.

7. Does Australian WHS law require organisations to manage residual risk?

The model WHS Regulations do not use the term, but regulation 36 requires duty holders to minimise “the remaining risk” so far as is reasonably practicable at each step down the hierarchy of control, and regulation 38 requires control measures to be reviewed and revised in defined circumstances. Requirements vary by jurisdiction and industry, so confirm your own with your regulator or a qualified adviser.

8. Where should residual risk be recorded?

In the risk register, alongside the inherent rating, the controls relied on, the risk owner and the date of the assessment. Keeping it anywhere else, such as inside an investigation report, means it will not be seen at the next review.

9. What is the relationship between residual risk and the hierarchy of controls?

The higher up the hierarchy your control sits, the smaller the remainder. Elimination and substitution change the work itself, so they leave little behind. Administrative controls and personal protective equipment depend on people acting consistently, so they leave more. A residual rating that barely moved usually means the treatment came from the bottom of the hierarchy.

10. How often should residual risk ratings be reviewed?

On a set cycle appropriate to the risk, and additionally whenever a control changes, a temporary control ends, an incident or near miss occurs, or the work changes. Annual review alone is too slow for anything rated high.

Sources

This guide is general information current at the date of publication and is not legal advice. Work health and safety duties differ between jurisdictions and change over time. Confirm your obligations with your work health and safety regulator or a qualified adviser.