Inherent Risk
Inherent risk is the level of risk that exists in the absence of controls, before any mitigations are applied, providing a baseline against which control effectiveness and residual risk can be measured.
Why Inherent Risk Matters as a Reference Point
Inherent risk answers a specific question: how much exposure would this activity or asset produce if we did nothing to protect it? That baseline is useful because it lets analysts measure the actual value of the controls in place, expressed as the reduction from inherent to residual risk.
Without an inherent-risk baseline, control investment cannot be defended cleanly. "We reduced risk" is not the same claim as "we reduced risk from $X inherent exposure to $Y residual exposure through controls costing $Z."
Inherent Risk in Practice
Calculating inherent risk requires modeling the same scenarios that produce residual risk figures, but assuming baseline controls only or no controls at all, depending on the framework. Some methodologies distinguish "gross" (no controls) from "inherent" (baseline controls) risk. Others treat the two as equivalent.
The specific definition matters less than consistency. As long as inherent risk is calculated the same way across scenarios, the resulting comparisons are meaningful.
Inherent Risk and CRQ
Quantified programs increasingly report both inherent and residual exposure. The gap between them, expressed in dollar terms, is the measured value of the control program. See what is cyber risk quantification (CRQ).
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


