ISACA defines residual risk as the amount of risk remaining after controls and mitigation efforts are put in place. Because risk management strategies are implemented to mitigate risk, the type of risk most directly reduced is residual risk. Inherent risk exists before controls are applied, so it is not the risk category most directly reduced by control implementation. Sampling risk and detection risk are audit risks, not the primary target of enterprise risk treatment strategies.
Option C is incorrect because inherent risk is the baseline level of risk absent controls. Option A and D relate to audit methodology and audit assurance rather than enterprise risk treatment outcomes. ISACA’s risk guidance consistently describes controls and mitigation efforts as mechanisms to reduce remaining exposure to an acceptable level, which is residual risk.
References (Official ISACA):
ISACA Journal, Quantifying the Qualitative Technology Risk Assessment.
ISACA Journal, Risk Assessment and Analysis Methods.
ISACA Journal, From Measurement to Management.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit