Black Kite is a finalist in the 2026 SC Awards for continued innovation and leadership in third-party cyber risk intelligence.Learn more
BlackKite: Home
Menu
Back to Glossary

Residual Risk

Residual risk is the level of risk that remains after security controls have been applied. The difference between inherent risk and residual risk reflects the effectiveness of a vendor's security program. Risk acceptance decisions are made against residual risk, not inherent risk.