European Definitions
=== European Definitions ===
{{definition|''ENISA uses the ISO definition, see below.'' <ref name="ENISAGlos"> [http://www.enisa.europa.eu/activities/risk-management/current-risk/risk-management-inventory/glossary ENISA Risk Glossary]</ref>}}<br />
Other International Definitions
=== Other International Definitions ===
European Definitions


ENISA uses the ISO definition, see below. [1]

Other International Definitions


The risk that remains in unmanaged form, even when effective disaster risk reduction measures are in place, and for which emergency response and recovery capacities must be maintained. [2]

According to UNISDR, the presence of residual risk implies a continuing need to develop and support effective capacities for emergency services, preparedness,response and recovery together with socio-economic policies such as safety nets and risk transfer mechanisms.

National Definitions


Risk that remains after implementing risk mitigation measures.

Risque qui subsiste après l’application de mesures d’atténuation du risque. [3]

Czech Republic

Zbytkové riziko: Riziko, které zůstává i po aplikaci příslušných opatření. [4]

Residual risk is the risk remaining even after an application of the appropriate measures. [5]

United States

Residual risk is risk that remains after risk management measures have been implemented. [6]

Standard Definition

ISO/IEC 27000:2014 and ISO 31000:2009

Risk remaining after risk treatment. [7] [8]

  • Residual risk can contain unidentified risk.
  • Residual risk can also be known as “retained risk”.

