Inherent risk

Inherent risk is a key measure of risk before any treatment or mitigation efforts have been applied. It indicates how badly an organization would be impacted if a risk were to materialize and offers a baseline understanding of the problem. 

Understanding Inherent Risk with example

Imagine you’re planning a picnic in the park. The inherent risk here is the chance of it raining, which would naturally ruin the outdoor event. This risk exists simply because of the unpredictable nature of weather, before you even think about checking the forecast or planning a backup indoor location. It’s a basic, unmanaged risk that comes with the decision to have an outdoor event.

Business Impact: The term “business impact” refers to the consequences or effects that the risk might have on the organization’s operations, financial health, reputation, or overall success. 


Minimal if any operational impact, negligible costs


Noticeable but limited operational impact, some costs


Substantial operational impact, very costly


Severe loss of operational capability, highly damaging and extremely costly but survivable


Complete operational failure, “bet the farm” impact, unsurvivable

Likelihood: The term “likelihood” refers to the probability or chance that a particular risk will be passed down or inherited from one phase, department, or process to another within a business or project.

Very Unlikely

Although they are conceivable, we will probably never experience incidents of this nature


Incidents of this nature are uncommon but there is a genuine chance that we may experience them at some future point


It is distinctly possible that we will experience incidents of this nature


We are likely to experience incidents of this nature before long

Very Likely

We are bound to experience further incidents of this nature – in fact they are probably occurring right now!

After inputting those scores, the ‘Inherent Risk Rating’ will be calculated, giving you the untreated or inherent level of risk.

The following screenshot shows the inherent risk section.

