Skip to main content

Residual Risk

The harm that remains after your controls have done their work: the errors a threshold still lets through, the failure mode an eval measured and could not remove, the segment where reliability is lowest. It never reaches zero, so it is always accepted by somebody; the governance question is whether that acceptance was a considered decision or a default.

Defined in 6 GAGE programs, which carry 15 distinct definitions of it. The wording above is taught in AI Governance: Applied Mastery.

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

AI Governance: Applied Mastery

The harm that remains after your controls have done their work: the errors a threshold still lets through, the failure mode an eval measured and could not remove, the segment where reliability is lowest. It never reaches zero, so it is always accepted by somebody; the governance question is whether that acceptance was a considered decision or a default.

AI Data Governance: The Data Chair

A known, unaddressed weakness that an organization has chosen, deliberately, not to fully remediate right now, because of cost, competing priorities, or business impact. Defensible only when documented explicitly, with a named person who accepted the risk and, where possible, a review date; indistinguishable from an undiscovered gap when left silent.

Engineering Judgment and Professional Formation

The risk that remains after elimination and engineering controls have reduced a hazard as far as reasonably achievable. A well-designed workcell still carries some residual risk; the correct practice is to document and manage it explicitly rather than claim a false zero.

AI Literacy & Professional Conduct

The risk that remains after mitigations are applied. A complete assessment names the highest residual Risk Priority, the person who accepts it, and the review date; the EU AI Act requires acceptable residual risk for high-risk systems (Article 9).

Agentic AI Governance: Applied Mastery

The risk that remains after compensating controls have been applied, distinct from risk that has been closed at its root cause. A governance record should name residual risk explicitly rather than implying a compensating control has eliminated it.

Where it is taught

The exact lessons this term appears in. The first 7 topics of every program are free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.