Residual Risk
The harm that remains after your controls have done their work: the errors a threshold still lets through, the failure mode an eval measured and could not remove, the segment where reliability is lowest. It never reaches zero, so it is always accepted by somebody; the governance question is whether that acceptance was a considered decision or a default.
Defined in 6 GAGE programs, which carry 15 distinct definitions of it. The wording above is taught in AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
The harm that remains after your controls have done their work: the errors a threshold still lets through, the failure mode an eval measured and could not remove, the segment where reliability is lowest. It never reaches zero, so it is always accepted by somebody; the governance question is whether that acceptance was a considered decision or a default.
A known, unaddressed weakness that an organization has chosen, deliberately, not to fully remediate right now, because of cost, competing priorities, or business impact. Defensible only when documented explicitly, with a named person who accepted the risk and, where possible, a review date; indistinguishable from an undiscovered gap when left silent.
The risk that remains after elimination and engineering controls have reduced a hazard as far as reasonably achievable. A well-designed workcell still carries some residual risk; the correct practice is to document and manage it explicitly rather than claim a false zero.
The risk that remains after mitigations are applied. A complete assessment names the highest residual Risk Priority, the person who accepts it, and the review date; the EU AI Act requires acceptable residual risk for high-risk systems (Article 9).
The risk that remains after compensating controls have been applied, distinct from risk that has been closed at its root cause. A governance record should name residual risk explicitly rather than implying a compensating control has eliminated it.
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- Risk Assessment in AI Decisions · Critical Thinking and Context Engineering, AI Literacy & Professional Conduct
- Building Your Context Engineering Portfolio: Capstone Project · Critical Thinking and Context Engineering, AI Literacy & Professional Conduct
- The Parts That Make an Agent Act · The Agent, Deconstructed, Agentic AI Governance: Applied Mastery
- What to Test · Testing and Red-Teaming, Agentic AI Governance: Applied Mastery
- Testing What You Did Not Build · Testing and Red-Teaming, Agentic AI Governance: Applied Mastery
- Pass, Fail, or Accept · Testing and Red-Teaming, Agentic AI Governance: Applied Mastery
- Governance that survives: rebuilding the estate's defenses so the next attack finds less · Adversarial Data Governance, AI Data Governance: The Data Chair
- Fixing the model, breaking it again: why fixes are never free · Build Before You Govern, AI Governance: Applied Mastery
- Third-party data and the vendor claims you must verify yourself · Data Reality, AI Governance: Applied Mastery
- The trust boundary: what this system may decide alone and where a human signs · Evaluation and Trust, AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.