Inherent risk

The likelihood and severity rating of a risk scenario before any control is counted. The gap between inherent and residual risk is the value claimed for the controls, and must be backed by their evidence 1.

Developed in
ch. 13, Inherent risk, residual risk and who accepts it
Chapters
ch. 13, Risk Management
Contrast with
Residual risk
Source
1 numbered reference, listed below

Where it is used

One chapter of the Body of Knowledge uses the term. Each link opens the first section that does.

Sources

  1. [1] Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (risk tolerance and residual risk; seven trustworthy characteristics; transparency answers "what happened", explainability "how", interpretability "why"; MAP 1.1 intended purposes; MANAGE 1.1 go/no-go determination; profiles). NIST. 2023-01-26. https://doi.org/10.6028/NIST.AI.100-1 (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Inherent risk. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/inherent-risk. CC BY 4.0

BibTeX

@misc{aige2026inherentrisk,
  author  = {Jorge García Aibar},
  title   = {{Inherent risk}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/inherent-risk}
}