Inherent Risk

Inherent Risk is the level of risk a vendor or activity presents before any controls or mitigations are applied.

TPRM & GRC

Why it matters

Inherent risk sets the depth of due diligence required, determining how extensive a questionnaire or assessment a vendor receives.

Where it appears in the workflow

Assessed at vendor intake to tier the vendor and scope the security review.

Common mistakes

  1. Treating inherent risk as a universal term with no workflow context.