A risk that remains after all efforts have been made to mitigate
or eliminate risks
associated with a business
process or investment
. After a risk assessment
, a residual risk may be known but not completely controllable, or, it may not be known. In either case, the residual risk is assumed by whoever owns
the investment or the business process.