Strunk
  • Compliance
  • Profitability
    • Pricing Manager
    • Overdraft Privilege
    • Econocheck
  • Connect
    • The Strunk Perspective
    • Contact Us
  • Login
  • DEMO
  • Menu Menu
  • X
  • LinkedIn

Residual Risk Explained

April 21, 2021/in Sales, Vendor Manager/by Joel Lawrence

Having a well maintained vendor management program will allow you to build relationships with your vendors, while also strengthening your business. Understanding your vendors’ residual risk is a key piece of your vendor management program and it will let you know the amount of risk or danger associated with a vendor’s action after controls are accounted for.

To understand Residual Risk we need to first understand Inherent Risk.  Inherent Risk is typically defined as the amount of risk that the vendor has in the absences of controls.  Any time a financial institution uses a third party to provide a service or product, the financial institution needs to complete a risk assessment so they can understand the criticality of the risk that vendor will have.  Inherent risk is established only after the vendor’s key objectives have been defined, and steps have been taken to identify what could go wrong to prevent the vendor from achieving those objectives.  In addition to impact and likelihood, management must consider the nature of the risk also.

Once the Inherent Risk of the vendor is established and the financial institution recognizes the criticality of the risk, then the financial institution must realize what controls the vendor has in place to help mitigate or reduce the risk that the vendor has.  Once the controls have been assessed they should also be tested to ensure that they are operating efficiently.  Testing the controls provides confidence that they actually reduce risk to a tolerable level.

Finally, we are able to take a look at residual risk.  Residual risk is the amount of risk associated with each vendor remaining after inherent risks have been reduced by controls that the vendor has in place.  When controls are weak, not in place, or not functioning properly then residual risk will be high.  If vendor residual risk is high then a corrective action plan needs to be put in place on how the vendor is going to strengthen those controls or management should seek out other vendors who can provide the product or service to the financial institution.

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://strunkaccess.com/wp-content/uploads/2021/04/risk-1945683_1280.jpg 853 1280 Joel Lawrence https://strunkaccess.com/wp-content/uploads/2022/03/Strunk-Original-300x100.png Joel Lawrence2021-04-21 10:00:052021-05-01 01:17:03Residual Risk Explained

Recent Articles

  • Banks Can Increase Customer Satisfaction & Fee Income at the Same TimeMay 7, 2025 - 10:00 am
  • Options for ODP Manager AccessApril 24, 2025 - 10:00 am
  • How can Strunk’s Vendor Manager software support your organization’s Third-Party Risk Management process?April 9, 2025 - 10:00 am
  • Bankers Look for Ways to Make More MoneyApril 2, 2025 - 10:00 am

GRC Topics

  • Banks
  • COCC
  • Compliance
  • Credit Unions
  • Financial Services
  • FINSYNC
  • Markets
  • Overdraft Privilege
  • Perspectives
  • Policy Manager
  • Pricing Manager
  • Risk Manager
  • Sales
  • Secure Checking
  • SOC2
  • Tips
  • Uncategorized
  • Vendor Manager
  • WBA
Schedule A Demo

An independent certified public accountant has examined Strunk’s operations and found them to be in compliance with the AICPA’s Trust Service Principles. It was determined that Strunk meets the Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria for SOC 2 established by the AICPA.

© Copyright - Strunk | Privacy Policy | Security Policy | Business Continuity Policy
Scroll to top