Control Effectiveness
Add the risks. Add the controls. Slide each control's effectiveness and watch residual risk fall.
Portfolio inherent
0
Sum of likelihood × impact across every risk.
Portfolio residual
0
What's left after every control is applied.
Reduction
0%
How much of the inherent risk your controls remove.
Risks and controls
Inherent vs residual, by risk
| Risk | Inherent | Residual | Reduction |
|---|
How this calculator thinks about risk
The math, in one paragraph
Each risk is scored on the standard 5x5 ERM heat map: likelihood (1-5) x impact (1-5) gives an inherent score from 1 to 25. Each control on that risk has an effectiveness percentage (0-100%). Residual risk is computed multiplicatively: each control acts independently on what's left after the previous control.
residual = inherent × ∏ (1 − effectivenessi / 100)
Three controls at 60% effectiveness each leave 0.4 x 0.4 x 0.4 = 6.4% of the original risk, not zero, even though the percentages would naively add to 180%. That is the practitioner's default and the conservative read.
What the effectiveness label means
The slider also surfaces a qualitative tier so a non-technical reader does not have to translate percentages in their head:
- Ineffective (0-33%): the control is absent, broken, or not meaningfully reducing risk.
- Partially Effective (34-66%): the control exists and works, but has gaps: coverage holes, inconsistent execution, or known workarounds.
- Effective (67-100%): the control functions as designed and is exercised consistently. Not a guarantee, but the level you can defend in an audit.
These are the same three bands used in most ERM/audit frameworks (COSO, COBIT, ISO 31000 in spirit). They are a translation layer, not a replacement for the percentage. The math underneath always uses the precise value.
Where the model is honest, and where it is not
- Honest: defense-in-depth almost never zeroes risk out. Multiplicative residual reflects that.
- Simplification: controls are assumed to act independently. In reality they often correlate (two controls run by the same team that loses budget at the same time, for instance). Real GRC platforms handle this with control families and dependency mapping. This calculator does not.
- Simplification: a control here belongs to one risk. In practice a single control (say MFA) reduces several risks. That is a many-to-many model. Possible, but a much bigger lift. This version keeps controls owned by their parent risk.
What the export gives you
Export PNG writes the chart exactly as drawn, suitable for slides or a status report. Export CSV writes the underlying rows (risk name, inherent, residual, reduction) for analysis in Excel, Sheets, or a GRC system.
Security and privacy
Everything you type stays in your browser tab. Nothing is sent to a server, written to disk, or saved across reloads. Refresh the page and you are back to the three example risks.