Residual risk is what remains after controls are in place. For example, even after a vendor encrypts data, enforces access controls and holds SOC 2, some small chance of a breach still exists, and that leftover exposure is the residual risk. The aim is to reduce it to a level your organization is willing to accept.
