The problem
Most risk assessments end with a residual risk: the level of risk expected once controls are in place. In practice, that figure often mixes two very different things. Some controls already exist and work. Others are still plans: a guard to be fitted, a procedure to be written, training to be delivered.
When both are combined into a single residual rating, the assessment shows a lower risk than the workplace actually has. The document looks finished. The risk reduction has not happened yet.
Why it matters
Decisions are made on the residual figure. Work is accepted, priorities are set and resources are allocated according to it. If that figure assumes controls that do not yet exist, people are accepting a risk level that is not real.
The gap is rarely deliberate. Planned controls are written down in good faith, then delayed, changed or forgotten. Meanwhile the assessment continues to show the target as though it had been reached. Months later, an auditor or investigator finds the "residual" risk was never achieved.
A practical approach
It helps to treat risk reduction as a chain, with a separate record at each stage:
Current risk. The risk with the controls that are actually in place today.
Planned controls. The additional controls needed, each with a clear description and, where possible, its place in the hierarchy of controls.
Target residual risk. The risk the team expects once those planned controls are implemented. This is a forecast.
Implementation. Each planned control becomes an action with a responsible person and a target date.
Action verification. Someone checks that the action was actually completed as intended, not just marked as closed.
Verified residual risk. Only after the controls are verified is the residual risk re-assessed and recorded as achieved.
Keeping these stages separate gives everyone an honest picture. A manager can see how much risk reduction is planned, how much has been delivered and how much has been confirmed.
Two practical habits support this. First, do not record verified residual risk while any relevant action is still open or unverified. Second, re-assess rather than copy: the verified rating should reflect what was found when the controls were checked, which may differ from the original target.
What a good system should provide
A good risk assessment system should make the distinction structural rather than relying on discipline alone. It should:
Store current, target and verified residual risk as separate values.
Link planned controls to actions with owners, dates and status.
Distinguish completion from verification.
Prevent verified residual risk from being recorded until the related actions are completed and verified.
Keep revision history, so it is clear when each value was recorded and by whom.
How Sospita addresses it
Sospita applies this chain in two separate products.
Sospita Risk Assessment, the local-first mobile app, records current, target residual and verified residual risk as three distinct views. Actions carry a responsible person, target date, status and verification, and overdue actions are flagged. Verified residual risk cannot be recorded until every active action is both Completed and Verified. Previous revisions remain read-only, and the PDF report includes the revision register. The choice of method behind these ratings is discussed in Risk Matrix, Fine-Kinney or FMEA: Which Method Fits the Assessment?.
The HSE Platform Risk Assessment module, an online, multi-user module of the Sospita HSE Platform, follows the same principle for teams. Current and target residual risk are calculated on the server. Planned controls become shared Actions, and residual risk is verified once those actions have been carried out and checked. Assessment revisions pass through a configurable check, review and approval workflow, and finalised revisions are locked.
Both are currently listed as coming soon.
Limitations and human responsibility
A system can stop verified residual risk from being recorded too early. It cannot judge whether a control is adequate.
Verification is still a human activity. Someone must look at the guard, read the procedure or confirm the training, and decide whether it does what it was meant to do. A ticked verification box is only as reliable as the check behind it.
A verified control also does not guarantee that the risk is now acceptable. Conditions change, and controls degrade. Verified residual risk is a point-in-time judgement that should be revisited through periodic review.
The responsibility for accepting residual risk remains with competent people and the organisation, not with the software that records it.