Residual risk is what is left after every mitigation has been applied. Controls reduce risk or move it somewhere else; none of them delete it. What an investor or a board needs is not the list of controls you built, it is the exposure that survived them, stated in one sentence with a size and a trigger attached.
A team that cannot name its largest residual risk has either not run the analysis or does not want to share the result. The reader prices for the worse of those two, which is almost always worse than the truth.
Gross, control, residual
Every vector from the adversarial pass starts with a gross rating: likelihood and impact before any control exists. Apply the control, re-rate both, and the second pair is the residual. The distance between the two ratings is the only evidence that the control does real work. If gross and residual come out identical, what got written down was a policy rather than a control.
None of that vocabulary was invented for crypto. It is the ordinary language of enterprise risk assessment, and the two reference points a board will recognize are NIST's guide for conducting risk assessments1 and COSO's enterprise risk management guidance.2 We use the vocabulary because it travels. We do not certify a token design as conforming to either framework, and no tokenomics document should claim that it does.
Controls relocate risk more often than they remove it
Replace a single admin key with a 3-of-5 multisig and single key compromise is gone, replaced by signer collusion and key custody spread across five people. Add an execution delay and instant unilateral change is gone, replaced by a public window in which a known bad transaction sits queued and nothing stops it unless someone holds a veto. Move an oracle to a time weighted average and single block manipulation is gone, replaced by latency, which in a fast drawdown is its own exposure.
Every one of those trades is defensible. None is free, and the residual line is where the price shows up. Founders who present the control without the trade are usually not hiding anything. They stopped the analysis one step early, and a diligence team will finish it for them in a less flattering way.
How to state it to an investor or a board
One sentence per residual, carrying four things: the exposure, the condition that triggers it, the size if it triggers, and what happens next. Written out, with illustrative numbers standing in for whatever your own model produces: "Our largest residual is oracle latency in thin depth. If the pair's depth falls below the level the model assumes and the feed lags a sharp move, undercollateralized positions can open before liquidation clears. We cap it with a deviation circuit breaker and a per block borrow limit, and the worst case the simulation produced is four percent of the lending pool." That is a sentence a risk committee can interrogate.
Compare it with "we have mitigated all identified risks," which tells a board nothing and reads as either careless or evasive. EY's token due diligence framework makes the same point from the other side of the table: once the mitigants are counted, residual risk is what an investor evaluates against their own risk appetite.3 You cannot hand them that judgment if you have not written the residual down.
Sizing it without predicting anything
Residual risk gets a size, and the size is conditional. Percentage of the pool, percentage of circulating supply, days of treasury runway, holders affected, hours until the position is unrecoverable. Not a price and not a date.
That distinction keeps the exercise inside what we are willing to publish. "If this triggers, up to X of Y is exposed" is a statement about a mechanism you built and can prove. A number attached to where the token trades is a statement about the market, which nobody can prove and which we do not put in client documents. The first is analysis. The second is a forecast, and it belongs in neither a risk register nor a deck.
Where residual risk goes to die
The legal annex. Residual risk written into the offering documents and nowhere else is a disclaimer, drafted to protect the issuer and read once, at signing. It changes nothing about the design.
Residual risk written into the mechanism design document is a design input. It is what the next revision has to reduce, it sets the thresholds in the post launch monitoring framework, and it tells a new hire why a parameter sits where it does. Across the 100+ projects we have advised, the residuals carrying a named owner and a monitoring metric are the ones that get revisited. The ones carrying only a paragraph do not.
Common questions
What is the difference between inherent risk and residual risk?
Inherent risk, also called gross risk, is the likelihood and impact of a threat before any control is applied. Residual risk is the same pair re-rated after the control is in place. Both get recorded, because the gap between them is the evidence that the control works. A control that leaves the two ratings identical has not reduced anything, it has only been described.
How should residual risk be documented in a tokenomics report?
One row per vector, in the body of the document rather than an annex: exposure, trigger condition, conditional size, the control in place, a named owner, and the metric that would show it developing. Write the size as a share of the pool, of supply, or of treasury runway. Keep prices and dates out of it, since those turn a conditional statement into a forecast.
Can residual risk ever be zero?
No, and a document claiming it is will be read as a signal that the analysis was skipped. Controls trade one exposure for another rather than removing exposure entirely: a multisig trades key compromise for collusion, a timelock trades speed for a public queue. The useful question is not whether residual risk exists but whether the remaining exposure is sized, owned and monitored.
See Tokenomics Audit Services for how this applies in practice.
Sources
- SP 800-30 Rev. 1, Guide for Conducting Risk Assessments
National Institute of Standards and Technology, Computer Security Resource Center
The U.S. federal reference for structured risk assessment. Cited as the origin of the gross and residual vocabulary, not as a standard this work is certified against. - Enterprise Risk Management guidance
Committee of Sponsoring Organizations of the Treadway Commission (COSO), 2026
COSO's current enterprise risk management guidance hub, the other reference a board audit committee will already know. Read 3 August 2026. - Token due diligence: a structured approach to evaluate digital asset risk
EY, 2024
Frames residual risk as what remains after mitigants such as audits, KYC and AML controls and market surveillance, to be evaluated against the investor's risk appetite.
Last reviewed 2026-08
Know the terms but not sure how they apply to your project? That is what an engagement is for. We design, document, and stress-test the whole token economy inside the Tokenomics Data Room.
100+ projects advised. Complete tokenomics in 4 to 6 weeks.