Inherent task risk versus safeguards
Inherent risk describes the task before controls; safeguards do not erase that underlying consequence.
The practical distinction
Inherent risk describes the task before controls; safeguards do not erase that underlying consequence. Inherent risk asks what could happen if the task is wrong before controls. Safeguards change whether and how a workflow may proceed; they do not rewrite a consequential task as low risk.
Worked example
A human approval step may reduce the chance of a harmful contract action, but the underlying legal consequence remains high. The review must therefore be qualified, evidence-based, and able to stop the action.
Apply it
State risk and controls separately so a safe process is not mistaken for a low-risk task.
- Describe the plausible consequence without crediting proposed controls.
- Assign the risk band from that consequence and affected people or systems.
- Select controls, autonomy, and evaluation depth appropriate to the unchanged inherent risk.
Evidence to collect
- Verify that the same task retains its band when a control is added or removed.
- Test whether the reviewer can actually detect the important failure before harm.
- Record residual uncertainty without claiming that the methodology certifies residual risk.
Common mistake
Lowering the risk label because approval, logging, or a disclaimer exists, even when the possible consequence is unchanged.
Scope limit
This guidance on inherent task risk versus safeguards helps define a task and its review evidence. It does not certify a model, source, reviewer, environment, legal position, or residual-risk level.
