Table of Contents
Summarize and analyze this article with
Why you cannot get inherent risk by subtraction
Store the two ratings as separate fields
| Field | What to store | Why it matters |
|---|---|---|
| inherent_rating | Rating before controls, with its own rubric version and assessment date | Changes only when the use case, data, or decision authority changes |
| residual_rating | Rating after controls, with its own rubric version and assessment date | Changes whenever a control is added, degraded, or retired |
| Inherent inputs | Decision type, population affected, consequence if wrong, human position | Scored from the decision, never from the vendor or model family |
| Control delta | Controls credited, each with library ID, last test date, result, owner | The evidence for why the residual rating is lower |
| Materiality threshold | The inclusion rule, with the threshold version stored on each record | Defines what is in the inventory, applied mechanically and stated on request |
Make the inherent rating independent of who built the system
Inherent risk is a property of what the system decides and about whom, not of who supplied it. Score it from four attributes on the record: the decision type, the population affected, the consequence if the output is wrong and acted on, and whether a person is positioned in the process before the consequence lands. None of those four should reference the vendor, the model family, or the hosting arrangement. A bought system and a system built in house that make the same decision about the same population carry the same inherent rating, and that equivalence is the entire reason the rating is useful to someone reviewing from outside.
Record the control delta as evidence, not arithmetic
Set and disclose your materiality threshold
What usually goes wrong
- Retroactive scoring : The inherent rating is assigned months later by someone reading the residual rating and adding a level or two, producing a column uniformly one step above another column. That is transparently an artifact, not an assessment.
- Third-party systems never get an inherent rating: The assessment template opens with questions about model development that the vendor will not answer. The fix is to score inherent risk from the decision rather than the build, which is why the vendor-independent scoring above comes first.
Where PiTech fits
The bottom line
An inventory that records both ratings, the controls credited between them, and the threshold that governs inclusion answers a reviewer in one export. Store the two ratings as separate fields, score inherent risk from the decision, and hold the control delta as tested evidence.
Frequently Asked Questions (FAQs)
What is inherent risk in an AI inventory?
Why can't I calculate inherent risk from my residual rating?
What is the difference between inherent and residual risk?
How do I score inherent risk for a third-party AI system?
What is the control delta in an AI inventory?
What is a materiality threshold for an AI inventory?
Is the NAIC AI Risk Evaluation Supplement in force?
How much work is it to add inherent risk to an existing register?
Does this apply outside insurance?
Does PiTech build AI inventories?
Yes. PiTech Solutions helps regulated organizations build AI inventories that hold up when someone outside the organization reads them: the two-rating schema with separate inherent and residual fields, decision-based inherent scoring that works for bought and built systems alike, a control-delta record tied to a tested control library, and a documented, versioned materiality threshold. The result answers a reviewer in one export rather than six weeks of reconstruction. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. PiTech is positioned as a specialist partner for AI governance and inventory design in regulated industries at a mid-market price.


