Compare the recorded residual position with current control evidence.
Link the actual controls
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the intended risk and the panel described below.
Open the risk's Controls, choose Link a control and select a control that mitigates this risk. Record the percentage of exposure it covers, its relative weight and the rationale for the link.
A weight of zero retains a noted control without letting it affect the aggregate. An untested or stale control can leave effectiveness unknown. Retired controls remain visible but stop counting.

Interpret the challenge
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the intended risk and the panel described below.
Open Residual vs controls to compare Recorded and Supported by controls. The result can be supported, not supported, evidence has slipped or cannot be checked. Inspect the stated reason and tolerance rather than interpreting every difference as the same problem.
When a methodology's Residual scoring mode is Derived from controls, the residual score is calculated nightly from control effectiveness and cannot be entered by hand. See choose how residual scores are set.
Record a decision
Product location: /rms/risks/residual-challenges. Open the relevant residual challenge.
If the recorded residual remains justified by information outside the linked controls, use The recorded residual stands and explain that reasoning. The acknowledgement concerns the current disagreement; changed scores or controls can raise it again.
The Residual challenges register is based on a nightly check. Open a risk for its current position. If a control stopped operating, retire it rather than unlinking it merely to hide the effect. Unlinking is appropriate when the control does not mitigate this risk.