Inherent, residual, and the rating that gets reported
Two numbers, frequently confused, describing different things.
Registers commonly record a rating before controls and a rating after them. The first describes the exposure if nothing were done, the second what remains given the controls in place. Both are useful and reporting the wrong one produces systematically misleading pictures.
The residual rating is the honest description of current exposure and it depends entirely on the controls actually operating, which is an assumption rather than a fact. A residual rating calculated on controls that exist on paper but are not performed is not a lower risk, it is the inherent risk with an optimistic label.
This is why control assurance matters more than reassessment. Confirming that a control is actually operating, by looking at the evidence it produces, is what makes a residual rating meaningful, and it is skipped far more often than the rating is revised.
The reporting convention is worth setting deliberately. An organisation that reports only residual ratings will show a comfortable profile and lose sight of how much of that comfort depends on controls continuing to work, which is precisely the assumption that fails during a disruption.
There is a practical way to make control assurance affordable, which is to test a small number of controls properly each quarter rather than reviewing all of them nominally each year. Choosing the ones the organisation most depends on, and looking at the evidence they actually produce, gives real information about a few. Reviewing everything by asking whether it is still in place gives no information about any.