Third-Party Risk Calculator
Score a whole third-party risk programme: assessment coverage, provider concentration, fourth-party visibility, audit rights and remediation speed.
Inputs
TPRM Programme Score
56.2%
Critical Vendor Assessment Coverage
85.7%
Overall Assessment Coverage
61.8%
Critical Vendors Not Assessed
6vendors
Vendor Incident Rate
0.88%
Remediation Speed Score
17.8%
Grade
D — Weak
Concentration Verdict
Watch — a material share of critical service depends on one provider, so exit and failover planning matter more than questionnaires
Weakest Programme Element
Assessment coverage of critical vendors — the ones that matter are being missed
Step by step
Values used
Third parties in the register = 340 vendors; Third parties rated critical = 42 vendors; Third parties assessed in the last 12 months = 210 vendors; Critical third parties assessed in the last 12 months = 36 vendors; Share of critical service resting on one provider = 38 %; Critical vendors whose subprocessors you can name = 25 %; Critical contracts carrying audit and evidence rights = 55 %; Vendor-caused incidents in the last 12 months = 3 incidents; Mean time for a vendor to close an agreed finding = 74 days
Third-Party Risk
Programme score = 0.30 × critical vendor coverage + 0.15 × overall coverage + 0.15 × (100 − concentration) + 0.15 × fourth-party visibility + 0.10 × audit rights + 0.15 × remediation speed.
TPRM Programme Score
= 56.2
Critical Vendor Assessment Coverage
= 85.7
Overall Assessment Coverage
= 61.8
Critical Vendors Not Assessed
= 6 vendors
Vendor Incident Rate
= 0.88
Remediation Speed Score
= 17.8
How it works
Coverage of critical vendors is weighted twice as heavily as overall coverage, because assessing three hundred low-risk suppliers while six critical ones go unvisited is the most common failure mode in third-party risk. Concentration and fourth-party visibility are scored as programme attributes rather than vendor attributes, since neither is visible from any single assessment. Regulators now ask about concentration and exit planning, not just about questionnaires, and the honest answer usually depends on whether anyone has counted. This is a programme-level management estimate, not an assurance conclusion about any individual vendor.
Formula
Third-Party Risk
Programme score = 0.30 × critical vendor coverage + 0.15 × overall coverage + 0.15 × (100 − concentration) + 0.15 × fourth-party visibility + 0.10 × audit rights + 0.15 × remediation speed.
- critical coverage
- Critical vendors assessed in 12 months ÷ critical vendors
- concentration
- Share of critical service on a single provider, inverted so diversification scores well
- remediation speed
- 100 − (mean days ÷ 90) × 100, so 90 days scores zero
Frequently Asked Questions
How is Third-Party Risk calculated?
Programme score = 0.30 × critical vendor coverage + 0.15 × overall coverage + 0.15 × (100 − concentration) + 0.15 × fourth-party visibility + 0.10 × audit rights + 0.15 × remediation speed. Coverage of critical vendors is weighted twice as heavily as overall coverage, because assessing three hundred low-risk suppliers while six critical ones go unvisited is the most common failure mode in third-party risk. Concentration and fourth-party visibility are scored as programme attributes rather than vendor attributes, since neither is visible from any single assessment.
Why does Third-Party Risk matter?
Regulators now ask about concentration and exit planning, not just about questionnaires, and the honest answer usually depends on whether anyone has counted. This is a programme-level management estimate, not an assurance conclusion about any individual vendor.
What values do I need to enter?
This calculator takes 9 inputs: Third parties in the register, Third parties rated critical, Third parties assessed in the last 12 months, Critical third parties assessed in the last 12 months, Share of critical service resting on one provider, Critical vendors whose subprocessors you can name, Critical contracts carrying audit and evidence rights, Vendor-caused incidents in the last 12 months, Mean time for a vendor to close an agreed finding. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
How is this different from assessing a single vendor?
A vendor assessment asks whether one supplier is safe enough. This asks whether the programme is working: are the right vendors being looked at, do you know who sits behind them, can you get evidence when you need it, and does anything actually get fixed. A portfolio of well-assessed vendors can still be one region outage away from a full stop.
What is fourth-party risk?
Your vendors' vendors. You have no contract with them, usually no visibility, and yet a failure there reaches you through a supplier who is themselves a victim. The practical minimum is knowing the subprocessors behind your critical vendors and where they concentrate.
You might also need
- Business Continuity CalculatorCommonly used together
- Enterprise Risk Score CalculatorCommonly used together
- Vendor Risk CalculatorCommonly used together
- Residual Risk CalculatorAlso in Compliance & GRC
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC