Skip to content
Calcrivo

Third-Party Risk Calculator

Score a whole third-party risk programme: assessment coverage, provider concentration, fourth-party visibility, audit rights and remediation speed.

Inputs

vendors
vendors
vendors
vendors
%
%
%
incidents
days

TPRM Programme Score

56.2%

Critical Vendor Assessment Coverage

85.7%

Overall Assessment Coverage

61.8%

Critical Vendors Not Assessed

6vendors

Vendor Incident Rate

0.88%

Remediation Speed Score

17.8%

Grade

D — Weak

Concentration Verdict

Watch — a material share of critical service depends on one provider, so exit and failover planning matter more than questionnaires

Weakest Programme Element

Assessment coverage of critical vendors — the ones that matter are being missed

Step by step

  1. Values used

    Third parties in the register = 340 vendors; Third parties rated critical = 42 vendors; Third parties assessed in the last 12 months = 210 vendors; Critical third parties assessed in the last 12 months = 36 vendors; Share of critical service resting on one provider = 38 %; Critical vendors whose subprocessors you can name = 25 %; Critical contracts carrying audit and evidence rights = 55 %; Vendor-caused incidents in the last 12 months = 3 incidents; Mean time for a vendor to close an agreed finding = 74 days

  2. Third-Party Risk

    Programme score = 0.30 × critical vendor coverage + 0.15 × overall coverage + 0.15 × (100 − concentration) + 0.15 × fourth-party visibility + 0.10 × audit rights + 0.15 × remediation speed.

  3. TPRM Programme Score

    = 56.2

  4. Critical Vendor Assessment Coverage

    = 85.7

  5. Overall Assessment Coverage

    = 61.8

  6. Critical Vendors Not Assessed

    = 6 vendors

  7. Vendor Incident Rate

    = 0.88

  8. Remediation Speed Score

    = 17.8

How it works

Coverage of critical vendors is weighted twice as heavily as overall coverage, because assessing three hundred low-risk suppliers while six critical ones go unvisited is the most common failure mode in third-party risk. Concentration and fourth-party visibility are scored as programme attributes rather than vendor attributes, since neither is visible from any single assessment. Regulators now ask about concentration and exit planning, not just about questionnaires, and the honest answer usually depends on whether anyone has counted. This is a programme-level management estimate, not an assurance conclusion about any individual vendor.

Formula

Third-Party Risk

Programme score = 0.30 × critical vendor coverage + 0.15 × overall coverage + 0.15 × (100 − concentration) + 0.15 × fourth-party visibility + 0.10 × audit rights + 0.15 × remediation speed.

critical coverage
Critical vendors assessed in 12 months ÷ critical vendors
concentration
Share of critical service on a single provider, inverted so diversification scores well
remediation speed
100 − (mean days ÷ 90) × 100, so 90 days scores zero

Frequently Asked Questions

How is Third-Party Risk calculated?

Programme score = 0.30 × critical vendor coverage + 0.15 × overall coverage + 0.15 × (100 − concentration) + 0.15 × fourth-party visibility + 0.10 × audit rights + 0.15 × remediation speed. Coverage of critical vendors is weighted twice as heavily as overall coverage, because assessing three hundred low-risk suppliers while six critical ones go unvisited is the most common failure mode in third-party risk. Concentration and fourth-party visibility are scored as programme attributes rather than vendor attributes, since neither is visible from any single assessment.

Why does Third-Party Risk matter?

Regulators now ask about concentration and exit planning, not just about questionnaires, and the honest answer usually depends on whether anyone has counted. This is a programme-level management estimate, not an assurance conclusion about any individual vendor.

What values do I need to enter?

This calculator takes 9 inputs: Third parties in the register, Third parties rated critical, Third parties assessed in the last 12 months, Critical third parties assessed in the last 12 months, Share of critical service resting on one provider, Critical vendors whose subprocessors you can name, Critical contracts carrying audit and evidence rights, Vendor-caused incidents in the last 12 months, Mean time for a vendor to close an agreed finding. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

How is this different from assessing a single vendor?

A vendor assessment asks whether one supplier is safe enough. This asks whether the programme is working: are the right vendors being looked at, do you know who sits behind them, can you get evidence when you need it, and does anything actually get fixed. A portfolio of well-assessed vendors can still be one region outage away from a full stop.

What is fourth-party risk?

Your vendors' vendors. You have no contract with them, usually no visibility, and yet a failure there reaches you through a supplier who is themselves a victim. The practical minimum is knowing the subprocessors behind your critical vendors and where they concentrate.

You might also need