Score a whole third-party risk programme: assessment coverage, provider concentration, fourth-party visibility, audit rights and remediation speed.
Coverage of critical vendors is weighted twice as heavily as overall coverage, because assessing three hundred low-risk suppliers while six critical ones go unvisited is the most common failure mode in third-party risk. Concentration and fourth-party visibility are scored as programme attributes rather than vendor attributes, since neither is visible from any single assessment. Regulators now ask about concentration and exit planning, not just about questionnaires, and the honest answer usually depends on whether anyone has counted. This is a programme-level management estimate, not an assurance conclusion about any individual vendor.
Third-Party Risk
Programme score = 0.30 × critical vendor coverage + 0.15 × overall coverage + 0.15 × (100 − concentration) + 0.15 × fourth-party visibility + 0.10 × audit rights + 0.15 × remediation speed.
Programme score = 0.30 × critical vendor coverage + 0.15 × overall coverage + 0.15 × (100 − concentration) + 0.15 × fourth-party visibility + 0.10 × audit rights + 0.15 × remediation speed. Coverage of critical vendors is weighted twice as heavily as overall coverage, because assessing three hundred low-risk suppliers while six critical ones go unvisited is the most common failure mode in third-party risk. Concentration and fourth-party visibility are scored as programme attributes rather than vendor attributes, since neither is visible from any single assessment.
Regulators now ask about concentration and exit planning, not just about questionnaires, and the honest answer usually depends on whether anyone has counted. This is a programme-level management estimate, not an assurance conclusion about any individual vendor.
This calculator takes 9 inputs: Third parties in the register, Third parties rated critical, Third parties assessed in the last 12 months, Critical third parties assessed in the last 12 months, Share of critical service resting on one provider, Critical vendors whose subprocessors you can name, Critical contracts carrying audit and evidence rights, Vendor-caused incidents in the last 12 months, Mean time for a vendor to close an agreed finding. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
A vendor assessment asks whether one supplier is safe enough. This asks whether the programme is working: are the right vendors being looked at, do you know who sits behind them, can you get evidence when you need it, and does anything actually get fixed. A portfolio of well-assessed vendors can still be one region outage away from a full stop.
Your vendors' vendors. You have no contract with them, usually no visibility, and yet a failure there reaches you through a supplier who is themselves a victim. The practical minimum is knowing the subprocessors behind your critical vendors and where they concentrate.