Skip to content
Calcrivo

Vendor Risk Calculator

Tier a single vendor on data, access, criticality and spend, weigh the assurance evidence, and get residual risk plus a reassessment interval.

Inputs

$
%
subprocessors

Vendor Risk Verdict

Low — proceed with standard clauses and periodic review

Inherent Vendor Risk

3.50of 5

Assurance Evidence Score

78.8%

Residual Vendor Risk

1.57of 5

Share of the Maximum Score

31.4%

Reassessment Interval

24months

Assessment Tier

Tier 2 — significant vendor: full questionnaire plus certificate or report review

Largest Assurance Gap

Assurance evidence is adequate for this tier

Step by step

  1. Values used

    Most sensitive data the vendor handles = 4 — Personal data; Access the vendor holds = 3 — SaaS holding our data; Criticality to your operations = 4 — Critical, replacement takes months; Annual contract value = 480,000 $; Independent assurance held = One current certificate or report — 75; Security questionnaire score = 72 %; Independent penetration test evidence provided = Yes; Subprocessors disclosed behind this vendor = 6 subprocessors; Publicly known breach in the last three years = No

  2. Vendor Risk

    Inherent vendor risk = 0.30 × data class + 0.25 × access type + 0.25 × operational criticality + 0.10 × spend band + 0.10 × subprocessor band, on 1–5.

  3. Assurance and residual

    Residual = inherent × (1 − 0.7 × assurance score) × 1.2 if there is a known breach, where assurance = 0.4 × certification + 0.4 × questionnaire + 0.2 × penetration test evidence.

  4. Vendor Risk Verdict

    = Low — proceed with standard clauses and periodic review

  5. Inherent Vendor Risk

    = 3.50 of 5

  6. Assurance Evidence Score

    = 78.8

  7. Residual Vendor Risk

    = 1.57 of 5

  8. Share of the Maximum Score

    = 31.4

  9. Reassessment Interval

    = 24 months

How it works

Tiering is driven by data and access rather than by spend, because a cheap tool with an API token in your production tenant outranks an expensive one that never touches your data. Assurance evidence is capped at 70% effectiveness since a certificate describes a scope you did not choose, at a date that has passed, and a questionnaire is only as good as the evidence behind the answers. Vendor tiering decides how much diligence each supplier gets, and getting the tier wrong is how a low-spend integration ends up with unmonitored privileged access. This is a management estimate to prioritise diligence, not an assurance opinion on the vendor.

Formulas

Vendor Risk

Inherent vendor risk = 0.30 × data class + 0.25 × access type + 0.25 × operational criticality + 0.10 × spend band + 0.10 × subprocessor band, on 1–5.

data class
Most sensitive data the vendor touches
access type
From no access through to privileged network access
subScore
Subprocessor count banded, because their supply chain is now yours

Assurance and residual

Residual = inherent × (1 − 0.7 × assurance score) × 1.2 if there is a known breach, where assurance = 0.4 × certification + 0.4 × questionnaire + 0.2 × penetration test evidence.

assurance
Independent evidence outweighs self-attestation
0.7
Even perfect evidence cannot remove more than 70% of the inherent risk, because it is a point-in-time view of someone else's estate

Frequently Asked Questions

How is Vendor Risk calculated?

Inherent vendor risk = 0.30 × data class + 0.25 × access type + 0.25 × operational criticality + 0.10 × spend band + 0.10 × subprocessor band, on 1–5. Tiering is driven by data and access rather than by spend, because a cheap tool with an API token in your production tenant outranks an expensive one that never touches your data. Assurance evidence is capped at 70% effectiveness since a certificate describes a scope you did not choose, at a date that has passed, and a questionnaire is only as good as the evidence behind the answers.

Why does Vendor Risk matter?

Vendor tiering decides how much diligence each supplier gets, and getting the tier wrong is how a low-spend integration ends up with unmonitored privileged access. This is a management estimate to prioritise diligence, not an assurance opinion on the vendor.

What values do I need to enter?

This calculator takes 9 inputs: Most sensitive data the vendor handles, Access the vendor holds, Criticality to your operations, Annual contract value, Independent assurance held, Security questionnaire score, Independent penetration test evidence provided, Subprocessors disclosed behind this vendor, Publicly known breach in the last three years. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is a SOC 2 report enough on its own?

Only after you have read it. Check the scope, the trust services categories, the observation period and the exceptions — a report scoped to one product with a three-month window and four exceptions is not the assurance the cover page implies. The report answers questions about their controls, not about the service you are buying.

Why do subprocessors affect the score?

Because your data goes where they send it. Every subprocessor is a fourth party you have no contract with, and concentration behind several of your vendors — the same cloud region, the same email provider — creates correlated failures that vendor-by-vendor assessment never surfaces.

You might also need