Tier a single vendor on data, access, criticality and spend, weigh the assurance evidence, and get residual risk plus a reassessment interval.
Tiering is driven by data and access rather than by spend, because a cheap tool with an API token in your production tenant outranks an expensive one that never touches your data. Assurance evidence is capped at 70% effectiveness since a certificate describes a scope you did not choose, at a date that has passed, and a questionnaire is only as good as the evidence behind the answers. Vendor tiering decides how much diligence each supplier gets, and getting the tier wrong is how a low-spend integration ends up with unmonitored privileged access. This is a management estimate to prioritise diligence, not an assurance opinion on the vendor.
Vendor Risk
Inherent vendor risk = 0.30 × data class + 0.25 × access type + 0.25 × operational criticality + 0.10 × spend band + 0.10 × subprocessor band, on 1–5.
Assurance and residual
Residual = inherent × (1 − 0.7 × assurance score) × 1.2 if there is a known breach, where assurance = 0.4 × certification + 0.4 × questionnaire + 0.2 × penetration test evidence.
Inherent vendor risk = 0.30 × data class + 0.25 × access type + 0.25 × operational criticality + 0.10 × spend band + 0.10 × subprocessor band, on 1–5. Tiering is driven by data and access rather than by spend, because a cheap tool with an API token in your production tenant outranks an expensive one that never touches your data. Assurance evidence is capped at 70% effectiveness since a certificate describes a scope you did not choose, at a date that has passed, and a questionnaire is only as good as the evidence behind the answers.
Vendor tiering decides how much diligence each supplier gets, and getting the tier wrong is how a low-spend integration ends up with unmonitored privileged access. This is a management estimate to prioritise diligence, not an assurance opinion on the vendor.
This calculator takes 9 inputs: Most sensitive data the vendor handles, Access the vendor holds, Criticality to your operations, Annual contract value, Independent assurance held, Security questionnaire score, Independent penetration test evidence provided, Subprocessors disclosed behind this vendor, Publicly known breach in the last three years. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Only after you have read it. Check the scope, the trust services categories, the observation period and the exceptions — a report scoped to one product with a three-month window and four exceptions is not the assurance the cover page implies. The report answers questions about their controls, not about the service you are buying.
Because your data goes where they send it. Every subprocessor is a fourth party you have no contract with, and concentration behind several of your vendors — the same cloud region, the same email provider — creates correlated failures that vendor-by-vendor assessment never surfaces.