Vendor Risk Calculator
Tier a single vendor on data, access, criticality and spend, weigh the assurance evidence, and get residual risk plus a reassessment interval.
Inputs
Vendor Risk Verdict
Low — proceed with standard clauses and periodic review
Inherent Vendor Risk
3.50of 5
Assurance Evidence Score
78.8%
Residual Vendor Risk
1.57of 5
Share of the Maximum Score
31.4%
Reassessment Interval
24months
Assessment Tier
Tier 2 — significant vendor: full questionnaire plus certificate or report review
Largest Assurance Gap
Assurance evidence is adequate for this tier
Step by step
Values used
Most sensitive data the vendor handles = 4 — Personal data; Access the vendor holds = 3 — SaaS holding our data; Criticality to your operations = 4 — Critical, replacement takes months; Annual contract value = 480,000 $; Independent assurance held = One current certificate or report — 75; Security questionnaire score = 72 %; Independent penetration test evidence provided = Yes; Subprocessors disclosed behind this vendor = 6 subprocessors; Publicly known breach in the last three years = No
Vendor Risk
Inherent vendor risk = 0.30 × data class + 0.25 × access type + 0.25 × operational criticality + 0.10 × spend band + 0.10 × subprocessor band, on 1–5.
Assurance and residual
Residual = inherent × (1 − 0.7 × assurance score) × 1.2 if there is a known breach, where assurance = 0.4 × certification + 0.4 × questionnaire + 0.2 × penetration test evidence.
Vendor Risk Verdict
= Low — proceed with standard clauses and periodic review
Inherent Vendor Risk
= 3.50 of 5
Assurance Evidence Score
= 78.8
Residual Vendor Risk
= 1.57 of 5
Share of the Maximum Score
= 31.4
Reassessment Interval
= 24 months
How it works
Tiering is driven by data and access rather than by spend, because a cheap tool with an API token in your production tenant outranks an expensive one that never touches your data. Assurance evidence is capped at 70% effectiveness since a certificate describes a scope you did not choose, at a date that has passed, and a questionnaire is only as good as the evidence behind the answers. Vendor tiering decides how much diligence each supplier gets, and getting the tier wrong is how a low-spend integration ends up with unmonitored privileged access. This is a management estimate to prioritise diligence, not an assurance opinion on the vendor.
Formulas
Vendor Risk
Inherent vendor risk = 0.30 × data class + 0.25 × access type + 0.25 × operational criticality + 0.10 × spend band + 0.10 × subprocessor band, on 1–5.
- data class
- Most sensitive data the vendor touches
- access type
- From no access through to privileged network access
- subScore
- Subprocessor count banded, because their supply chain is now yours
Assurance and residual
Residual = inherent × (1 − 0.7 × assurance score) × 1.2 if there is a known breach, where assurance = 0.4 × certification + 0.4 × questionnaire + 0.2 × penetration test evidence.
- assurance
- Independent evidence outweighs self-attestation
- 0.7
- Even perfect evidence cannot remove more than 70% of the inherent risk, because it is a point-in-time view of someone else's estate
Frequently Asked Questions
How is Vendor Risk calculated?
Inherent vendor risk = 0.30 × data class + 0.25 × access type + 0.25 × operational criticality + 0.10 × spend band + 0.10 × subprocessor band, on 1–5. Tiering is driven by data and access rather than by spend, because a cheap tool with an API token in your production tenant outranks an expensive one that never touches your data. Assurance evidence is capped at 70% effectiveness since a certificate describes a scope you did not choose, at a date that has passed, and a questionnaire is only as good as the evidence behind the answers.
Why does Vendor Risk matter?
Vendor tiering decides how much diligence each supplier gets, and getting the tier wrong is how a low-spend integration ends up with unmonitored privileged access. This is a management estimate to prioritise diligence, not an assurance opinion on the vendor.
What values do I need to enter?
This calculator takes 9 inputs: Most sensitive data the vendor handles, Access the vendor holds, Criticality to your operations, Annual contract value, Independent assurance held, Security questionnaire score, Independent penetration test evidence provided, Subprocessors disclosed behind this vendor, Publicly known breach in the last three years. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is a SOC 2 report enough on its own?
Only after you have read it. Check the scope, the trust services categories, the observation period and the exceptions — a report scoped to one product with a three-month window and four exceptions is not the assurance the cover page implies. The report answers questions about their controls, not about the service you are buying.
Why do subprocessors affect the score?
Because your data goes where they send it. Every subprocessor is a fourth party you have no contract with, and concentration behind several of your vendors — the same cloud region, the same email provider — creates correlated failures that vendor-by-vendor assessment never surfaces.
You might also need
- Residual Risk CalculatorCommonly used together
- Third-Party Risk CalculatorCommonly used together
- Business Continuity CalculatorCommonly used together
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC
- ISO 27001 Compliance CalculatorAlso in Compliance & GRC