Vendor Security Risk Calculator

Score vendors across access, data, controls, and resilience. Quantify risk using weighted factors and benchmarks. Prioritize reviews, remediation, and contract decisions with confidence today.

Calculator Inputs

Use 1 for lowest and 5 for highest unless noted.

1 = public data, 5 = highly sensitive data.
1 = no internal access, 5 = privileged access.
1 = clean history, 5 = repeated issues.
1 = weak controls, 5 = strong controls.
1 = weak terms, 5 = strong security clauses.

Formula Used

The calculator separates inherent exposure from control strength, then estimates residual risk after control mitigation and penalties.

Step 1: Normalize factor scores

Normalized Score = ((Input - 1) / 4) × 100

This converts every 1 to 5 rating into a 0 to 100 scale.

Step 2: Calculate inherent risk

Inherent Risk = Σ(Driver Score × Driver Weight)

Drivers include data sensitivity, system access, internet exposure, incident history, criticality, dependency, geographic risk, and subprocessors.

Step 3: Calculate control effectiveness

Control Effectiveness = Σ(Control Strength × Control Weight)

Controls include maturity, monitoring, contract assurance, financial stability, MFA, SSO, encryption, incident notice, and certifications.

Step 4: Estimate residual risk

Mitigation Factor = 1 - (0.65 × Control Effectiveness / 100)

Base Residual Risk = Inherent Risk × Mitigation Factor

Final Residual Risk = Base Residual Risk + Adjustment Penalties

Adjustment penalties

The model adds penalties for breach history, regulated data handling, privacy review needs, missing MFA on high access, and missing encryption on high internet exposure.

How to Use This Calculator

  1. Enter the vendor name and the type of service provided.
  2. Score business and technical exposure factors from 1 to 5.
  3. Score the vendor’s maturity for controls, monitoring, and contract protections.
  4. Enter the subprocessor count and recent breach count.
  5. Tick the boxes for available controls and assurance evidence.
  6. Click Calculate Vendor Risk to see the residual risk score above the form.
  7. Review the chart, factor table, and suggested review cadence.
  8. Use the CSV and PDF buttons to save the assessment output.

Example Data Table

Vendor Service Type Data Sensitivity System Access Control Maturity Subprocessors Breaches Illustrative Result
NorthGrid Cloud Infrastructure Hosting 5 4 4 6 1 High
InsightFlow Analytics Reporting Platform 3 2 4 2 0 Moderate
PulseDesk Support Customer Service Tool 4 5 2 8 2 Critical

FAQs

1. What does vendor security risk mean?

Vendor security risk is the chance that a third party could expose data, disrupt operations, weaken compliance, or introduce cyber threats into your environment.

2. Why use weighted scoring?

Weighted scoring reflects reality better than flat scoring. Sensitive data, privileged access, and business criticality usually matter more than low impact attributes.

3. What is inherent risk?

Inherent risk is the exposure created by the vendor relationship before considering safeguards. It focuses on what the vendor can access, process, and impact.

4. What is control effectiveness?

Control effectiveness estimates how much the vendor’s safeguards reduce exposure. Strong monitoring, MFA, encryption, evidence, and contract terms can materially lower residual risk.

5. Do SOC 2 or ISO 27001 remove risk?

No. Certifications and reports help, but they do not eliminate exposure. Actual data use, access levels, architecture, and operational maturity still matter.

6. How often should vendors be reviewed?

Higher risk vendors deserve more frequent reviews. Annual reviews may fit low risk vendors, while high or critical vendors often need quarterly or monthly oversight.

7. Can this calculator replace a full due diligence review?

No. It is a decision support tool. It helps prioritize reviews and summarize exposure, but detailed questionnaires, evidence review, and technical testing may still be necessary.

8. Why include subprocessors in the score?

Every additional subprocessor can expand the attack surface and reduce visibility. Concentration and chain complexity often increase operational and security dependency risk.

Related Calculators

third party impactthird party risk scorevendor cyber riskvendor compliance risk

Important Note: All the Calculators listed in this site are for educational purpose only and we do not guarentee the accuracy of results. Please do consult with other sources as well.