Rank suppliers with consistent risk scoring and clear levels. Tune weights and thresholds for your program needs. Export clean CSV and PDF reports.
| vendor | impact | likelihood | control_eff | resilience | sensitivity | regulatory | financial | availability | fourth_party | incident_history | notes |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Acme Payments | 5 | 4 | 55 | 60 | 5 | 5 | 4 | 5 | 4 | 2 | Handles card data |
| BlueSupport BPO | 3 | 3 | 70 | 65 | 3 | 2 | 2 | 3 | 3 | 1 | Customer contact center |
| CloudStorage Pro | 4 | 3 | 60 | 75 | 4 | 3 | 3 | 4 | 4 | 0 | Stores internal documents |
| DataInsights AI | 4 | 4 | 45 | 50 | 4 | 4 | 3 | 3 | 5 | 3 | Uses multiple sub‑processors |
vendor,impact,likelihood,control_eff,resilience,sensitivity,regulatory,financial,availability,fourth_party,incident_history,notes Acme Payments,5,4,55,60,5,5,4,5,4,2,Handles card data BlueSupport BPO,3,3,70,65,3,2,2,3,3,1,Customer contact center CloudStorage Pro,4,3,60,75,4,3,3,4,4,0,Stores internal documents DataInsights AI,4,4,45,50,4,4,3,3,5,3,Uses multiple sub-processors
Inherent risk: Inherent = Impact × Likelihood (range 1–25).
Component scaling: Inherent, Exposure, and Incident are scaled to 0–100, then blended by weights.
Residual score: Residual = Base × (1 − Controls%) × (1 − 0.20×Resilience%) × Uplift.
Exposure uplift: Uplift = 1 + 0.15×(ExposureAvg − 1), to reflect sensitive and regulated vendors.
It is a 0–100 residual risk score after considering inherent risk, exposure drivers, incident history, and reductions from controls and resilience.
Use your organization’s rubric. Impact reflects business harm if a vendor fails. Likelihood estimates probability during the review period, using incidents, audits, and threat context.
Exposure drivers capture what is at stake: sensitive data, regulation, financial dependency, uptime needs, and sub‑processor reliance. Higher exposure increases the uplift applied to residual scoring.
Yes. Edit the Low, Moderate, High, and Critical maximum thresholds in Advanced settings. Anything above Critical becomes Severe automatically.
Use a percent estimate based on control testing, certifications, audit results, and contract requirements. Higher values reduce residual risk more strongly in the formula.
Paste CSV with the supported header, submit, and the tool calculates every row. Results are sorted by highest score and can be exported to CSV and PDF.
No. It’s a structured triage and reporting aid. Use it to prioritize reviews, set monitoring cadence, and justify decisions alongside questionnaires and evidence.
Important Note: All the Calculators listed in this site are for educational purpose only and we do not guarentee the accuracy of results. Please do consult with other sources as well.