Free third-party risk tool
Vendor Risk Assessment Tool
Score operational, financial, privacy and security risk, then identify the vendor gaps most likely to matter if the relationship becomes critical.
Simple vendor screen
0–100 risk scoreRate vendor controls across four risk domains
Vendor profile
Maturity scale0 Unknown / absent1 Weak2 Partial3 Established4 Strong & evidenced
Operational risk
Control / conditionWeightMaturity
Service reliability & SLA performanceHistorical uptime, support response and SLA discipline.
12%/ 4
Business continuity & disaster recoveryRecovery plans, backup capability and tested continuity.
10%/ 4
Capacity, staffing & support resilienceAbility to maintain service through growth, outages and key-person loss.
8%/ 4
Financial risk
Financial stabilityLiquidity, profitability, funding durability or other evidence of viability.
10%/ 4
Insurance / contractual financial protectionAppropriate insurance, caps, credits and other financial protections.
7%/ 4
Pricing / renewal / prepayment exposurePredictable commercial terms and limited stranded-prepayment risk.
6%/ 4
Privacy risk
Data handling & retention controlsClear purpose, access, retention and deletion practices.
9%/ 4
Subprocessor / fourth-party oversightKnown subprocessors, contractual flow-downs and change oversight.
7%/ 4
Privacy incident / request readinessNotification, deletion/export support and privacy-response processes.
6%/ 4
Security risk
Identity & privileged-access securityMFA, least privilege and privileged-access governance.
10%/ 4
Vulnerability, patching & endpoint securitySecure configuration, patching and vulnerability-management discipline.
8%/ 4
Security monitoring & incident responseDetection, escalation, containment and customer notification readiness.
7%/ 4
Simple methodControl maturity produces a 0–100 control-strength score. Remaining control gap is combined with vendor criticality, switching difficulty and data sensitivity to estimate residual vendor risk. Domain scores use the same logic so a strong overall vendor cannot hide a weak security, privacy, financial or operational area.
Advanced vendor-risk model
Evidence-adjustedSeparate inherent exposure from residual risk
Vendor profile & inherent exposure
Domain weights
Operational controls
ControlMaturityEvidence confidenceLocal weight
SLA reliability & support performance
/4
%
%
Business continuity / disaster recovery
/4
%
%
Capacity, staffing & support resilience
/4
%
%
Financial controls
Financial stability & funding durability
/4
%
%
Insurance / indemnity / financial protection
/4
%
%
Commercial-term / prepayment / renewal protection
/4
%
%
Privacy controls
Data minimization, retention & deletion
/4
%
%
Subprocessor / fourth-party oversight
/4
%
%
Privacy incident / rights-request readiness
/4
%
%
Security controls
Identity, MFA & privileged-access security
/4
%
%
Vulnerability, patching & endpoint security
/4
%
%
Monitoring, incident response & notification
/4
%
%
Advanced methodEffective control strength = maturity ÷ 4 × an evidence-confidence adjustment. Each control is normalized inside its domain, then domain scores are normalized using the entered domain weights. Inherent risk is based on business criticality, switching difficulty, data sensitivity, dependency, fourth-party exposure and exit protection. Residual risk combines the remaining control gap with inherent exposure.
Domain breakdown
Residual risk by domainOperational, financial, privacy and security risk
| Domain | Domain weight | Control strength | Control gap | Residual domain risk |
|---|
Priority gaps
Highest impact firstControls ranked by modeled residual-risk reduction
| Priority | Control | Domain | Effective control strength | Evidence confidence | Potential risk reduction |
|---|
Criticality sensitivity
Controls unchangedResidual risk as vendor criticality changes
| Criticality | Inherent risk | Control strength | Residual risk | Risk level |
|---|
Evidence sensitivity
All controls scaled togetherResidual risk as evidence confidence changes
| Evidence scale | Control strength | Residual risk | Highest-risk domain |
|---|
Scope
A vendor-risk score is a screening framework, not due-diligence completion
This tool does not certify a vendor, determine legal or regulatory compliance, replace financial due diligence, validate a security assessment, or establish whether a processor/subprocessor arrangement is lawful. A strong score can still hide contract-specific, jurisdiction-specific, concentration, geopolitical or technical risks that require separate review.
