risk-compliance · assessments · third-party-risk

Vendor Risk Scorecard

Scores a third-party vendor's risk across several domains from a weighted questionnaire, with a risk tier. Use it to triage vendor due diligence; the questions are original and a score is not a certification.

Last updated
Assessment Journey

Calculator overview

Inputs and outputs

This summary comes from the calculator's published input and output contract.

Inputs

Assessment Questions
About this input

One row per third-party risk question grouped under domains such as security, privacy, resilience and compliance: enter a score for how well the control is in place and a scope flag, and edit the weight if needed. The questions are written for this tool and are not the text of any framework, so a score is not evidence of a vendor's compliance. A question marked not applicable is removed from both the numerator and the denominator, so it does not penalise the score. Every question needs a score and an applicability flag from the dropdowns; an entry that is blank or not on the list makes the tool refuse to score rather than guess.

Default 20 rows
ColumnRange or allowed values
Category Not declared
Question Not declared
Weight At least 0
Score 0 - Not in place, 1 - Ad hoc, 2 - Partially in place, 3 - Largely in place, 4 - Fully in place, 5 - Fully in place and verified
Applicability Applicable, Not applicable

Outputs

Share Not Applicable
About this output

The questions marked not applicable as a percent of all questions, a check on how much of the set was excluded.

Unit %
Second Priority
About this output

The in-scope question with the second largest weighted gap to a full score.

Unit question
Questions Not Applicable
About this output

The number of questions marked not applicable. These are removed from both the numerator and the denominator, so they neither help nor penalise the score.

Unit count
Share Of The Total Gap In The Top Three
About this output

The combined weighted gap of the top three priorities as a percent of the whole gap to a full score, showing how concentrated the remaining risk is.

Unit %
Total Weight In Scope
About this output

The sum of the weights of the questions in scope, as a weight total. It is the denominator the weighted score is measured against.

Unit weight
Top Priority
About this output

The in-scope question contributing the largest weighted gap to a full score, the single item worth the most remediation.

Unit question
Third Priority
About this output

The in-scope question with the third largest weighted gap to a full score.

Unit question
Questions In Scope
About this output

The number of questions marked applicable and therefore included in the score.

Unit count
Lowest Scoring Category
About this output

The risk domain with the weakest weighted score, the area of greatest concern.

Unit category
Highest Scoring Category
About this output

The risk domain with the strongest weighted score, the vendor's relative strength.

Unit category
Category Scores
About this output

One row per risk domain: its weighted score in percent and its share of the total weight, so you can see where the overall figure comes from.

No unit declared
Model Status
About this output

The overall check on your entries, shown above the results. It reads OK when the inputs are usable, NOT VALID with a reason when an entry makes the model meaningless, or CHECK with a reason when a result is valid but worth a second look. Read it before you trust the numbers below.

No unit declared
Points Available To Gain
About this output

The total weighted gap to a full score: the sum over the questions in scope of weight times score shortfall. It is measured in raw weight-times-score points on your own weight scale, not in percentage points, so re-weighting changes it even when the answers do not.

Unit points
Overall Score
About this output

The weighted score across the risk questions in scope, in percent, combining each answer with its weight. A higher score reflects stronger reported controls and lower residual risk.

Unit %
Overall Band
About this output

The control maturity band, from Not established to Optimised, read from the overall score. A higher band means more mature controls and therefore lower inferred residual risk; it is a summary of your answers, not a risk rating of the vendor.

Unit band

What it is

This is a third-party vendor risk self-assessment. You score 20 questions about a supplier across five risk domains, each on a scale from zero to five, and it returns a weighted score as a percentage, a band, a score for each domain, and a ranked list of the gaps worth pressing on first.

What it is not. The 20 questions were written for this workbook. They are not drawn from any due-diligence standard or certification scheme, and a score here is not a certification, an assurance opinion, or a substitute for reading what the vendor actually holds. If a supplier has a SOC 2 report or an ISO/IEC 27001 certificate, that document (its scope, its exceptions, its date) tells you far more than this page can, and this page does not evaluate it. The weights, rating scale and band boundaries are editable and carry no official standing.

What it is good for is triaging a portfolio of suppliers consistently, deciding how much diligence each one warrants, and producing a defensible list of what to ask a vendor for next.

Methodology

Purpose and model boundary

This model scores self-reported vendor-control maturity across twenty original questions grouped into financial stability, information security, operational resilience, compliance and legal, and concentration and exit. It produces category scores, an overall control-maturity score and band, and a weighted improvement-priority list.

It supports initial triage and structured discussion. It is not a vendor risk rating, certification or substitute for due diligence. It does not independently assess inherent risk, service criticality, likelihood, impact, exposure, evidence quality or residual risk.

Inputs and units

Each fixed question row has:

Field Meaning and restriction
Domain and question Locked workbook text. The questions are original to this model.
Weight, w_i Nonnegative integer expressing importance within the domain.
Score, s_i Required choice mapped to 0 through 5, from Not in place through Fully in place and verified.
Applicability, a_i Required choice mapped to 1 for Applicable or 0 for Not applicable.

The published page uses fixed domain weights: Financial stability 15, Information security 30, Operational resilience 20, Compliance and legal 20, and Concentration and exit 15. Maturity bands start at 0% Not established, 25% Initial, 45% Developing, 65% Managed, and 85% Optimised. Higher bands mean more mature self-reported controls and therefore lower inferred residual risk only if the answers and scope are reliable; they are not vendor risk tiers.

Governing relationships

For domain c and maximum score s_max = 5:

DomainScore_c = sum over i in c (w_i × s_i × a_i) / (s_max × sum over i in c (w_i × a_i))

A Not-applicable question is removed from numerator and denominator. If a domain has no applicable questions, its score returns zero, its band reads not assessed, and it is excluded from the overall domain-weight denominator.

With fixed domain weight W_c:

OverallScore = sum over assessed c (W_c × DomainScore_c) / sum over assessed c W_c

The overall band is the highest sorted threshold reached by 100 × OverallScore.

Improvement gaps use:

Gap_i = w_i × (s_max - s_i) × a_i

Points_Available_To_Gain = sum(Gap_i)

Positive gaps are ranked descending, with a small row-index term to make tied ranks unique. The top-three share divides the sum of gaps ranked 1 through 3 by total gap and returns zero when the total gap is zero.

Calculation sequence

  1. Validate every score, applicability and weight entry.
  2. Convert rating labels to 0 through 5 and scope labels to 1 or 0.
  3. Calculate each applicable question's weighted score and weighted shortfall.
  4. Calculate each assessed domain's score and maturity band.
  5. Combine assessed domains using the fixed domain weights.
  6. Rank positive weighted gaps and return the top three priority questions.
  7. Calculate scope counts, category extrema, total gap and top-three share.
  8. Evaluate Model_Status in the sequence below.

Outputs and interpretation

Overall_Score and Overall_Band summarize control maturity under the workbook's custom weights. They do not quantify vendor risk without inherent-risk, criticality, exposure and evidence inputs. The category table and chart show within-domain maturity scores, not weighted contribution or monetary risk.

Points_Available_To_Gain is a raw weight-times-score-shortfall total, not percentage points. The priority outputs identify the largest positive weighted gaps. Highest and lowest domain outputs consider only domains with at least one applicable question.

Validation and status logic

The workbook evaluates status in this order:

Condition Returned status
Fewer than all 20 score entries match the six-item score list NOT VALID: a score entry is blank or not one of the listed options
Fewer than all 20 applicability entries match the scope list NOT VALID: an applicability entry is blank or not one of the listed options
Any weight is not numeric NOT VALID: a weight is not a number
Any weight is blank NOT VALID: a weight is blank
Any weight is negative NOT VALID: a weight is negative
No question is Applicable NOT VALID: every question is marked not applicable, so there is nothing to score
Total weight across Applicable questions is zero NOT VALID: the total weight in scope is zero, so there is nothing to score
More than 25% of questions are Not applicable CHECK: more than a quarter of questions are marked not applicable; confirm that is right
Overall score is below 45% CHECK: the overall score is below the Developing band; treat the priority list as a work plan
None of the preceding conditions applies OK

Entry and denominator failures take precedence. The high-exclusion warning is evaluated before the low-score warning.

Assumptions and limitations

  • The score depends on vendor or assessor statements and does not verify audit reports, contracts, financial statements, certifications, test results or control operation.
  • The twenty questions are a custom triage set, not a complete third-party or cyber supply-chain risk assessment.
  • The model measures reported control maturity. It does not model inherent risk, service criticality, concentration exposure, data sensitivity, substitutability, likelihood, impact or residual risk.
  • Domain and question weights, the 0-to-5 scale and maturity bands are illustrative and have no official standing.
  • Not applicable is a mathematical exclusion. The workbook cannot decide whether a vendor, service, jurisdiction or data flow justifies that exclusion.
  • A high average can conceal a critical single-point failure, weak evidence or an unacceptable contract term. Review the underlying evidence and individual answers.
  • The model does not create risk acceptance, remediation ownership, ongoing monitoring, exit testing or assurance workflows.

Restrictions and non-computing states

The assessment grid has exactly twenty rows. Domain and question columns are locked. Every editable weight, score and applicability cell is required, including a valid score label for excluded rows. The page refuses negative weights, unlisted choices, blanks and incorrect grid shape before calculation. The workbook requires at least one Applicable question and positive total weight among Applicable questions.

Errors and warnings

A rejected entry means the request did not satisfy the published input rules. Workbook NOT VALID means there is no usable basis for a maturity score. Workbook CHECK retains results but flags a high exclusion share or below-Developing outcome. A connection or calculation-service failure is an availability issue and says nothing about the vendor.

References

The workbook derives its scoring rather than reproducing any table, chart, figure or control text from a standard or certification scheme. The 20 questions are original to this workbook, and the weights, rating scale and band boundaries are choices made in it.

The following are the kinds of evidence this tool is meant to help you go and ask for, not things it implements or evaluates:

A current SOC 2 report or ISO/IEC 27001 certificate, read for its scope, exceptions and date, is stronger evidence than any questionnaire. No trademark or organisation name appearing in this tool implies endorsement by its owner.

Frequently asked questions

Can this replace a SOC 2 report or an ISO 27001 certificate?
No, and it is not trying to. Those are independent examinations with a defined scope, performed by someone accountable for the opinion. This is your own assessment of a vendor based on what they told you. If a supplier holds either document, read it (particularly its scope, its exceptions and its date), because it will tell you more than this page can, and this page does not evaluate it.
What does a score of 5 mean on a vendor question?
Verified, not asserted. A supplier saying they encrypt data at rest is a 3 or a 4 depending on how specific the claim is. The same control named in scope in a current SOC 2 report, or evidenced in a document you have actually read, is a 5. Treating claims as verified is the most common way a vendor assessment becomes decorative, and it defeats the purpose of the top rating existing separately.
Why did the priority list pick exit questions when information security is weighted highest?
Because priorities rank by weight times shortfall, not by domain weight or domain score. Information security carries the heaviest domain weight, but in the shipped example that domain scores near the middle, so its individual gaps are moderate. The exit questions carry real weight and large shortfalls, so they recover more. A domain can be important and still not be where your next hour is best spent.
Should I use the same weights for every vendor?
Probably not, and the weights are editable for that reason. A payroll processor handling personal data and a stationery supplier do not warrant the same emphasis, and forcing both through one weighting produces scores that look comparable but are not measuring the same risk. What consistency does buy is portfolio triage; if you change weights per vendor, keep a record of which profile you used.
How often should this be redone?
More often than most organisations do it. Both halves of what it measures move: a supplier's financial position can change in a quarter, and their security posture changes with every reorganisation, acquisition and product launch. A score is a snapshot of what you knew on the day you took it, and nothing on this page ages it for you.
What if a vendor genuinely has no personal data, so several questions do not apply?
Then mark those questions not applicable; that is the correct use, and they will leave the calculation cleanly. Be honest about the boundary, though: the same mechanism is the easiest way to make a supplier you have already chosen look acceptable. The page reports the exclusion count and share beside the score so anyone reading it can see what was left out.
This page is provided by LogicCommons for informational purposes only. Results are analysis outputs computed from the inputs you supply and are not engineering advice, a design, or a substitute for review by a licensed professional under the codes adopted where the work is built. Verify all inputs and results independently.

LogicCommons is in beta. If a result, label, or reference looks wrong, tell us here; we read every message.