Calculator overview
Inputs and outputs
This summary comes from the calculator's published input and output contract.
Inputs
- Assessment Questions
-
Default 20 rows
About this input
One row per third-party risk question grouped under domains such as security, privacy, resilience and compliance: enter a score for how well the control is in place and a scope flag, and edit the weight if needed. The questions are written for this tool and are not the text of any framework, so a score is not evidence of a vendor's compliance. A question marked not applicable is removed from both the numerator and the denominator, so it does not penalise the score. Every question needs a score and an applicability flag from the dropdowns; an entry that is blank or not on the list makes the tool refuse to score rather than guess.
Column Range or allowed values Category Not declared Question Not declared Weight At least 0 Score 0 - Not in place, 1 - Ad hoc, 2 - Partially in place, 3 - Largely in place, 4 - Fully in place, 5 - Fully in place and verified Applicability Applicable, Not applicable
Outputs
- Share Not Applicable
-
Unit %
About this output
The questions marked not applicable as a percent of all questions, a check on how much of the set was excluded.
- Second Priority
-
Unit question
About this output
The in-scope question with the second largest weighted gap to a full score.
- Questions Not Applicable
-
Unit count
About this output
The number of questions marked not applicable. These are removed from both the numerator and the denominator, so they neither help nor penalise the score.
- Share Of The Total Gap In The Top Three
-
Unit %
About this output
The combined weighted gap of the top three priorities as a percent of the whole gap to a full score, showing how concentrated the remaining risk is.
- Total Weight In Scope
-
Unit weight
About this output
The sum of the weights of the questions in scope, as a weight total. It is the denominator the weighted score is measured against.
- Top Priority
-
Unit question
About this output
The in-scope question contributing the largest weighted gap to a full score, the single item worth the most remediation.
- Third Priority
-
Unit question
About this output
The in-scope question with the third largest weighted gap to a full score.
- Questions In Scope
-
Unit count
About this output
The number of questions marked applicable and therefore included in the score.
- Lowest Scoring Category
-
Unit category
About this output
The risk domain with the weakest weighted score, the area of greatest concern.
- Highest Scoring Category
-
Unit category
About this output
The risk domain with the strongest weighted score, the vendor's relative strength.
- Category Scores
-
No unit declared
About this output
One row per risk domain: its weighted score in percent and its share of the total weight, so you can see where the overall figure comes from.
- Model Status
-
No unit declared
About this output
The overall check on your entries, shown above the results. It reads OK when the inputs are usable, NOT VALID with a reason when an entry makes the model meaningless, or CHECK with a reason when a result is valid but worth a second look. Read it before you trust the numbers below.
- Points Available To Gain
-
Unit points
About this output
The total weighted gap to a full score: the sum over the questions in scope of weight times score shortfall. It is measured in raw weight-times-score points on your own weight scale, not in percentage points, so re-weighting changes it even when the answers do not.
- Overall Score
-
Unit %
About this output
The weighted score across the risk questions in scope, in percent, combining each answer with its weight. A higher score reflects stronger reported controls and lower residual risk.
- Overall Band
-
Unit band
About this output
The control maturity band, from Not established to Optimised, read from the overall score. A higher band means more mature controls and therefore lower inferred residual risk; it is a summary of your answers, not a risk rating of the vendor.
What it is
This is a third-party vendor risk self-assessment. You score 20 questions about a supplier across five risk domains, each on a scale from zero to five, and it returns a weighted score as a percentage, a band, a score for each domain, and a ranked list of the gaps worth pressing on first.
What it is not. The 20 questions were written for this workbook. They are not drawn from any due-diligence standard or certification scheme, and a score here is not a certification, an assurance opinion, or a substitute for reading what the vendor actually holds. If a supplier has a SOC 2 report or an ISO/IEC 27001 certificate, that document (its scope, its exceptions, its date) tells you far more than this page can, and this page does not evaluate it. The weights, rating scale and band boundaries are editable and carry no official standing.
What it is good for is triaging a portfolio of suppliers consistently, deciding how much diligence each one warrants, and producing a defensible list of what to ask a vendor for next.
Methodology
Purpose and model boundary
This model scores self-reported vendor-control maturity across twenty original questions grouped into financial stability, information security, operational resilience, compliance and legal, and concentration and exit. It produces category scores, an overall control-maturity score and band, and a weighted improvement-priority list.
It supports initial triage and structured discussion. It is not a vendor risk rating, certification or substitute for due diligence. It does not independently assess inherent risk, service criticality, likelihood, impact, exposure, evidence quality or residual risk.
Inputs and units
Each fixed question row has:
| Field | Meaning and restriction |
|---|---|
| Domain and question | Locked workbook text. The questions are original to this model. |
Weight, w_i |
Nonnegative integer expressing importance within the domain. |
Score, s_i |
Required choice mapped to 0 through 5, from Not in place through Fully in place and verified. |
Applicability, a_i |
Required choice mapped to 1 for Applicable or 0 for Not applicable. |
The published page uses fixed domain weights: Financial stability 15, Information security 30, Operational resilience 20, Compliance and legal 20, and Concentration and exit 15. Maturity bands start at 0% Not established, 25% Initial, 45% Developing, 65% Managed, and 85% Optimised. Higher bands mean more mature self-reported controls and therefore lower inferred residual risk only if the answers and scope are reliable; they are not vendor risk tiers.
Governing relationships
For domain c and maximum score s_max = 5:
DomainScore_c = sum over i in c (w_i × s_i × a_i) / (s_max × sum over i in c (w_i × a_i))
A Not-applicable question is removed from numerator and denominator. If a domain has no applicable questions, its score returns zero, its band reads not assessed, and it is excluded from the overall domain-weight denominator.
With fixed domain weight W_c:
OverallScore = sum over assessed c (W_c × DomainScore_c) / sum over assessed c W_c
The overall band is the highest sorted threshold reached by 100 × OverallScore.
Improvement gaps use:
Gap_i = w_i × (s_max - s_i) × a_i
Points_Available_To_Gain = sum(Gap_i)
Positive gaps are ranked descending, with a small row-index term to make tied ranks unique. The top-three share divides the sum of gaps ranked 1 through 3 by total gap and returns zero when the total gap is zero.
Calculation sequence
- Validate every score, applicability and weight entry.
- Convert rating labels to 0 through 5 and scope labels to 1 or 0.
- Calculate each applicable question's weighted score and weighted shortfall.
- Calculate each assessed domain's score and maturity band.
- Combine assessed domains using the fixed domain weights.
- Rank positive weighted gaps and return the top three priority questions.
- Calculate scope counts, category extrema, total gap and top-three share.
- Evaluate
Model_Statusin the sequence below.
Outputs and interpretation
Overall_Score and Overall_Band summarize control maturity under the workbook's custom weights. They do not quantify vendor risk without inherent-risk, criticality, exposure and evidence inputs. The category table and chart show within-domain maturity scores, not weighted contribution or monetary risk.
Points_Available_To_Gain is a raw weight-times-score-shortfall total, not percentage points. The priority outputs identify the largest positive weighted gaps. Highest and lowest domain outputs consider only domains with at least one applicable question.
Validation and status logic
The workbook evaluates status in this order:
| Condition | Returned status |
|---|---|
| Fewer than all 20 score entries match the six-item score list | NOT VALID: a score entry is blank or not one of the listed options |
| Fewer than all 20 applicability entries match the scope list | NOT VALID: an applicability entry is blank or not one of the listed options |
| Any weight is not numeric | NOT VALID: a weight is not a number |
| Any weight is blank | NOT VALID: a weight is blank |
| Any weight is negative | NOT VALID: a weight is negative |
| No question is Applicable | NOT VALID: every question is marked not applicable, so there is nothing to score |
| Total weight across Applicable questions is zero | NOT VALID: the total weight in scope is zero, so there is nothing to score |
| More than 25% of questions are Not applicable | CHECK: more than a quarter of questions are marked not applicable; confirm that is right |
| Overall score is below 45% | CHECK: the overall score is below the Developing band; treat the priority list as a work plan |
| None of the preceding conditions applies | OK |
Entry and denominator failures take precedence. The high-exclusion warning is evaluated before the low-score warning.
Assumptions and limitations
- The score depends on vendor or assessor statements and does not verify audit reports, contracts, financial statements, certifications, test results or control operation.
- The twenty questions are a custom triage set, not a complete third-party or cyber supply-chain risk assessment.
- The model measures reported control maturity. It does not model inherent risk, service criticality, concentration exposure, data sensitivity, substitutability, likelihood, impact or residual risk.
- Domain and question weights, the 0-to-5 scale and maturity bands are illustrative and have no official standing.
- Not applicable is a mathematical exclusion. The workbook cannot decide whether a vendor, service, jurisdiction or data flow justifies that exclusion.
- A high average can conceal a critical single-point failure, weak evidence or an unacceptable contract term. Review the underlying evidence and individual answers.
- The model does not create risk acceptance, remediation ownership, ongoing monitoring, exit testing or assurance workflows.
Restrictions and non-computing states
The assessment grid has exactly twenty rows. Domain and question columns are locked. Every editable weight, score and applicability cell is required, including a valid score label for excluded rows. The page refuses negative weights, unlisted choices, blanks and incorrect grid shape before calculation. The workbook requires at least one Applicable question and positive total weight among Applicable questions.
Errors and warnings
A rejected entry means the request did not satisfy the published input rules. Workbook NOT VALID means there is no usable basis for a maturity score. Workbook CHECK retains results but flags a high exclusion share or below-Developing outcome. A connection or calculation-service failure is an availability issue and says nothing about the vendor.
References
The workbook derives its scoring rather than reproducing any table, chart, figure or control text from a standard or certification scheme. The 20 questions are original to this workbook, and the weights, rating scale and band boundaries are choices made in it.
The following are the kinds of evidence this tool is meant to help you go and ask for, not things it implements or evaluates:
- AICPA. SOC 2, the service organisation control reporting framework. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2
- ISO. ISO/IEC 27001, Information security management systems. https://www.iso.org/standard/27001
- National Institute of Standards and Technology. Cybersecurity Supply Chain Risk Management, SP 800-161. https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
- Wikipedia. Third-party risk management. https://en.wikipedia.org/wiki/Third-party_management
A current SOC 2 report or ISO/IEC 27001 certificate, read for its scope, exceptions and date, is stronger evidence than any questionnaire. No trademark or organisation name appearing in this tool implies endorsement by its owner.
Frequently asked questions
Can this replace a SOC 2 report or an ISO 27001 certificate?
What does a score of 5 mean on a vendor question?
Why did the priority list pick exit questions when information security is weighted highest?
Should I use the same weights for every vendor?
How often should this be redone?
What if a vendor genuinely has no personal data, so several questions do not apply?
Found a problem, or have an idea?
Tell us if a result looks wrong, a label is unclear, or something is missing. We read every message.
LogicCommons is in beta. If a result, label, or reference looks wrong, tell us here; we read every message.