How risky is that new software vendor you just onboarded? What about the payroll processor handling your employee data? Or the cloud provider storing your customer records?
If you're answering these questions with gut feelings instead of numbers, you're not alone. Most business leaders know they should be tracking vendor risk, but few have a practical system for actually quantifying it.
Here's the good news: you don't need a PhD in statistics or a six-figure risk platform to score your vendors effectively. You need a simple formula, a clear process, and the discipline to apply it consistently.
Let's break it down.
The Core Formula: Likelihood × Impact = Risk
Every sophisticated risk management framework ultimately boils down to one fundamental equation:
Likelihood × Impact = Risk Score
That's it. Two variables, one multiplication sign, and you have the foundation for every vendor risk decision your organization will ever make.
Likelihood answers the question: "How probable is it that something goes wrong with this vendor?"
Impact answers the question: "If something does go wrong, how bad will it hurt us?"
Multiply them together, and you get a risk score that tells you where to focus your attention, resources, and oversight.

Breaking Down Likelihood: What Could Go Wrong?
Likelihood isn't about predicting the future. It's about honestly assessing the probability of a risk event based on available evidence.
When evaluating a vendor's likelihood of causing problems, consider these factors:
Security posture indicators:
- Do they have current security certifications (SOC 2, ISO 27001)?
- Have they experienced breaches in the past?
- How mature are their security controls?
Operational stability signals:
- How long have they been in business?
- What's their financial health look like?
- Do they have documented business continuity plans?
Compliance track record:
- Are they subject to regulatory requirements?
- Have they faced enforcement actions?
- Do they maintain current compliance certifications?
For simplicity, rate likelihood on a 1-5 scale:
| Score | Likelihood | Description |
|---|---|---|
| 1 | Rare | Less than 5% chance annually |
| 2 | Unlikely | 5-20% chance annually |
| 3 | Possible | 20-50% chance annually |
| 4 | Likely | 50-80% chance annually |
| 5 | Almost Certain | Greater than 80% chance annually |
Be honest here. A vendor without SOC 2 certification handling sensitive data isn't a "2": they're probably a "4" or "5."
Breaking Down Impact: How Bad Could It Get?
Impact measures the consequences to your organization if the risk actually materializes. This is where many leaders underestimate the true cost of vendor failures.
Consider impact across multiple dimensions:
Financial impact:
- Direct costs (breach notification, legal fees, remediation)
- Indirect costs (lost revenue, customer churn)
- Regulatory fines and penalties
Operational impact:
- Business disruption duration
- Recovery time and resources required
- Effect on service delivery
Reputational impact:
- Customer trust erosion
- Media coverage and public perception
- Partner and investor confidence
Regulatory impact:
- Compliance violations
- Audit findings
- License or certification risks
Rate impact on the same 1-5 scale:
| Score | Impact | Description |
|---|---|---|
| 1 | Negligible | Minimal disruption, easily absorbed |
| 2 | Minor | Some disruption, manageable costs |
| 3 | Moderate | Significant disruption, notable costs |
| 4 | Major | Severe disruption, substantial costs |
| 5 | Catastrophic | Existential threat to operations |

Putting the Formula to Work: A Real Example
Let's walk through a practical scenario.
Your organization uses a cloud-based HR platform that stores employee Social Security numbers, salary information, and health benefits data. Here's how you might score them:
Likelihood Assessment:
- The vendor has SOC 2 Type 2 certification (good)
- They've been in business for 8 years with no known breaches (good)
- However, they recently had significant staff turnover in their security team (concerning)
- Likelihood Score: 2 (Unlikely)
Impact Assessment:
- They handle highly sensitive PII for all 500 employees
- A breach would trigger state notification laws in 12 states
- Regulatory exposure includes potential HIPAA implications for health data
- Reputational damage would be significant with employees and candidates
- Impact Score: 4 (Major)
Risk Score: 2 × 4 = 8
On a 25-point scale (5 × 5 maximum), an 8 puts this vendor in the medium-high risk category: not an emergency, but definitely requiring enhanced oversight and regular reassessment.
Beyond the Basic Score: Risk Tiers That Drive Action
A number by itself doesn't tell you what to do. That's why smart organizations translate scores into risk tiers with corresponding management requirements.
High Risk (Scores 15-25):
- Quarterly security assessments
- Annual on-site audits or detailed questionnaires
- Executive-level relationship management
- Contractual right-to-audit clauses required
- Incident response coordination plans
Medium Risk (Scores 8-14):
- Semi-annual security reviews
- Annual vendor questionnaires
- Regular performance monitoring
- Standard contractual protections
Low Risk (Scores 1-7):
- Annual check-ins
- Basic due diligence at renewal
- Standard terms and conditions
This tiered approach lets you allocate your limited resources where they matter most. You're not treating the office plant vendor the same as your cloud infrastructure provider.
For a deeper dive into the questions you should be asking vendors at each tier, check out our Vendor Risk Assessment Checklist: 50 Questions That Actually Reduce Risk.
Building a Sustainable Scoring System
Here's where most organizations stumble: they score vendors once and never revisit. Third-party risk scoring isn't a one-time project: it's an ongoing operational discipline.
Establish scoring triggers:
- New vendor onboarding (always)
- Contract renewals (always)
- Significant vendor changes (mergers, leadership changes, breaches)
- Changes in data shared or services provided
- Annual reassessment for high-risk vendors
Document your methodology:
- Write down your scoring criteria
- Define what constitutes each likelihood and impact level
- Create examples for consistency across assessors
- Train anyone who will be scoring vendors
Integrate with business processes:
- Procurement shouldn't finalize contracts without risk scores
- Legal should incorporate tier-appropriate protections
- Finance should factor risk costs into vendor economics
- IT should align access controls with risk levels

Common Pitfalls to Avoid
Even with a solid formula, organizations make predictable mistakes. Watch out for these:
Pitfall #1: Ignoring inherent vs. residual risk
Inherent risk is the vendor's baseline risk before any controls. Residual risk is what remains after controls are applied. A high-inherent-risk vendor with excellent controls might have acceptable residual risk. Score both.
Pitfall #2: Set-it-and-forget-it syndrome
Vendor risk changes constantly. The secure vendor from last year might have had layoffs, leadership changes, or unreported incidents. Build reassessment into your calendar.
Pitfall #3: Scoring in a vacuum
Risk scoring should involve stakeholders who actually work with the vendor. IT knows the technical reality. Procurement knows the contractual leverage. Business owners know the operational dependency.
Pitfall #4: Analysis paralysis
Don't let perfect be the enemy of good. A simple scoring system applied consistently beats a sophisticated framework that never gets implemented. Start with the basic formula and refine over time.
Making Risk Scoring Work for Your Organization
The formula is simple: Likelihood × Impact = Risk. But the real value comes from applying it consistently, acting on the results, and building it into your operational rhythm.
Start with your most critical vendors: the ones that would cause the most disruption if they failed. Score them this week. Then work your way through the rest of your vendor inventory over the next quarter.
If you're looking for expert guidance on building a sustainable third-party risk management program, CISOSHARE works with organizations across healthcare, nonprofit, and high-growth sectors to operationalize vendor risk. Sometimes the smartest move is bringing in a partner who's done this hundreds of times.
The vendors you trust with your data, your operations, and your reputation deserve more than a gut feeling. Give them a number: and manage accordingly.


