Third-Party Risk Scoring: A Simple Formula for Leaders : CISOSHARE

Third party risk scoring
Written By

CISOSHARE

Post Date

8
Minute Read


How risky is that new software vendor you just onboarded? What about the payroll processor handling your employee data? Or the cloud provider storing your customer records?

If you're answering these questions with gut feelings instead of numbers, you're not alone. Most business leaders know they should be tracking vendor risk, but few have a practical system for actually quantifying it.

Here's the good news: you don't need a PhD in statistics or a six-figure risk platform to score your vendors effectively. You need a simple formula, a clear process, and the discipline to apply it consistently.

Let's break it down.

The Core Formula: Likelihood × Impact = Risk

Every sophisticated risk management framework ultimately boils down to one fundamental equation:

Likelihood × Impact = Risk Score

That's it. Two variables, one multiplication sign, and you have the foundation for every vendor risk decision your organization will ever make.

Likelihood answers the question: "How probable is it that something goes wrong with this vendor?"

Impact answers the question: "If something does go wrong, how bad will it hurt us?"

Multiply them together, and you get a risk score that tells you where to focus your attention, resources, and oversight.

Modern conference table with clear blocks arranged in a formula, illustrating third-party risk scoring for business leaders

Breaking Down Likelihood: What Could Go Wrong?

Likelihood isn't about predicting the future. It's about honestly assessing the probability of a risk event based on available evidence.

When evaluating a vendor's likelihood of causing problems, consider these factors:

Security posture indicators:

  • Do they have current security certifications (SOC 2, ISO 27001)?
  • Have they experienced breaches in the past?
  • How mature are their security controls?

Operational stability signals:

  • How long have they been in business?
  • What's their financial health look like?
  • Do they have documented business continuity plans?

Compliance track record:

  • Are they subject to regulatory requirements?
  • Have they faced enforcement actions?
  • Do they maintain current compliance certifications?

For simplicity, rate likelihood on a 1-5 scale:

Score Likelihood Description
1 Rare Less than 5% chance annually
2 Unlikely 5-20% chance annually
3 Possible 20-50% chance annually
4 Likely 50-80% chance annually
5 Almost Certain Greater than 80% chance annually

Be honest here. A vendor without SOC 2 certification handling sensitive data isn't a "2": they're probably a "4" or "5."

Breaking Down Impact: How Bad Could It Get?

Impact measures the consequences to your organization if the risk actually materializes. This is where many leaders underestimate the true cost of vendor failures.

Consider impact across multiple dimensions:

Financial impact:

  • Direct costs (breach notification, legal fees, remediation)
  • Indirect costs (lost revenue, customer churn)
  • Regulatory fines and penalties

Operational impact:

  • Business disruption duration
  • Recovery time and resources required
  • Effect on service delivery

Reputational impact:

  • Customer trust erosion
  • Media coverage and public perception
  • Partner and investor confidence

Regulatory impact:

  • Compliance violations
  • Audit findings
  • License or certification risks

Rate impact on the same 1-5 scale:

Score Impact Description
1 Negligible Minimal disruption, easily absorbed
2 Minor Some disruption, manageable costs
3 Moderate Significant disruption, notable costs
4 Major Severe disruption, substantial costs
5 Catastrophic Existential threat to operations

Overhead view of a business leader analyzing risk charts and data on a tablet at a clean office desk

Putting the Formula to Work: A Real Example

Let's walk through a practical scenario.

Your organization uses a cloud-based HR platform that stores employee Social Security numbers, salary information, and health benefits data. Here's how you might score them:

Likelihood Assessment:

  • The vendor has SOC 2 Type 2 certification (good)
  • They've been in business for 8 years with no known breaches (good)
  • However, they recently had significant staff turnover in their security team (concerning)
  • Likelihood Score: 2 (Unlikely)

Impact Assessment:

  • They handle highly sensitive PII for all 500 employees
  • A breach would trigger state notification laws in 12 states
  • Regulatory exposure includes potential HIPAA implications for health data
  • Reputational damage would be significant with employees and candidates
  • Impact Score: 4 (Major)

Risk Score: 2 × 4 = 8

On a 25-point scale (5 × 5 maximum), an 8 puts this vendor in the medium-high risk category: not an emergency, but definitely requiring enhanced oversight and regular reassessment.

Beyond the Basic Score: Risk Tiers That Drive Action

A number by itself doesn't tell you what to do. That's why smart organizations translate scores into risk tiers with corresponding management requirements.

High Risk (Scores 15-25):

  • Quarterly security assessments
  • Annual on-site audits or detailed questionnaires
  • Executive-level relationship management
  • Contractual right-to-audit clauses required
  • Incident response coordination plans

Medium Risk (Scores 8-14):

  • Semi-annual security reviews
  • Annual vendor questionnaires
  • Regular performance monitoring
  • Standard contractual protections

Low Risk (Scores 1-7):

  • Annual check-ins
  • Basic due diligence at renewal
  • Standard terms and conditions

This tiered approach lets you allocate your limited resources where they matter most. You're not treating the office plant vendor the same as your cloud infrastructure provider.

For a deeper dive into the questions you should be asking vendors at each tier, check out our Vendor Risk Assessment Checklist: 50 Questions That Actually Reduce Risk.

Building a Sustainable Scoring System

Here's where most organizations stumble: they score vendors once and never revisit. Third-party risk scoring isn't a one-time project: it's an ongoing operational discipline.

Establish scoring triggers:

  • New vendor onboarding (always)
  • Contract renewals (always)
  • Significant vendor changes (mergers, leadership changes, breaches)
  • Changes in data shared or services provided
  • Annual reassessment for high-risk vendors

Document your methodology:

  • Write down your scoring criteria
  • Define what constitutes each likelihood and impact level
  • Create examples for consistency across assessors
  • Train anyone who will be scoring vendors

Integrate with business processes:

  • Procurement shouldn't finalize contracts without risk scores
  • Legal should incorporate tier-appropriate protections
  • Finance should factor risk costs into vendor economics
  • IT should align access controls with risk levels

Business professionals reviewing a color-coded risk dashboard together in a collaborative office meeting

Common Pitfalls to Avoid

Even with a solid formula, organizations make predictable mistakes. Watch out for these:

Pitfall #1: Ignoring inherent vs. residual risk

Inherent risk is the vendor's baseline risk before any controls. Residual risk is what remains after controls are applied. A high-inherent-risk vendor with excellent controls might have acceptable residual risk. Score both.

Pitfall #2: Set-it-and-forget-it syndrome

Vendor risk changes constantly. The secure vendor from last year might have had layoffs, leadership changes, or unreported incidents. Build reassessment into your calendar.

Pitfall #3: Scoring in a vacuum

Risk scoring should involve stakeholders who actually work with the vendor. IT knows the technical reality. Procurement knows the contractual leverage. Business owners know the operational dependency.

Pitfall #4: Analysis paralysis

Don't let perfect be the enemy of good. A simple scoring system applied consistently beats a sophisticated framework that never gets implemented. Start with the basic formula and refine over time.

Making Risk Scoring Work for Your Organization

The formula is simple: Likelihood × Impact = Risk. But the real value comes from applying it consistently, acting on the results, and building it into your operational rhythm.

Start with your most critical vendors: the ones that would cause the most disruption if they failed. Score them this week. Then work your way through the rest of your vendor inventory over the next quarter.

If you're looking for expert guidance on building a sustainable third-party risk management program, CISOSHARE works with organizations across healthcare, nonprofit, and high-growth sectors to operationalize vendor risk. Sometimes the smartest move is bringing in a partner who's done this hundreds of times.

The vendors you trust with your data, your operations, and your reputation deserve more than a gut feeling. Give them a number: and manage accordingly.


Latest Insights