TPRM glossary

Inherent risk, the exposure before anything is done about it

Inherent risk is the level of risk present before any controls are applied — what a vendor could expose you to purely by what it accesses, holds and supports. It is the basis for tiering, because it can be judged at onboarding from facts you already have, without waiting for an assessment.

What drives inherent risk

Four factors, all knowable before any evidence arrives. Data — what categories the vendor holds or can see, and how much. Access — network connectivity, privileged accounts, code in your production path. Dependency — whether a business service stops if the vendor does, and how quickly. Context — the jurisdiction, the regulatory perimeter, and whether the vendor sub-contracts the work.

Note what is absent: how good the vendor's security is. That belongs to residual risk. A vendor with excellent controls processing your entire customer base still has high inherent risk, because inherent risk asks what is at stake rather than how well it is defended. Programmes that conflate the two end up tiering by questionnaire score, which means the depth of assessment is set by the answers to the assessment.

How to use it

Inherent risk sets the effort. It decides the tier, the depth of diligence, the reassessment frequency, the contractual terms you insist on, and whether an exit plan is required. Because it derives from facts captured at intake, it can be scored on day one — which is the only way to avoid the common failure where every vendor gets the same 300-question review because nobody has decided which ones matter.

It is not static. Inherent risk moves when the relationship moves: a new integration, a new data category, an expanded scope of service. Reassess on change rather than on the calendar, since the calendar has no opinion about the integration that went live in March.

Common questions

What is the difference between inherent risk and residual risk?
Inherent risk is the exposure before controls; residual risk is what remains after them. Inherent risk answers "how much is at stake here", residual risk answers "how much of that is still exposed". You tier on the first and report on the second.
How do you score inherent risk?
From intake facts rather than assessment answers: data categories and volume, access and connectivity, criticality of the process supported, and jurisdiction. A short weighted set of questions answered by the business owner produces a defensible tier in minutes, which is the point — it has to be fast enough to run before diligence.
Can inherent risk change?
Yes, whenever the relationship changes: new data, new integrations, a new business process, or a vendor sub-contracting part of the service. It does not change because the vendor improved its controls — that reduces residual risk while leaving inherent risk exactly where it was.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.