Inherent risk, the exposure before anything is done about it
Inherent risk is the level of risk present before any controls are applied — what a vendor could expose you to purely by what it accesses, holds and supports. It is the basis for tiering, because it can be judged at onboarding from facts you already have, without waiting for an assessment.
What drives inherent risk
Four factors, all knowable before any evidence arrives. Data — what categories the vendor holds or can see, and how much. Access — network connectivity, privileged accounts, code in your production path. Dependency — whether a business service stops if the vendor does, and how quickly. Context — the jurisdiction, the regulatory perimeter, and whether the vendor sub-contracts the work.
Note what is absent: how good the vendor's security is. That belongs to residual risk. A vendor with excellent controls processing your entire customer base still has high inherent risk, because inherent risk asks what is at stake rather than how well it is defended. Programmes that conflate the two end up tiering by questionnaire score, which means the depth of assessment is set by the answers to the assessment.
How to use it
Inherent risk sets the effort. It decides the tier, the depth of diligence, the reassessment frequency, the contractual terms you insist on, and whether an exit plan is required. Because it derives from facts captured at intake, it can be scored on day one — which is the only way to avoid the common failure where every vendor gets the same 300-question review because nobody has decided which ones matter.
It is not static. Inherent risk moves when the relationship moves: a new integration, a new data category, an expanded scope of service. Reassess on change rather than on the calendar, since the calendar has no opinion about the integration that went live in March.
Common questions
What is the difference between inherent risk and residual risk?
How do you score inherent risk?
Can inherent risk change?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.