TPRM glossary

Vendor risk scoring, a number is a summary, not an argument

Vendor risk scoring expresses a supplier’s risk as a single comparable figure, derived from some combination of inherent risk factors, assessment results and externally observed security signals. Its value is triage across a portfolio; its limit is that a score summarises a judgement rather than replacing one.

What goes into a score

Three inputs, weighted differently by every methodology. Inherent riskfactors — data, access, dependency, jurisdiction — which are about exposure rather than security. Assessment results — questionnaire responses and the documents supporting them. And outside-in observation — what the vendor's external estate reveals about patching, exposure, certificate hygiene and breach history.

A score built from only one of the three is narrower than it looks. Security ratings that read the external estate alone say nothing about access management or staff vetting. Questionnaire scores alone are self-assertions. The composite is better, provided the weighting is published — an unexplained number is not evidence, it is a claim.

Reading a score properly

Use it for what it is good at: ranking a portfolio, spotting movement, and deciding where to spend the assessment budget this quarter. A drop of forty points at a critical vendor is a genuinely useful signal, and no human review would have caught it that week.

Do not use it as the decision. Two vendors on the same score can carry entirely different exposures — one holds no data, the other holds your customer base — and a score that ignores inherent risk weights them identically. The defensible pattern is score for triage, tier for effort, and evidence for the decision that actually gets recorded.

Common questions

How is a vendor risk score calculated?
Methodologies differ, but most combine inherent risk factors such as data and access, assessment results from questionnaires and documents, and externally observed signals such as exposed services, patch cadence and breach history. The weighting is the methodology, which is why an unpublished weighting makes a score hard to defend.
What is the difference between a security rating and a vendor risk score?
A security rating is normally derived from outside-in observation of a vendor’s external estate alone. A vendor risk score is broader, and usually incorporates inherent risk and assessment evidence alongside the external signal. A rating is an input to a score rather than a synonym for one.
Should a low score block a vendor?
It should trigger a decision, not make one. A low score on a vendor with no data access may be tolerable; the same score on a critical vendor should stop the onboarding until findings are remediated or accepted against a stated appetite. Scores route attention; evidence and appetite decide outcomes.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.