Skip to main content
VENDOR-RISK5 MIN READ

Build a Vendor Criticality Score in 10 Minutes

construct a simple criticality score from dependency signals

Tara has six vendor requests and only one afternoon to decide which need security review. Interagency Guidance on Third-Party Relationships: Risk Management The common trap is treating the artifact as the answer. A score, SOC report, or loss estimate is only useful when it changes approval, remediation, monitoring, or risk acceptance. Signal 1 Score data sensitivity: none=0, internal=1, confidential=2, regulated or payroll=3. Data sensitivity is a proxy for impact if the vendor mishandles information. Signal 2 Score operational dependency: optional=0, useful=1, business workflow=2, revenue/payroll/customer-critical=3. Criticality is about what breaks when the vendor fails. Signal 3 Add substitutability: easy switch=0, several…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us