Compliance

Vendor Risk Tiering Calculator

Score a vendor on data sensitivity, access, criticality and concentration to produce a defensible risk tier, the due diligence depth it warrants, and the review frequency that follows.

Last reviewed by the Radiatus Cloud team

The tier appears here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Tiering exists to stop every vendor getting the same questionnaire

A programme that sends the same two hundred questions to a payroll processor and to a stationery supplier fails in both directions: it wastes the assessor's time on the supplier and gives the processor no more scrutiny than anything else. Tiering fixes the allocation, and the tier has to be derived from properties of the engagement rather than from the size of the vendor, because a small vendor with administrative access to a production system is a larger risk than a large vendor with none.

Access is a separate axis from data

Vendors are commonly scored on the sensitivity of the data they hold, and that is only half the exposure. A vendor with no data but with privileged access to your infrastructure, or one whose code executes inside your product, presents a different failure mode: the supply chain incidents that have caused the most damage came through software updates and administrative access rather than through stolen databases. Scoring the two axes separately keeps that visible.

Concentration turns a moderate risk into a critical one

A vendor with no substitute available inside your recovery objective is a single point of failure regardless of how well it is run. That is a business continuity property rather than a security one, and it belongs in the tier because it changes what you must do: a critical vendor with an alternative needs contractual exit rights, while a critical vendor without one needs a plan that does not depend on the vendor existing.

Related tools

Frequently Asked Questions

Why not tier by contract value?

Because value correlates poorly with exposure. A low-cost monitoring agent with root access on every server carries far more risk than an expensive supplier of physical goods.

Why score access separately from data?

Because they are different failure modes. The supply chain incidents that caused the most damage came through software updates and administrative access rather than through stolen databases, and a data-only score misses those entirely.

How often should each tier be reviewed?

Annually at minimum for the highest tier, with continuous monitoring where available, and on a two or three year cycle for the lowest. Reassess on any material change regardless of the cycle.

What does concentration risk mean here?

That no substitute is available inside your recovery objective. It is a continuity property rather than a security one, but it changes what you have to do about the vendor, so it belongs in the tier.

Is this an industry standard scoring model?

No. It is a transparent weighted model whose inputs and weights are all visible, so you can defend or adjust the result. Any tiering model is a judgement made consistent, not a measurement.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Score the vendor on each dimension to get its tier.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.