Third-Party Risk Assessment
Inherent risk, residual risk, and how a real assessment gets scored - what separates a genuine methodology from a questionnaire that goes in a drawer.
A third-party risk assessment evaluates a single vendor's risk at a point in time: inherent risk (exposure before controls), residual risk (exposure after the vendor's actual controls are verified), and a resulting tier that sets the monitoring cadence. A genuine assessment verifies evidence rather than accepting self-reported answers, and produces a documented, comparable score - not a pass/fail gut check.
Real US search demand (Ahrefs): ~600 searches/mo for "third party risk assessment" · ~$25.00 CPC.
The buyer problem
"We assess our vendors" often means a questionnaire gets sent and filed, with no scoring methodology behind it and no way to compare vendor A's risk to vendor B's. Buyers evaluating an assessment methodology - whether building one internally or evaluating an advisor's approach - need to know the difference between inherent risk (how risky this vendor relationship is before you know anything about their controls) and residual risk (how risky it is after you've verified what controls they actually have), because conflating the two is the most common reason assessment scores end up meaningless.
What a third-party risk assessment engagement covers
A structured assessment starts with inherent-risk scoring (data sensitivity, financial exposure, operational criticality, regulatory scope) done before any vendor contact, which sets the assessment's depth and the assessor's starting assumptions. The vendor then completes a standardized questionnaire (most commonly SIG-based) scaled to that inherent-risk tier. Every material claim in the response gets checked against real evidence - a SOC 2 report, a certificate, a financial filing - rather than taken at face value. The result is a residual-risk score: what's actually left after the vendor's real controls are accounted for, documented well enough that a different assessor reviewing the same evidence would reach a comparable conclusion.
Methods and techniques
- Inherent-risk scoring before vendor contact (data sensitivity, financial exposure, operational criticality, regulatory scope)
- Standardized questionnaire scaled to risk tier - full SIG for high-risk vendors, a lite/core version for lower-tier ones
- Evidence verification: SOC 2 Type II reports, ISO 27001 certificates, penetration-test summaries, insurance certificates, financial statements
- Residual-risk scoring after evidence review, documented against a consistent, repeatable rubric
- Gap and remediation tracking for findings that don't clear the acceptable-risk threshold
- Reassessment scheduling tied to the resulting risk tier, not a fixed calendar date for every vendor
What to verify before you retain
- Inherent and residual risk are scored separately. If a methodology only produces one number, ask what it represents. A single blended score without the inherent/residual distinction usually means evidence isn't actually changing the outcome.
- The scoring rubric is documented and repeatable. Two different assessors reviewing the same vendor evidence should land on a comparable score. Ask to see the actual rubric, not just a sample output.
- Evidence is genuinely checked, not just requested. Ask what happens when a vendor's SOC 2 report shows exceptions or a qualified opinion. A methodology that can't describe how exceptions affect the score isn't really verifying evidence.
- Depth scales with inherent risk. A vendor with no data access and no operational criticality shouldn't get the same 200-question deep-dive as one holding regulated customer data. Confirm the methodology actually tiers assessment depth, not just documentation depth.
- Findings connect to a remediation process. An assessment that surfaces a gap and stops there isn't risk management. Confirm there's a defined path from finding to remediation tracking to re-scoring.
Questions to put in your RFP
- Walk us through how you score inherent risk before any vendor contact happens.
- How does residual risk get calculated once evidence is reviewed - what's the actual scoring logic?
- What specific evidence do you require for a high-risk vendor, and how do you verify it's genuine and current?
- How do you handle a vendor that refuses to share requested evidence, or whose evidence shows exceptions?
- Can two different assessors on your team score the same evidence and reach a comparable result? How do you ensure that consistency?
- What does your remediation-tracking process look like after an assessment surfaces a real finding?
Skip the cold search. Send this scope to us and we route it toward qualified third-party risk assessment advisors.
Request advisorsRed flags
- A single risk score with no inherent/residual distinction and no explanation of the underlying rubric.
- Evidence is "collected" but there's no described process for actually reviewing SOC 2 exceptions, certificate validity dates, or financial-statement red flags.
- The same assessment depth applies to every vendor regardless of inherent risk.
- No defined process for what happens when a vendor refuses to provide evidence.
- Scoring methodology can't be shown or described in specific, repeatable terms - it's described as "proprietary AI" with no further detail.
Standards & frameworks referenced
Real, named standards bodies and frameworks relevant to this category. Listed for context; they do not endorse this index or any vendor. Verify any framework-alignment claim directly against the issuing body.
- SIG
- Shared Assessments Program. The Standardized Information Gathering questionnaire is the most widely used due-diligence instrument underlying third-party risk assessments, available in Core and Lite depth tiers.
- SOC 2
- American Institute of CPAs. SOC 2 Type II reports (issued under AICPA's Trust Services Criteria) are the most commonly requested piece of verification evidence in a security-focused third-party assessment.
- ISO 27001
- International Organization for Standardization. ISO/IEC 27001 certification is a frequently requested evidence artifact for information-security-management-system maturity in a vendor assessment.
Notable third-party risk assessment vendors
Real, publicly-documented vendors active in this category. Sourced and verified; not a ranking or endorsement.
Third-Party Risk Assessment: buyer FAQ
What's the difference between inherent risk and residual risk?
Inherent risk is how risky a vendor relationship is before you know anything about the vendor's actual controls - based purely on what data or systems they'd touch. Residual risk is what's left after you verify the vendor's real controls (encryption, access management, business-continuity planning). A vendor can have high inherent risk but low residual risk if their controls are genuinely strong.
How often should a third-party risk assessment be repeated?
Cadence should track risk tier: high-risk vendors typically get reassessed annually or on any material change (a breach, a subcontractor change, a contract renewal); low-risk vendors may go two to three years between reassessments. A fixed calendar date for every vendor regardless of tier is a sign the program isn't actually risk-based.
Is a SIG questionnaire response enough on its own?
No. A completed SIG is self-reported by the vendor. A genuine assessment cross-checks material answers against real evidence - SOC 2 reports, certificates, financial filings - rather than treating the questionnaire response as the final word.