Third-Party Risk Assessment (TPRM) Scoring Tool
Evaluate vendor security risk by answering 10 key questions about the vendor's security posture. This tool produces an objective risk score, per-category breakdown, and specific recommendations to reduce vendor risk. ISO 27001, SOC 2, HIPAA, and regulatory frameworks are factored into scoring.
1. Vendor Data Access Level
What type of data will this vendor access or process?
2. Vendor Type
How is the vendor's service delivered?
3. Certifications & Compliance
Does the vendor hold recognized security certifications?
4. Cyber Insurance
Does the vendor carry cyber liability insurance with minimum $1M coverage?
5. Multi-Factor Authentication (MFA)
Is MFA required for all vendor employee access to systems handling your data?
6. Data Encryption
Does the vendor encrypt data at rest (AES-256) and in transit (TLS 1.3)?
7. Breach History
Has the vendor experienced a security breach?
8. Third-Party Subcontractor Usage
Does the vendor subcontract any data processing to other parties?
9. Right-to-Audit Clause
Does the contract include a right-to-audit clause for security reviews?
What Is a Third-Party Risk Assessment?
A third-party risk assessment evaluates the security posture of vendors, suppliers, and partners before and during engagement. The National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA) both emphasize third-party risk management as a critical control — over 60% of data breaches now involve a third-party vendor. The average supply chain attack cost reached $4.96M in the IBM 2026 Cost of a Data Breach report.
This scoring tool evaluates 10 categories weighted by their impact on overall vendor risk. Data access level, breach history, and certification status carry the highest weights because they represent the most predictive indicators of vendor risk. The scoring model maps to requirements from NIST SP 800-53 (Access Control, Risk Assessment), SOC 2(Common Criteria), ISO 27001 (Annex A controls), and HIPAA Security Rule.
Organizations that perform vendor risk assessments at onboarding and annually reduce their likelihood of a third-party breach by an estimated 40-60% compared to organizations that perform no assessment. Key program elements include standardized questionnaires, right-to-audit clauses, minimum security requirements (MFA, encryption, insurance), and ongoing monitoring.