UprootSecurity
Book a demo
TemplateSpreadsheetNo email required

Vendor risk assessment matrix

Score a vendor across 12 weighted dimensions and watch the inherent-risk tier resolve live. Edit the scores, name the vendor, then export the whole assessment to a CSV you can drop into your GRC system or a spreadsheet.

Assessment

1 = weak control · 5 = strong control
Risk dimensionWeightScore
Data sensitivity accessed
What classification of data the vendor can touch
×5
Access scope & least privilege
Breadth of access vs. what they actually need
×5
Authentication (SSO / MFA)
Enforced SSO, MFA, and session controls
×4
Encryption in transit & at rest
TLS everywhere, KMS-managed keys
×4
Compliance attestations
SOC 2 Type II, ISO 27001, current reports
×4
Subprocessor management
Fourth-party visibility and flow-downs
×3
Business continuity & DR
Tested recovery, RTO/RPO commitments
×3
Incident response & history
IR plan, breach history, notification SLAs
×4
Vulnerability management
Patch cadence, pentest results, bug bounty
×3
Questionnaire responsiveness
Speed and quality of security review answers
×2
Contractual safeguards (DPA/BAA)
Signed DPA, BAA, breach & audit clauses
×4
Financial & operational stability
Runway, ownership, concentration risk
×2

Weighting reflects blast radius if the vendor is compromised. Adjust scores to match your due-diligence findings.

Inherent risk score
66/100
Moderate risk
CriticalHighModerateLow

Stop assessing vendors in a spreadsheet

Uproot Vendor Risk pulls live posture from your vendors' trust centers, auto-scores them against this matrix, and re-checks every quarter — so the assessment never goes stale the day after you finish it.

See Vendor RiskExplore the product