Score a vendor across 12 weighted dimensions and watch the inherent-risk tier resolve live. Edit the scores, name the vendor, then export the whole assessment to a CSV you can drop into your GRC system or a spreadsheet.
| Risk dimension | Weight | Score |
|---|---|---|
Data sensitivity accessed What classification of data the vendor can touch | ×5 | |
Access scope & least privilege Breadth of access vs. what they actually need | ×5 | |
Authentication (SSO / MFA) Enforced SSO, MFA, and session controls | ×4 | |
Encryption in transit & at rest TLS everywhere, KMS-managed keys | ×4 | |
Compliance attestations SOC 2 Type II, ISO 27001, current reports | ×4 | |
Subprocessor management Fourth-party visibility and flow-downs | ×3 | |
Business continuity & DR Tested recovery, RTO/RPO commitments | ×3 | |
Incident response & history IR plan, breach history, notification SLAs | ×4 | |
Vulnerability management Patch cadence, pentest results, bug bounty | ×3 | |
Questionnaire responsiveness Speed and quality of security review answers | ×2 | |
Contractual safeguards (DPA/BAA) Signed DPA, BAA, breach & audit clauses | ×4 | |
Financial & operational stability Runway, ownership, concentration risk | ×2 |
Weighting reflects blast radius if the vendor is compromised. Adjust scores to match your due-diligence findings.
Uproot Vendor Risk pulls live posture from your vendors' trust centers, auto-scores them against this matrix, and re-checks every quarter — so the assessment never goes stale the day after you finish it.