Guide

Third Party Risk Program Maturity Scorecard

Twelve observable questions that score how your third party risk program actually operates today, not how the policy describes it. Each question maps to a five level maturity scale from Reactive to Continuous, with the specific practice that defines each level. The result gives you an overall maturity level, the three lowest scoring areas to fix first, and a worksheet to assign each one an owner and a date. Built to be completed in a working session with security, procurement, legal, privacy, and business owners.

What You'll Learn

  • Score twelve areas of your vendor risk program against observable practice, from inventory and ownership through incident readiness and audit trail
  • Identify which of the five maturity levels your program actually operates at, and what typically breaks at that level
  • Find the three gaps most likely to leave risk unmanaged, even when your average score looks healthy
  • Test whether your program detects material vendor change between formal assessments, or waits for the next scheduled review
  • Check whether your due diligence obligations are actually carried into contract terms, including notification, evidence rights, and subcontractor change notice
  • Convert the result into a prioritized improvement plan with named owners and dates

Inside the guide

Score your vendor risk program in 10 minutes and identify the gaps keeping it reactive.

Most third party risk programs are assessed the way they are documented. The policy describes tiering criteria, annual reassessment, and evidence requirements, and on that basis the program looks sound. The operational reality is usually different: coverage depends on which business unit remembered to route the vendor through intake, reassessments are overdue, evidence expired months ago, and findings from the last review are sitting in an email thread.

This scorecard measures the second thing. Twelve questions, each with five levels of observable practice, scored on what happens consistently today. It takes about ten minutes alone, and it works better as a working session with security, procurement, legal, privacy, and the business owners who actually sign the contracts.

It is a practical diagnostic, not an external certification or an industry benchmark. Interpret the result in the context of your organization's size, risk appetite, regulatory obligations, and vendor criticality.

Download for free