Twelve observable questions that score how your third party risk program actually operates today, not how the policy describes it. Each question maps to a five level maturity scale from Reactive to Continuous, with the specific practice that defines each level. The result gives you an overall maturity level, the three lowest scoring areas to fix first, and a worksheet to assign each one an owner and a date. Built to be completed in a working session with security, procurement, legal, privacy, and business owners.
Score your vendor risk program in 10 minutes and identify the gaps keeping it reactive.
Most third party risk programs are assessed the way they are documented. The policy describes tiering criteria, annual reassessment, and evidence requirements, and on that basis the program looks sound. The operational reality is usually different: coverage depends on which business unit remembered to route the vendor through intake, reassessments are overdue, evidence expired months ago, and findings from the last review are sitting in an email thread.
This scorecard measures the second thing. Twelve questions, each with five levels of observable practice, scored on what happens consistently today. It takes about ten minutes alone, and it works better as a working session with security, procurement, legal, privacy, and the business owners who actually sign the contracts.
It is a practical diagnostic, not an external certification or an industry benchmark. Interpret the result in the context of your organization's size, risk appetite, regulatory obligations, and vendor criticality.