Guide

Third Party Risk Program Maturity Scorecard

Twelve observable questions that score how your third party risk program actually operates today, not how the policy describes it. Each question maps to a five level maturity scale from Reactive to Continuous, with the specific practice that defines each level. The result gives you an overall maturity level, the three lowest scoring areas to fix first, and a worksheet to assign each one an owner and a date. Built to be completed in a working session with security, procurement, legal, privacy, and business owners.

What You'll Learn

  • Score twelve areas of your vendor risk program against observable practice, from inventory and ownership through incident readiness and audit trail
  • Identify which of the five maturity levels your program actually operates at, and what typically breaks at that level
  • Find the three gaps most likely to leave risk unmanaged, even when your average score looks healthy
  • Test whether your program detects material vendor change between formal assessments, or waits for the next scheduled review
  • Check whether your due diligence obligations are actually carried into contract terms, including notification, evidence rights, and subcontractor change notice
  • Convert the result into a prioritized improvement plan with named owners and dates

Download for free