Guide · Risk scoring

How vendor risk and health scoring works

RiskBee scores a vendor twice, for two different purposes: an inherent risk score the moment you add them, before any evidence exists, and a health score once assessments and evidence come back. Knowing which one you are looking at makes the numbers on a vendor record much easier to read.

Last updated: 2026-08-28

Inherent risk: what you know before any evidence

When you add a vendor, RiskBee estimates inherent risk from what you tell it at intake: a data sensitivity classification (categories like PHI, PCI, biometric or credential data weigh heaviest; PII, financial, confidential and communications data next; employee, customer and telemetry data less again; public data not at all) and access level (from none up to privileged, with an added weight for vendors who get on-site physical access). These combine into a score that buckets into low, medium, high or critical - and business criticality separately sets the vendor's tier: Critical, Important or Low impact. Tier matters beyond the score itself: it is what should drive how deep a questionnaire you send.

Health score: what the evidence actually shows

Once a vendor has completed an assessment, the risk dashboard shifts to an evidence-based health score built from three domains. Every questionnaire question is tagged to one of them and carries its own risk weight; an answer scores automatically, or is auto-credited if it is already covered by an active certification such as SOC 2 or ISO 27001.

Security - 50%

The largest share of the score. Driven by questionnaire answers and evidence mapped to security categories, weighted by each question's risk weight.

Privacy - 30%

Covers data handling, sub-processors and privacy-related controls answered in the assessment.

Compliance - 20%

Covers certifications, regulatory posture and framework alignment reported by the vendor.

Each domain nets out earned versus possible points, minus a penalty for gaps in evidence, before the three combine into the overall score shown on the vendor's risk dashboard. That score is then adjusted by external attack-surface signals (TLS, DMARC, SPF and certificate expiry, capped at a small share of the total), any contract risk flags on file, and a labour/modern slavery sub-score where relevant. A single critical finding caps the score at a level that forces a failing grade regardless of everything else - a "fatal flaw" rule that keeps one serious gap from being averaged away by good answers elsewhere. The resulting number maps to a letter grade, A through F, shown alongside a breakdown by domain.

Where to see it

The vendor risk matrix lists every vendor with its current score, tier and last review date, and can be filtered by criticality. Opening a vendor's risk dashboard expands into the domain breakdown and shows exactly which answers or missing evidence are pulling the score down - the same evidence you collect when sending a security questionnaire.