Skip to main content
Category: Ratings and Risk Tiering

Risk Rating

Also known as: risk rating score, risk criticality rating
Simply put

A risk rating is a label or score that classifies a risk into a defined level of severity, such as low, medium, or high, based on how likely it is to occur and how much harm it could cause. In third-party and supply chain contexts, it helps an organization prioritize which suppliers, vendors, or relationships warrant closer attention. A risk rating summarizes judgment about a risk; it does not by itself eliminate or resolve that risk.

Formal definition

A risk rating is the output of classifying a given risk into pre-determined criticality levels (for example, low/medium/high) as a function of estimated likelihood and impact. It is a component or product of a broader risk assessment process rather than a synonym for the assessment itself, and methodologies vary by domain: credit risk rating focuses on the likelihood and consequence of counterparty default, compliance risk rating estimates the risk of doing business with a given individual or entity, and security-oriented approaches such as the OWASP Risk Rating Methodology estimate the likelihood of a successful attack. A rating typically reflects a defined scope of risk factors and may capture inherent risk, residual risk, or both, depending on the methodology; practitioners should confirm which is being rated, since a rating does not inherently distinguish the two. Ratings are commonly point-in-time and may be based on self-reported or unverified inputs, so they can become stale and may not reflect risks outside the factors and tiers the methodology considers.

Why it matters

A risk rating gives an organization a shared vocabulary for prioritization. When a program is monitoring many suppliers, vendors, and business partners, ratings such as low, medium, or high let teams direct finite due diligence and monitoring resources toward the relationships that could cause the most harm, rather than treating every counterparty identically. Without a rating scheme, prioritization tends to become inconsistent and difficult to defend to auditors, regulators, or internal governance bodies.

The value of a risk rating depends heavily on the methodology behind it, and this is where programs often stumble. A rating is the product of estimates about likelihood and impact, not a resolution of the underlying risk; assigning a supplier a 'high' rating does nothing on its own to reduce exposure. Ratings can also be misread when practitioners do not confirm whether a given score reflects inherent risk, residual risk, or both, since the same label can mean very different things across methodologies. Ratings drawn from self-reported or unverified inputs carry the additional weakness that they may overstate a counterparty's actual posture.

Because ratings are commonly point-in-time, they can grow stale as a supplier's circumstances, ownership, financial health, or security posture change. A rating captured at onboarding may not reflect present conditions, and it may say nothing about risk factors or supply chain tiers that the methodology never considered. Treating a rating as a durable, comprehensive verdict rather than a scoped snapshot is a recurring source of misplaced confidence in third-party and supply chain programs.

Who it's relevant to

Third-Party Risk and Vendor Management Teams
These teams use risk ratings to triage a large population of vendors and business partners, directing deeper due diligence and more frequent monitoring toward higher-rated relationships. They should confirm whether ratings reflect inherent or residual risk and treat point-in-time scores as inputs that require periodic refresh rather than standing conclusions.
Procurement and Sourcing Professionals
Ratings help inform supplier selection and prioritization decisions during onboarding. Procurement teams benefit from understanding that a favorable rating built on self-reported inputs is not the same as independently verified assurance, and that the rating's scope may exclude factors relevant to a particular sourcing decision.
Credit and Financial Risk Analysts
For counterparties where financial exposure is a concern, credit risk rating focuses on the likelihood and consequence of default. Analysts should recognize that a credit-oriented rating addresses financial stability and may not capture security, compliance, operational, or geopolitical dimensions of the same relationship.
Compliance and Financial Crime Teams
Compliance-oriented risk rating estimates the risk of doing business with a given individual or entity, supporting decisions about the depth of scrutiny a relationship warrants. These teams should treat such ratings as scoped to the compliance factors considered and refresh them as circumstances and available information change.
Security Assessment Practitioners
Security-focused approaches such as the OWASP Risk Rating Methodology estimate the likelihood of a successful attack. Practitioners applying these methods should be clear that the resulting rating addresses a defined set of security factors and does not, on its own, cover financial, contractual, or broader supply chain risk.

Inside Risk Rating

Risk Scoring Methodology
The defined logic used to translate assessment inputs into a rating, whether qualitative (e.g., high/medium/low), quantitative (numeric scores), or a hybrid. The methodology specifies how individual factors are weighted and combined, and depending on the program may vary by risk domain.
Inherent Risk Rating
A rating that reflects the level of risk before controls or mitigations are applied, typically derived from factors such as the nature of the service, data accessed, criticality, and spend. It is distinct from the residual rating and should not be conflated with it.
Residual Risk Rating
A rating that reflects the remaining risk after accounting for the third party's controls and any mitigations. It depends on the reliability of the evidence used to assess those controls, which in many programs is partly self-reported.
Risk Domains Covered
The specific categories a rating addresses, which may include information security, financial stability, operational resilience, geopolitical exposure, or ESG. A single rating often does not cover all domains, and the scope of what is and is not reflected should be stated explicitly.
Risk Tiering
The grouping of third parties into tiers based on their rating, which typically drives the depth of due diligence, frequency of reassessment, and level of ongoing monitoring applied to each relationship.
Data Inputs and Evidence
The sources feeding the rating, such as questionnaire responses (e.g., SIG), independent attestations or reports (e.g., SOC 2), external threat intelligence, and financial data. The strength of a rating depends on whether inputs are independently verified or self-attested.

Common questions

Answers to the questions practitioners most commonly ask about Risk Rating.

Does a risk rating represent residual risk after controls are applied?
Not necessarily. A risk rating may reflect inherent risk, residual risk, or a blend, depending on how the program defines it. Inherent risk describes exposure before accounting for the third party's controls, while residual risk reflects exposure after those controls are considered. Because the two can differ substantially, it is important to confirm which basis a given rating uses rather than assuming it captures the post-control position.
Is a high risk rating the same as saying a third party has poor security or is likely to fail?
No. A risk rating is a prioritization signal, not a verdict on a third party's actual performance or a prediction of failure. A rating often reflects the criticality of the service, the sensitivity of data involved, or the potential impact of disruption, meaning a well-controlled vendor can still carry a high rating simply because of what it supports. The rating indicates the level of scrutiny warranted, not a conclusion about the vendor's quality.
What factors typically feed into assigning a risk rating?
Programs commonly combine factors such as the sensitivity of data accessed or processed, the criticality of the service to operations, spend or contractual exposure, regulatory relevance, and geographic or geopolitical considerations. The specific inputs and their weighting vary by program and by the type of risk being assessed, since a rating focused on information security may not capture financial, operational, or ESG dimensions.
How often should a risk rating be reviewed once assigned?
A risk rating is typically point-in-time and can become stale as the relationship, the services provided, or the external environment changes. Many programs re-evaluate ratings on a defined cycle tied to the risk tier, and also trigger reassessment when a material change occurs, such as a new data flow, a change in scope, or a significant event affecting the third party. Without periodic refresh, a rating may no longer reflect current exposure.
How do risk ratings connect to the depth of due diligence a third party receives?
In many programs, the risk rating drives the tier of assessment applied, so higher-rated relationships receive more extensive due diligence and more frequent ongoing monitoring, while lower-rated ones receive lighter review. This tiering helps allocate limited assessment resources, but it also means a mis-assigned rating can lead to insufficient scrutiny of a consequential relationship.
What are the main limitations to be aware of when relying on a risk rating?
Ratings often depend on self-reported inputs that may not be independently verified, reflect a single point in time, and may be scoped to only certain risk categories rather than the full range of financial, operational, geopolitical, and ESG exposure. They also typically focus on the direct third party and may not capture fourth-party or Nth-party dependencies. Treating a rating as a complete or standalone measure of risk can overstate the assurance it provides.

Common misconceptions

A risk rating reflects the current, real-time risk posture of a third party.
Most ratings are point-in-time and can become stale as the third party's environment, controls, financial condition, or geopolitical exposure change between assessments. Continuous or periodic reassessment is typically needed to keep a rating meaningful.
A low residual risk rating means the risk has been eliminated or that no monitoring is needed.
A residual rating reflects remaining risk after controls are considered; it does not remove risk. It also often relies on self-reported information that lacks independent validation, so a favorable rating does not guarantee the controls operate as described.
A single risk rating captures a third party's overall risk across all dimensions.
A rating typically addresses defined domains and scope. A rating focused on information security, for example, may not reflect financial, operational, geopolitical, or ESG risk, and may cover only the direct third party rather than fourth-party or Nth-party exposure.

Best practices

Document the scoring methodology, including which factors are weighted and combined, and state explicitly which risk domains the rating covers and which it does not.
Maintain separate inherent and residual ratings, and avoid presenting one as the other so that the effect of controls and the value of mitigations remains transparent.
Use risk tiering derived from ratings to calibrate due diligence depth, reassessment frequency, and ongoing monitoring rather than treating all third parties uniformly.
Distinguish self-attested inputs from independently verified evidence when assigning a rating, and weight or caveat the rating accordingly.
Treat ratings as point-in-time and pair them with periodic reassessment or continuous monitoring so that changes in a third party's posture are reflected before they become stale.
Note the scope limits of each rating, including whether it extends beyond the direct third party to fourth-party or Nth-party dependencies, and communicate those boundaries to stakeholders.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps