Cybersecurity Risk & Third-Party Risk Assessment: A Methodology That Survives an Audit
A representative risk and third-party risk methodology — from asset and vendor scoping through inherent risk, control evidence, residual risk, and treatment — aligned to SG2'scompliance and risk practice.
Executive Summary
Most vendor programs collect answers and stop there — no common scoring model, no evidence standard, no clear line from a concerning answer to a treatment. This methodology turns the questionnaire into a decision, and does it the same way every time: score inherent risk before controls, demand evidence not attestations, and track residual risk to an owner and a date — so the results hold up when an auditor or the board asks how a particular vendor got approved.
Business Challenges
Reference Workflow
Assessment Workflow
Domain & Scope Definition
Asset, process, and vendor risk domains defined — what each vendor touches, and what breaks if they fail or are breached.
Threat, Vulnerability & Likelihood
Realistic threat model per vendor class, plausible weaknesses, and the probability of a material incident.
Impact Assessment
Business consequence scored across regulatory, financial, operational, and reputational dimensions.
Inherent Risk Scoring
Likelihood × impact, before controls — this score sets due-diligence depth, evidence bar, and reassessment cadence.
Control & Evidence Evaluation
Control design plus operating evidence — a current SOC 2 Type II, a pen-test summary, architecture docs — not attestations. Claims without evidence become their own finding class.
Residual Risk
What remains after controls are accounted for — the number that drives the approve / conditions / reject decision.
Treatment & Escalation
Accept, mitigate, transfer, or avoid — each with an owner, a target date, and an escalation threshold if the date slips.
Capabilities
Common Scoring Model
- • One inherent/residual scale for internal and vendor risk
- • Documented tiers and thresholds
- • Consistent across assessors and over time
Evidence Standard
- • Evidence required per control, not attestations
- • Evidence exceptions tracked as findings
- • Expired certifications flagged automatically
Risk Register
- • Living register with owners and review dates
- • Internal and third-party risk in one place
- • Board- and auditor-ready views
Treatment Workflow
- • Accept / mitigate / transfer / avoid decisions
- • Target dates and escalation thresholds
- • Re-attestation and event-driven triggers
Third-Party Due Diligence
- • Questionnaire structured to the scoring model
- • Risk-tiered assessment depth
- • Onboarding and periodic re-review cycles
Reporting
- • High-risk vendor tracking
- • Assessments-due and overdue views
- • Residual-critical items awaiting treatment
Key Deliverables
Risk assessment methodology · risk register · third-party questionnaire structure · control and evidence assessment · residual-risk scoring · treatment and escalation workflow.
Example Management View
Illustrative figures for a mid-size vendor portfolio — not a measured project result.
Outcomes This Methodology Typically Targets
Representative, not measured — see the note at the top of this page.
Works With
Frequently Asked Questions
Common questions from enterprise and mid-market teams across India and internationally.
Why score inherent risk before looking at controls?
What counts as evidence versus an attestation?
How is residual risk different from inherent risk?
How often should vendors be reassessed?
Is this a Representative Implementation or a named-client case study?
Could you explain how your last vendor got approved?
Talk to our GRC team about standing up a repeatable risk and third-party risk methodology.
