Inherent Risk
Definition
The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be: a vendor handling sensitive personal data has higher inherent risk than one providing office supplies, and therefore warrants a more rigorous evaluation.
- Field
- Third-party and vendor risk management
- Measured before
- Any controls are applied
- Drives
- Depth of the vendor assessment
- Key input
- Sensitivity of data or access the vendor handles
Common questions
How does inherent risk change the scope of a vendor assessment?+
A vendor scored as high inherent risk, such as one processing sensitive personal data, typically triggers a full questionnaire, evidence review, and possibly an onsite or independent audit. A low inherent risk vendor may only need a short screening form.
Is inherent risk a one-time rating or does it get reassessed?+
It is normally reassessed whenever the vendor relationship changes, such as new data access, a new service line, or contract renewal, because the inherent risk depends on what the vendor does, not on how well they currently do it.
Related terms
- Audit Rights Clause
- A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
- CAIQ (Consensus Assessments Initiative Questionnaire)
- A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix...
- Fourth-Party Risk
- The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's...
- SIG (Standardised Information Gathering)
- A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business...
- SOC 2 Type II Report
- An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover...