Skip to content

Inherent Risk

Definition

The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be: a vendor handling sensitive personal data has higher inherent risk than one providing office supplies, and therefore warrants a more rigorous evaluation.

Field
Third-party and vendor risk management
Measured before
Any controls are applied
Drives
Depth of the vendor assessment
Key input
Sensitivity of data or access the vendor handles

Common questions

How does inherent risk change the scope of a vendor assessment?+

A vendor scored as high inherent risk, such as one processing sensitive personal data, typically triggers a full questionnaire, evidence review, and possibly an onsite or independent audit. A low inherent risk vendor may only need a short screening form.

Is inherent risk a one-time rating or does it get reassessed?+

It is normally reassessed whenever the vendor relationship changes, such as new data access, a new service line, or contract renewal, because the inherent risk depends on what the vendor does, not on how well they currently do it.

Related terms

Audit Rights Clause
A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
CAIQ (Consensus Assessments Initiative Questionnaire)
A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix...
Fourth-Party Risk
The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's...
SIG (Standardised Information Gathering)
A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business...
SOC 2 Type II Report
An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.