This feature is currently in Early Access. Learn how to turn it on for your organization here.
When a business partner completes a vendor intake form, SecurityScorecard scores the answers to calculate the vendor's inherent risk tier. The tier determines how you triage the vendor and which questionnaire template the platform sends next. This article explains how the calculation works and lists the default point values and thresholds that a new form starts with. Every value described here is configurable per organization in form settings.
How scoring works
Each intake question is either informational or risk-scored. Of the default questions, 6 do not contribute to the score (owner, business unit, status, contract dates, external ID, and the vendor contact email) and 8 contribute to the inherent risk tier. The platform calculates the tier as follows:
- Each answer option on a risk-scored question carries a point value that reflects how much risk it represents.
- On questions where more than one answer can apply, only the highest-scoring selected option counts. Selecting several options does not stack the score; it reflects the most severe option that applies.
- The platform adds the points from all 8 risk-scored questions, then converts the total into a 0–100 score as a percentage of the maximum possible total.
- That score maps to a tier using your organization's configured thresholds.
The default thresholds are Low 0–34, Medium 35–59, High 60–84, and Critical 85–100. The maximum possible raw total is 108 points, which normalizes to 100.
Default question points
The table below summarizes how much each of the 8 risk-scored questions can contribute and how respondents answer it. You can edit any point value in form settings.
| Question | Maximum points | Selection |
| Data types shared with this vendor | 38 | Select all; highest counts |
| How the vendor interacts with your data | 22 | Select all; highest counts |
| Business impact of an outage or breach | 22 | Select one |
| Vendor access type | 18 | Select all; highest counts |
| Type of service provided | 2 | Select one |
| Where the vendor stores or processes data | 2 | Select all; highest counts |
| Estimated volume of records or individuals affected | 2 | Select one |
| AI / machine learning involvement | 2 | Select one |
The four highest-weight questions are detailed below. The four low-weight modifiers, each worth at most 2 points, follow as a short list.
Data types shared with this vendor (select all that apply; highest applicable counts)
| Answer | Points |
| PHI | 38 |
| Credentials / secrets | 38 |
| Financial | 27 |
| Sensitive | 27 |
| PII | 24 |
| Intellectual property | 24 |
| Public / non-sensitive, none, or n/a | 0 |
Vendor access type (select all that apply; highest applicable counts)
| Answer | Points |
| Privileged / admin access | 18 |
| Physical on-site access | 11 |
| Handles hardware | 9 |
| API integration | 6 |
| Remote network access | 5 |
| None / n/a | 0 |
Business impact of an outage or breach (select one)
| Answer | Points |
| Critical | 22 |
| High | 19 |
| Medium | 10 |
| Low | 3 |
| None / n/a | 0 |
How the vendor interacts with your data (select all that apply; highest applicable counts)
| Answer | Points |
| Stores data | 22 |
| Creates data | 16 |
| Processes data | 9 |
| Accesses only | 3 |
| N/a | 0 |
The remaining four questions are light modifiers. Each adds at most 2 points:
- Type of service provided (select one): data provider and outsourcing / BPO score 2; SaaS, managed service, professional services, or other score 1; hardware/equipment scores 0.
- Where the vendor stores or processes data (select all that apply; highest applicable counts): an unknown region scores 2, multiple regions score 1, and any single named region or n/a scores 0.
- Estimated volume of records or individuals affected (select one): 100,000+ records score 2; 1,000–100,000 records or an unknown volume score 1; fewer than 1,000 or n/a scores 0.
- AI/machine learning involvement (select one): generative AI scores 2; traditional AI / ML or an unknown status score 1; no AI scores 0.
Design principles
The default model reflects a few deliberate choices that help you interpret and adjust the scores:
- Data type, access level, and business impact carry the most weight, because they are the strongest individual signals of inherent risk. Service type, data volume, residency, and AI involvement are intentionally light modifiers.
- Data residency does not penalize any specific country or region. Only uncertainty ("unknown") or complexity ("multiple regions") adds points, so the model never implies that a particular jurisdiction is inherently risky.
- These values are starting defaults, not a fixed model. An admin can edit every point value and threshold in form settings.