Skip to main content
VISO TRUST produces two risk scores for every vendor: inherent risk and residual risk. Understanding how these are calculated helps you interpret what the scores mean and how to act on them.

The Core Formula

Everything in the VISO TRUST risk model flows from a single industry-standard principle:
Impact answers: If this vendor were compromised, how bad could it be? Likelihood answers: How likely is something to go wrong? Both values are numeric (0 to 1 internally) and combine to produce an inherent risk score. Residual risk then factors in how much risk the vendor’s actual controls reduce.

Step 1 — Establish Impact

Impact is driven by data sensitivity — the types of data your vendor handles. The most sensitive data type selected for the relationship sets the impact score. Data types fall into sensitivity levels — None, Minimal, Moderate, Elevated, and Critical. A vendor handling payment card data (Critical) starts with a higher impact score than one handling only low-sensitivity data (Minimal). See Data Types for the full list of data types and their sensitivity levels.

Step 2 — Assess Likelihood (Threat Surface)

Likelihood is driven by threat surface — how the vendor interacts with your environment. This is determined by the business cases selected when configuring relationship context. Business cases capture factors like:
  • Does the vendor store or process your data?
  • Does the vendor have privileged access to your systems?
  • Does the vendor operate a production environment?
  • Does the vendor have physical access to your facilities?
Each business case brings relevant control domains into scope and contributes to the likelihood score.

Step 3 — Determine Controls in Scope

Not all security controls matter equally for every vendor. Based on the business cases selected, VISO TRUST automatically determines which control domains are relevant for the assessment. A SaaS vendor on a hyperscale cloud needs different controls validated than a vendor with physical server access. Controls in scope define what evidence must be collected and reviewed.

Step 4 — Gather and Weigh Evidence

VISO TRUST collects evidence from multiple sources:
  • Independent audits (SOC 2, ISO 27001, HITRUST, PCI DSS)
  • Security policies and procedures
  • Technical assessments (penetration tests)
  • Questionnaire responses
  • Publicly available artifacts and certifications
Each piece of evidence is weighted based on three factors:

Step 5 — Calculate the Scores

Inherent Risk is the starting point — potential risk before any controls are considered. It reflects Impact × Likelihood based solely on relationship context. Residual Risk is the end point — inherent risk minus credit for proven controls. Risk only goes down when there’s verified evidence. A vendor that claims good security practices but can’t prove them gets no credit. Both scores are mapped to risk labels: Label names and the thresholds that map to them can be customized to align with your organization’s risk language. See Your Risk Model.

Predicted vs. Validated Scores

VISO TRUST provides two flavors of risk scores: Predicted — calculated immediately when a relationship is created using publicly available data and vendor profile information. Provides an immediate estimate before any documentation is reviewed. Validated — calculated after evidence has been submitted and analyzed through an assessment. More accurate and carries higher confidence. As assessments complete and evidence is added, predicted scores are replaced by validated scores. You can see which score type is displayed on any relationship.

What Drives Score Changes

Risk scores update automatically when:
  • New artifacts are uploaded or analyzed
  • Business cases or data types are changed
  • Artifacts expire (reducing assurance on previously credited controls)
  • New risk advisories are detected (flagged as pending changes)
  • An assessment update runs
Focus on residual risk when prioritizing your workload — it’s the most actionable number. A vendor with high inherent risk but strong controls may be lower priority than one with medium inherent risk but unvalidated controls.