Revenue Rex logo mark
💰 Financial · Rex's Toolbox

Third-Party Vendor Risk Exposure Calculator

Score and dollar-weight vendor risk from data access, criticality, and control maturity.

Revenue Rex peeking

Rex says

Money math without the spreadsheet headache. Plug in your numbers and I'll show you exactly where the dollars land.

Try a scenario

Click to load — tweak from there.

Inputs

Result

Estimated annual risk exposure

$307,500

Composite risk score (1-10)

6.2

Recommended oversight tier

High — annual review + contractual controls

Data sensitivity input

7

Control maturity input

5

Revenue Rex peeking

Psst — share this and help Rex grow

One click, a permanent link with your numbers baked in.

More financial

How to use this

  1. 1Enter data sensitivity vendor can access (1=none, 10=crown jewel pii/financial).
  2. 2Enter operational criticality if vendor is disrupted (1-10).
  3. 3Enter vendor security control maturity (1=poor, 10=excellent — soc2, mfa, insurance).
  4. 4Enter typical breach cost for your org.
  5. 5Enter share of your data/systems vendor can reach.
  6. 6Read your estimated annual risk exposure on the right — it updates as you type.
  7. 7Hit Share to keep the scenario or send it to someone.

About this calculator

Third-party and supply chain incidents (think SolarWinds, MOVEit, or a compromised managed service provider) now account for a large and growing share of major breaches, yet most vendor risk programs still rely on a static questionnaire filed away and never revisited. This calculator produces a composite risk score by weighting data sensitivity the vendor can access, how critical the vendor is to your operations, and their control maturity (based on things like whether they hold a current SOC 2 report, use MFA, and have cyber insurance), then converts that score into an estimated annual exposure dollar figure by applying it against your typical breach cost. Use it to prioritize which vendors need deeper due diligence, contractual security requirements, or continuous monitoring versus which represent immaterial risk and don't need the same scrutiny, since treating every vendor identically wastes review capacity on low-risk relationships while under-scrutinizing the handful that actually carry your crown-jewel data.

FormulaRisk score = (data sensitivity × 0.4 + operational criticality × 0.35 + (10 − control maturity) × 0.25) on a 1-10 scale. Estimated exposure = base breach cost × (risk score ÷ 10) × access scope factor.

Worked example

Using the values the calculator loads with:

Inputs

  • Data sensitivity vendor can access (1=none, 10=crown jewel PII/financial): 7
  • Operational criticality if vendor is disrupted (1-10): 6
  • Vendor security control maturity (1=poor, 10=excellent — SOC2, MFA, insurance): 5
  • Typical breach cost for your org: 2000000
  • Share of your data/systems vendor can reach: 25

Results

  • Estimated annual risk exposure: $307,500
  • Composite risk score (1-10): 6.2
  • Recommended oversight tier: High — annual review + contractual controls
  • Data sensitivity input: 7
  • Control maturity input: 5

What each field means

Inputs

Data sensitivity vendor can access (1=none, 10=crown jewel PII/financial)
The data sensitivity vendor can access (1=none, 10=crown jewel pii/financial) used in the calculation. Starts at 7 so you have a working example on load. Accepted range: 1–10.
Operational criticality if vendor is disrupted (1-10)
The operational criticality if vendor is disrupted (1-10) used in the calculation. Starts at 6 so you have a working example on load. Accepted range: 1–10.
Vendor security control maturity (1=poor, 10=excellent — SOC2, MFA, insurance)
The vendor security control maturity (1=poor, 10=excellent — soc2, mfa, insurance) used in the calculation. Starts at 5 so you have a working example on load. Accepted range: 1–10.
Typical breach cost for your org
The typical breach cost for your org used in the calculation. Starts at 2000000 so you have a working example on load.
Share of your data/systems vendor can reach
The share of your data/systems vendor can reach used in the calculation. Starts at 25 so you have a working example on load. Accepted range: 1–100.

Results

Estimated annual risk exposure
Returned as a money amount in US dollars and shown as the headline result. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
Composite risk score (1-10)
Returned as a decimal number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
Recommended oversight tier
Returned as a plain value. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
Data sensitivity input
Returned as a whole number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
Control maturity input
Returned as a whole number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.

FAQ

What counts as 'control maturity' evidence?

A current SOC 2 Type II report (not just Type I, which only tests design, not operating effectiveness), evidence of MFA enforcement, a named security contact, incident notification commitments in the contract, and active cyber insurance coverage are the baseline items most vendor risk questionnaires should verify rather than just ask about.

Why does access scope matter separately from data sensitivity?

A vendor could have access to extremely sensitive data but only for a narrow slice of your environment (like a benefits provider seeing SSNs for HR only), versus a vendor with broad infrastructure access but lower per-record sensitivity (like an MSP with admin rights across your whole network). Both create real risk, but the calculation needs to separately weight how much of your environment is actually reachable.

How often should high-risk vendors be reassessed?

Annually at minimum for critical/high-tier vendors, with immediate reassessment triggered by any vendor security incident (even one that doesn't touch your data directly), significant vendor infrastructure changes, or contract renewal, since control maturity can degrade between review cycles without any visible warning sign.

Should this replace a formal vendor risk questionnaire?

No, it's a prioritization and budget-justification tool that sits on top of your questionnaire process, helping you decide where to spend limited due-diligence time and whether to require additional contractual security terms, cyber insurance minimums, or right-to-audit clauses for your highest-exposure vendors.

Accuracy and limitations

  • Results are estimates before tax, fees, and inflation unless an input explicitly covers them.
  • Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.
  • This is educational maths, not financial advice. Check anything contractual with the lender or your accountant.

Related tools

Cite this calculator

Writing about this topic? Grab a citation — every link helps keep these tools free.

APA
RevenueLab. (2026). Vendor Risk Exposure Calculator. Retrieved from https://www.revenuelab.fyi/toolbox/vendor-risk-exposure
HTML
<p>Source: <a href="https://www.revenuelab.fyi/toolbox/vendor-risk-exposure" target="_blank" rel="noopener">Vendor Risk Exposure Calculator — RevenueLab</a> (2026).</p>
Markdown
Source: [Vendor Risk Exposure Calculator — RevenueLab](https://www.revenuelab.fyi/toolbox/vendor-risk-exposure) (2026).
Advertisement