Our approach draws on the consulting background described on our expertise page. See our editorial and quality standards for how we prepare these resources.
Risk tiers help determine how much review, evidence, approval, and monitoring a vendor relationship needs.
Vendor type alone is not enough. The same software company may be Low risk for a public newsletter tool and Critical when it stores regulated records and supports a core business process.
Working checklist
- Low: limited exposure, easy replacement, no sensitive data or meaningful access
- Moderate: some internal data or operational impact, manageable alternatives
- High: sensitive data, important systems, financial authority, or difficult replacement
- Critical: severe operational dependence, privileged access, highly sensitive data, or major legal and financial impact
A practical way to approach it
1Evaluate data
Consider sensitivity, volume, purpose, retention, and whether the vendor can access customer or employee information.
2Evaluate access
Distinguish no access, ordinary user access, integrations, administrative access, and persistent remote access.
3Evaluate business dependence
Ask what happens after four hours, one day, one week, or a permanent failure.
4Evaluate exposure
Consider money movement, legal obligations, physical safety, reputation, and customer commitments.
5Use judgment and record it
Scores support consistency, but the final tier should reflect context and explainable judgment.
Common mistakes to avoid
- Tiering solely by annual spend
- Calling every SaaS vendor High risk
- Ignoring privileged access for a small vendor
- Lowering a tier because the vendor is well known
- Failing to update the tier when the service changes
A useful tier explains the relationship’s potential impact and drives proportionate action.
Sources and further reading
- NIST Cybersecurity Framework 2.0
- NIST SP 800-161 Rev. 1: Supply Chain Risk Management
- CISA Cyber Guidance for Small Businesses
- FTC Cybersecurity for Small Business
These sources inform the methodology. Inclusion does not imply endorsement, certification, or applicability to every organization. The worked examples and decision prompts are PBW’s practical guidance.
This guidance is a general business resource, not legal, insurance, cybersecurity, or regulatory-compliance advice. Adapt it to your circumstances and obtain qualified advice when appropriate.