Consulting-informed guidance

Our approach draws on the consulting background described on our expertise page. See our editorial and quality standards for how we prepare these resources.

Risk tiers help determine how much review, evidence, approval, and monitoring a vendor relationship needs.

Vendor type alone is not enough. The same software company may be Low risk for a public newsletter tool and Critical when it stores regulated records and supports a core business process.

Working checklist

  • Low: limited exposure, easy replacement, no sensitive data or meaningful access
  • Moderate: some internal data or operational impact, manageable alternatives
  • High: sensitive data, important systems, financial authority, or difficult replacement
  • Critical: severe operational dependence, privileged access, highly sensitive data, or major legal and financial impact

A practical way to approach it

1Evaluate data

Consider sensitivity, volume, purpose, retention, and whether the vendor can access customer or employee information.

2Evaluate access

Distinguish no access, ordinary user access, integrations, administrative access, and persistent remote access.

3Evaluate business dependence

Ask what happens after four hours, one day, one week, or a permanent failure.

4Evaluate exposure

Consider money movement, legal obligations, physical safety, reputation, and customer commitments.

5Use judgment and record it

Scores support consistency, but the final tier should reflect context and explainable judgment.

Common mistakes to avoid

  • Tiering solely by annual spend
  • Calling every SaaS vendor High risk
  • Ignoring privileged access for a small vendor
  • Lowering a tier because the vendor is well known
  • Failing to update the tier when the service changes
The practical takeaway

A useful tier explains the relationship’s potential impact and drives proportionate action.

Sources and further reading

These sources inform the methodology. Inclusion does not imply endorsement, certification, or applicability to every organization. The worked examples and decision prompts are PBW’s practical guidance.

This guidance is a general business resource, not legal, insurance, cybersecurity, or regulatory-compliance advice. Adapt it to your circumstances and obtain qualified advice when appropriate.