Risk & Criticality
Define how third party risk is calculated, how tiers are banded, and how often each tier is reviewed.
| Risk factor | Applies when | Weight | Origin | Status | Actions |
|---|---|---|---|---|---|
Data sensitivity | Sensitive or high-impact data processed | +20 | System | Updated 2026-08-01 · System | |
Vendor criticality | Critical business dependency | +20 | System | Updated 2026-08-01 · System | |
Cross-border transfer | Data leaves India | +10 | System | Updated 2026-08-01 · System | |
Access level | Direct access to production systems | +10 | System | Updated 2026-08-01 · System | |
Data volume | More than 100k data principals | +10 | System | Updated 2026-08-01 · System | |
Children's data | Processes children's data | +15 | System | Updated 2026-08-01 · System | |
Sub-processors | Engages sub-processors | +5 | System | Updated 2026-08-01 · System | |
Compliance gaps | Open findings or missing certifications | +10 | System | Updated 2026-08-01 · System |
Risk tiers & thresholds
Maximum achievable score with active factors: 100. Scores are capped at 100.
0–25 Low · 26–50 Medium · 51–75 High · 76–100 Critical
Risk simulator
See exactly how a score is produced before applying it to real third parties.
Risk Score: 75 / 100
High
Why?
- Sensitive / high-impact data processed+20
- Critical business dependency+20
- Personal data leaves India+10
- High volume of data principals+10
- Engages sub-processors+5
- 2 open gap(s) / missing evidence+10
Review frequency for High: every 6 months.
