Why is residual risk different from a vendor’s security rating?
A security rating tells you how a vendor looks to the world. Residual risk tells you how much risk that vendor creates for you specifically. Consider Stripe: a SOC 2 Type II compliant, PCI DSS Level 1 certified, well-resourced payments processor. For a company sending payment card data, Stripe is a high-inherent-risk vendor — the data is sensitive, the integration is deep, and a failure would be material. For a company using Stripe only for self-service subscription billing with no access to PII beyond email addresses, the residual risk is much lower. The vendor is the same. The relationship is different.
What factors drive residual risk?
Residual risk in vendor relationships is a function of: (1) Inherent risk — the sensitivity of data shared, the criticality of the integration, and the vendor’s role in your product or operations; (2) Control effectiveness — the vendor’s certifications, their SOC 2 posture, their subprocessor governance, and their incident history; (3) Evidence freshness — how current the evidence supporting the control assessment is, weighted by the half-life of each evidence type; and (4) Your own mitigations — contractual terms, DPAs, data minimization, encryption at rest and in transit, and break-glass procedures.
How does TrustVendor compute residual risk?
TrustVendor’s residual risk model combines two objective scores — posture (control coverage) and assurance (evidence freshness) — with your relationship-specific inputs: the data classes you share, the integration criticality you assign, and any custom mitigations you document. The computation is deterministic arithmetic over stored claims, not a black box. Every recomputation is versioned and replayable, so you can audit why a score changed. This is the property that makes the score defensible to an auditor.
How do you use residual risk to prioritize work?
Sort your vendor portfolio by residual risk descending. The top of the list is where your risk analysts should spend time. Vendors below a defined threshold can be handled through automated monitoring alone, with human review triggered only by material signal events. This inverts the traditional annual calendar-based review cycle: instead of reviewing every vendor every year regardless of what has changed, you review vendors when evidence says something has changed.