Residual risk is a matrix, not a feeling
Criticality times maturity, with tier shifts you can defend to a regulator. The full scoring model behind every Transilience grade, including the two clamps that make it honest.
Ask three risk analysts to grade the same vendor by gut and you will get three answers. A defensible TPRM program removes the gut from the final grade. Residual risk becomes a deterministic function of two inputs, inherent risk and control maturity, combined through a matrix you can write down, explain and defend. This article sets out the whole model.
Input one: inherent risk
Criticality is a weighted blend of five dimensions, each rated 1 to 4: operational impact if the vendor fails, sensitivity of the data they access, regulatory exposure the relationship creates, financial exposure, and lock-in or substitutability. The weights are not equal: data sensitivity and operational impact carry the most, financial exposure the least, because a vendor that can leak your customer data is more dangerous than one that is merely expensive. The weighted score maps to a tier: Low, Medium, High or Critical. This is the risk before any controls are considered.
Input two: control maturity
Maturity is a weighted 0 to 100 score derived from the questionnaire. Each answered control contributes a 0 to 5 rating, and higher-assurance tiers (Evidence, Effectiveness) count for more than a policy that merely exists on paper, so a vendor cannot inflate its score by writing documents it never operates. The score resolves into a band: Weak, Limited, Moderate or Strong.
A coverage gate sits in front of this. If too little of the questionnaire is answered, the maturity score is not yet allowed to move the grade, because a two-of-sixty questionnaire cannot credibly claim the vendor's controls are good or bad. Until coverage crosses the threshold, residual risk equals inherent risk.
The matrix
Residual risk is the inherent tier shifted by the maturity band. Strong, evidenced controls pull the tier down by up to two steps; Moderate controls pull it down one; Weak or absent controls push it up. The result is then clamped, and the clamp is the entire point:
- A low-impact vendor with terrible controls tops out at Medium. It simply cannot hurt you enough to be Critical, no matter how bad its security.
- A Critical vendor with weak controls stays Critical. No amount of paperwork talks a genuinely critical dependency down to comfortable.
- Below the coverage threshold, residual risk equals inherent risk, because you have not yet learned enough to move it.
These clamps are what stop the model from producing absurd grades, and they are the first thing a good regulator will probe. A model where strong paperwork can make a critical payments processor look Low is not defensible; a model that refuses to do so is.
Why regulators like a formula
Because the grade is a formula over two documented inputs, you can always answer the two questions an inspector will ask: why is this vendor graded the way it is, and what would change the grade? 'It felt about right' is not an answer. 'Critical inherent tier, Moderate maturity at 63% with 80% coverage, one band of downward credit, residual High' is an answer, and it is the same answer every time, for every reviewer.
Recompute, always
The last property that matters is freshness. Because the grade is a function of current answers and current evidence, it should recompute the moment either changes. A vendor whose SOC 2 expired last week should not still be showing last quarter's grade. When the model is deterministic and the inputs are live, the number on the board pack is today's number, and that is what turns a scoring model from a spreadsheet exercise into a control.
See it in your own portfolio
Full question bank, both portals, and transparent launch pricing by vendor volume.
See launch pricing