Fundamentals

Residual risk is a matrix, not a feeling

April 2, 2026 · 9 min read

Criticality times maturity, with tier shifts you can defend to a regulator. The full scoring model behind every Transilience grade, including the two clamps that make it honest.


Ask three risk analysts to grade the same vendor by gut and you will get three answers. A defensible TPRM program removes the gut from the final grade. Residual risk becomes a deterministic function of two inputs, inherent risk and control maturity, combined through a matrix you can write down, explain and defend. This article sets out the whole model.

Input one: inherent risk

Criticality is a weighted blend of five dimensions, each rated 1 to 4: operational impact if the vendor fails, sensitivity of the data they access, regulatory exposure the relationship creates, financial exposure, and lock-in or substitutability. The weights are not equal: data sensitivity and operational impact carry the most, financial exposure the least, because a vendor that can leak your customer data is more dangerous than one that is merely expensive. The weighted score maps to a tier: Low, Medium, High or Critical. This is the risk before any controls are considered.

Input two: control maturity

Maturity is a weighted 0 to 100 score derived from the questionnaire. Each answered control contributes a 0 to 5 rating, and higher-assurance tiers (Evidence, Effectiveness) count for more than a policy that merely exists on paper, so a vendor cannot inflate its score by writing documents it never operates. The score resolves into a band: Weak, Limited, Moderate or Strong.

A coverage gate sits in front of this. If too little of the questionnaire is answered, the maturity score is not yet allowed to move the grade, because a two-of-sixty questionnaire cannot credibly claim the vendor's controls are good or bad. Until coverage crosses the threshold, residual risk equals inherent risk.

The matrix

Residual risk is the inherent tier shifted by the maturity band. Strong, evidenced controls pull the tier down by up to two steps; Moderate controls pull it down one; Weak or absent controls push it up. The result is then clamped, and the clamp is the entire point:

These clamps are what stop the model from producing absurd grades, and they are the first thing a good regulator will probe. A model where strong paperwork can make a critical payments processor look Low is not defensible; a model that refuses to do so is.

Why regulators like a formula

Because the grade is a formula over two documented inputs, you can always answer the two questions an inspector will ask: why is this vendor graded the way it is, and what would change the grade? 'It felt about right' is not an answer. 'Critical inherent tier, Moderate maturity at 63% with 80% coverage, one band of downward credit, residual High' is an answer, and it is the same answer every time, for every reviewer.

Recompute, always

The last property that matters is freshness. Because the grade is a function of current answers and current evidence, it should recompute the moment either changes. A vendor whose SOC 2 expired last week should not still be showing last quarter's grade. When the model is deterministic and the inputs are live, the number on the board pack is today's number, and that is what turns a scoring model from a spreadsheet exercise into a control.

See it in your own portfolio

Full question bank, both portals, and transparent launch pricing by vendor volume.

See launch pricing

Keep reading

Frameworks

SEBI CSCRF, explained for vendor risk teams

The Cybersecurity and Cyber Resilience Framework changed what SEBI-regulated entities must prove about their t

Fundamentals

What is third-party risk management? A 2026 primer

Inherent risk, control maturity, residual risk: the three numbers every TPRM program runs on, why the order ma

Frameworks

RBI outsourcing directions: a vendor-by-vendor checklist

How to translate the RBI Master Directions on IT outsourcing into criticality ratings, questionnaire depth, co