Vendor risk tiering is the step that decides how much effort every supplier deserves, and it is the step most programs get wrong. Treat every vendor the same and you drown in questionnaires for stationery suppliers while a payment processor gets a cursory review. Tier too loosely and your critical dependencies hide in the middle of the pack. A clear tiering model lets a small team spend its time where the risk actually sits.
This guide sets out a four-tier model, the criteria that place a vendor in each tier, a simple weighted scoring method with override rules, and how the tier should drive due diligence depth, contract terms and review frequency.
Why vendor risk tiering matters
Regulators expect proportionality. The 2023 interagency guidance on third-party relationships, issued jointly by the Federal Reserve, the FDIC and the OCC in June 2023, states that not all third-party relationships present the same level of risk and expects practices to be commensurate with the institution’s risk profile and complexity. It does not mandate a specific number of tiers, which leaves the design to you, but it does expect you to be able to explain it. You can read the issuance on the OCC bulletin page for the guidance.
The same logic applies outside banking. Security standards, privacy laws and customer contracts all expect you to manage suppliers according to risk. Vendor risk tiering is how you demonstrate that expectation is met. Our overview of the third-party risk management framework shows where tiering sits in the wider lifecycle.
The 4 tiers in a vendor risk tiering model
Three to five tiers are common. Four is a good default because it separates the genuinely critical few from the large low-risk tail without creating distinctions nobody can apply consistently. The cadences below are illustrative starting points, not requirements.
| Tier | Definition | Example | Due diligence | Review cadence |
|---|---|---|---|---|
| 1 Critical | Failure or breach would seriously harm operations, customers or compliance | Core platform, payment processor, cloud host | Full assessment, evidence review, contract clauses, exit plan | At least annually, with ongoing monitoring |
| 2 High | Significant data or process dependence, with workable alternatives | CRM, HR system, managed security provider | Detailed questionnaire and certifications | Annually |
| 3 Medium | Limited data or system access and easy substitution | Marketing tools, scheduling software | Standard questionnaire | Every two years or on change |
| 4 Low | No sensitive data, no system access, low dependence | Stationery, catering, generic subscriptions | Basic onboarding checks | On contract renewal |
Vendor risk tiering criteria that actually separate vendors
Tier on inherent risk, meaning the risk before any assessment of the vendor’s controls. If you tier on control quality, a vendor with strong controls can slide into a low tier while remaining critical to the business. Score each vendor on a small set of factors.
- Business criticality. How badly would operations suffer if the vendor failed for a day, a week or a month?
- Data sensitivity and volume. Does the vendor handle personal, financial, health or confidential data, and how much?
- System and network access. Does the vendor connect to your environment or run code in it?
- Substitutability. How long would it take to replace the vendor, and is there concentration in one provider?
- Regulatory exposure. Does the service support a regulated activity or require notification to a regulator?
- Customer impact. Would a failure directly affect customers or their data?
A simple weighted scoring model
Rate each factor from one to five, multiply by a weight and add up the result. Weights should reflect your priorities. A typical illustration gives criticality and data sensitivity the highest weights, system access and substitutability a medium weight, and regulatory exposure and customer impact a lower weight. Then set score bands for each tier and test the model on twenty known vendors. If your obvious critical suppliers do not land in tier one, adjust the weights before you roll it out.
Override rules
Scores alone can miss important cases, so add explicit overrides that force a vendor into a higher tier regardless of score. Sensible examples include any vendor that processes special category personal data, any vendor with privileged access to production systems, any single point of failure for a critical service and any vendor supporting an activity your regulator treats as critical or important. Record every override and who approved it, because reviewers will ask why a low-scoring vendor sits in tier one.
How the tier drives due diligence
The tier decides how much evidence you ask for, so define the package for each level in advance.
- Tier 4: business owner confirmation, basic company checks and a standard contract.
- Tier 3: a short security questionnaire and review of any available certifications.
- Tier 2: a detailed questionnaire, evidence of independent assurance such as a SOC 2 report or ISO 27001 certificate, and review of insurance and financial stability.
- Tier 1: everything in tier 2, plus contract clauses on audit rights, incident notification and exit support, a business continuity review, sub-supplier visibility and a documented exit plan.
Our vendor due diligence checklist shows the evidence to request, and the guide to fourth-party risk explains how to see beyond your direct suppliers.
Ongoing monitoring for the top tiers
An annual review is a snapshot, and critical vendors can change between snapshots. For tier one, add lightweight monitoring between reviews: watch for public security incidents, breach notifications, financial distress, leadership changes, outages against agreed service levels and expiry of certifications or insurance. Assign a relationship owner who receives these signals and decides whether to trigger an early review. For tier two, a simple annual attestation that nothing material has changed may be enough. Tiers three and four rarely justify monitoring beyond contract renewal, and saying so explicitly protects your team from pressure to over-assess.
Re-tiering triggers
A vendor’s tier is not permanent. Reassess whenever the relationship changes: a new type of data is shared, access is widened, the service becomes part of a critical process, the vendor changes ownership, has a security incident or is found to depend on a new sub-supplier. Also review tiers annually as a whole, because business dependence grows quietly over time. A small tool that started as a pilot may become a critical system without anyone updating the inventory.
Tie re-tiering to procurement and change management so that it happens without relying on memory. Our guide to the TPRM lifecycle covers where those checkpoints belong.
A worked example
Consider a hypothetical mid-sized firm with 120 suppliers. A payments provider scores five on criticality, five on data sensitivity, four on access and four on substitutability, so it lands firmly in tier one. A cloud email service scores four on data sensitivity and three on criticality, so it lands in tier two. A marketing newsletter tool holding customer email addresses scores lower on criticality but the personal data pushes it into tier three. A catering supplier has no data or access and lands in tier four. The exercise shows most of the 120 suppliers are tier three or four, which frees review time for the dozen that matter most.
Common vendor risk tiering mistakes
- Tiering on control quality. Tier on inherent risk, then assess controls.
- Too many tiers. Distinctions nobody can apply consistently create noise.
- No override rules. Scores miss cases such as privileged access.
- Static tiers. Dependence and data flows change, so tiers must too.
- Business owners tier their own vendors. Add a second review for tier one and two decisions.
- No link to contracts. Tier one vendors need audit, notification and exit clauses.
Start from a finished vendor risk tiering structure
You can build a tiering model in a spreadsheet in a day, but agreeing the criteria, weights and due diligence packages takes longer. The Third-Party Risk Assessment Report and Workbook gives you a ready structure covering vendor tiering, due diligence, risks, controls and a live workbook to adapt to your supplier base. For a finished case, see the third-party risk assessment example and the assessment template.
Vendor risk tiering FAQ
How many tiers should a vendor risk tiering model have?
Four is a sensible default, though three to five can work. Choose the number you can apply consistently, and make sure each tier changes what you actually do.
Should I tier vendors on inherent or residual risk?
Tier on inherent risk, because it reflects the potential impact of the relationship. Use your assessment of the vendor’s controls to determine residual risk and the actions needed within the tier.
How often should vendors be re-tiered?
Whenever the relationship changes materially and at least annually for the inventory as a whole. Trigger-based re-tiering catches changes that a calendar review misses.
Does a regulator require a specific tiering model?
Guidance such as the 2023 US interagency guidance expects risk-based, proportionate management but does not mandate a number of tiers. Check the rules that apply to your sector and record how your model meets them.
Who should approve tier assignments?
The business owner proposes the tier, and a risk or procurement function should review tier one and two decisions and any override, so ratings are not left to the team that wants the vendor.