Define third-party risk area criteria
A third-party risk area criteria is a group of risk domains (sometimes called risk areas in other platform features) that applies to a particular type of third party.
Before you begin
Role required: sn_vdr_risk_asmt.vendor_risk_manager
About this task
This is an example of the group of risk domains that you include in a risk area criteria that you might apply to IT service providers.
Note:
Risk domains are called "risk areas" in some platform applications.
Procedure
Example
- Your company is more concerned with security-related criteria, so the Security risk area has a scoring method of Average Risk and a weight of 20.
- The weights for both risk areas add up to 30. Resulting in the risk area with a weight of 10 calculating as 10/30 or roughly 33%.
- The risk area with a weight of 20 calculates as 20/30 or roughly 66%.
- If both risk areas had a weight of 10, they would each carry a weight of 50%.