Gain a 360-degree view of third-party risk by using our SaaS software to centralize, track, automate, assess and report on your vendors. 

Managed Services

Let us handle the manual labor of third-party risk management by collaborating with our experts to reduce the workload and mature your program. 

Document Collection
Policy/Program Template/Consulting
Virtual Vendor Management Office
Vendor Site Audit

Ongoing Monitoring

Let us handle the manual labor of third-party risk management by collaborating with our experts.

Venminder Exchange

As Venminder completes assessments for clients on new vendors, they are then made available inside the Venminder Exchange for you to preview scores and purchase as you need.


Use Cases

Learn more on how customers are using Venminder to transform their third-party risk management programs. 


Venminder is used by organizations of all sizes in all industries to mitigate vendor risk and streamline processes

Why Venminder

We focus on the needs of our customers by working closely and creating a collaborative partnership

Sample Vendor Risk Assessments

Venminder experts complete 30,000 vendor risk assessments annually. Download samples to see how outsourcing to Venminder can reduce your workload.



Trends, best practices and insights to keep you current in your knowledge of third-party risk.


Earn CPE credit and stay current on the latest best practices and trends in third-party risk management.  

See Upcoming Webinars

On-Demand Webinars



Join a free community dedicated to third-party risk professionals where you can network with your peers. 

Weekly Newsletter

Receive the popular Third Party Thursday newsletter into your inbox every Thursday with the latest and greatest updates.



Venminder Samples

Download samples of Venminder's vendor risk assessments and see how we can help reduce the workload. 

State of Third-Party Risk Management 2023!

Venminder's seventh annual whitepaper provides insight from a variety of surveyed individuals into how organizations manage third-party risk today.


Inherent Risk vs Residual Vendor Risk

3 min read
Featured Image

Peanut butter and jelly. Batman and Robin. Some things shouldn't exist alone, and the same goes for third-party vendor inherent risk and residual risk. A robust vendor risk assessment will identify inherent risk and help you determine residual risk, so it's essential to understand the difference between the two.

Inherent Vendor Risk

Inherent risks naturally exist as part of every product or service. For example, suppose your vendor provides a service that requires accessing your organization's or its customer's sensitive data. In that case, there is always a risk of a data breach. Or, if your vendor must interact with your customers, reputation risk is always present. And, the vendor always has inherent risks to consider as well. For example, a vendor may use subcontractors to deliver your service, so there is a risk that those subcontractors are not adequately vetted or managed. Inherent risk takes many forms and exists in varying degrees, so identifying that risk is an essential first step.

Once you have identified the inherent risks, the next step is determining if the vendor has appropriate controls to manage them. Your organization's evaluation of the vendor's controls will pave the way for determining the vendor engagement's residual risk. Subject matter experts should conduct these evaluations, which should be formalized, documented, reference the specific controls, the evidence of controls provided by the vendor and include a qualified opinion regarding the controls' sufficiency.

Remember, controls should generally reduce the known risks' likelihood, occurrence, severity or impact.

inherent vs residual risk

Residual Vendor Risk

Once you have identified the risks and reviewed the vendor's controls, you can now consider the residual risk. Your residual risk rating should be based on the presence and sufficiency of vendor controls.

Here's a simple calculation:

inherent residual risk equation

Residual should never be higher than the inherent risk, so keep this in mind when making the calculation.

6 Best Practices for Third-Party Vendor Inherent Risk and Residual Risk

Keep these six tips in mind as you assess a vendor's inherent and residual risk:

  1. Inherent risk assessments are internal and should be completed by the vendor owner or those responsible for initiating the relationship. After all, these are the individuals who are most knowledgeable about the product and service and should easily be able to identify the risks.
  2. Risk should be assessed for every product and service engagement. It should not just be assessed at the vendor level.
  3. Have a formalized vendor risk management methodology in place. It's a best practice to document this within your vendor risk
    management policy.
  4. Be sure to document any forms, questionnaires or other items used to evaluate the vendor's controls.
  5. Maintain practical metrics for evaluating vendor inherent and residual risks. When used and reported appropriately, these metrics can provide insight into the amount of risk at the vendor, product or organizational levels.
  6. Periodically re-assess vendor risk as it does fluctuate. Critical and inherently high-risk vendors should be assessed at least annually.

Remember, it's essential always to document the vendor's inherent and residual risk so that you can provide this information to senior management and the board. Maintaining this information shows that you're correctly identifying and controlling the level of risk posed by any particular vendor, which can protect your organization from avoidable risks.

Subscribe to Venminder

Get expert insights straight to your inbox.

Ready to Get Started?

Schedule a personalized solution demonstration to see if Venminder is a fit for you.

Request a Demo