Vendor risk tier.
Twenty seconds per vendor.Three questions classify any vendor into the tier that decides its review depth — the same logic from our due diligence checklist, as a calculator.
Why tier vendors at all?
Because uniform diligence fails in both directions — deep reviews of the swag vendor waste hours while the logging vendor holding customer data gets a glance. Tiering matches review depth to actual risk, and auditors sample the tiering rationale itself.
How do auditors test vendor tiers?
They pick vendors and ask how you decided the tier and whether the promised diligence happened — the SOC 2 report on file, the review dated, the DPA signed. A recorded tier with rationale answers in seconds.
What if a vendor lands in Critical and we can't get their SOC 2?
Fall back the standard ladder: completed CAIQ or SIG Lite, public trust page, contractual security terms with breach clocks. A critical vendor offering none of those is itself the finding — and the answer to whether to keep them.