Determining the risk rating, based on guidance like the Interagency Guidance on Third-Party Relationships: Risk Management, to help better understand the risk a vendor poses to the organization based on specific categories (e.g., strategic, compliance, operational, financial). Determines the vendor’s inherent risk, which is often measured on a scale of high, moderate, or low.