Risk Assessments

 View Only
  • 1.  Risk category weights

    This message was posted by a user wishing to remain anonymous
    Posted 12-29-2023 01:28 PM
    This message was posted by a user wishing to remain anonymous

    Hello TPRM community,

    Background: I work for a community Bank. 

     I am curious as to how much weight do you put on your risk categories when conducting your risk assessment within venminder or any other tool, and why?

    For example, we place 20% weight for Operational, Cyber and Business continuity categories. However, we don't particularly have a good rationale. 

    How does everybody else decide?

    Thanks, and Happy New Year to everybody.



  • 2.  RE: Risk category weights

    This message was posted by a user wishing to remain anonymous
    Posted 12-29-2023 04:28 PM
    This message was posted by a user wishing to remain anonymous

    Our risk sections are equal in weight, with the exception of the reputational risk, which is the highest percentage. The reputational risk questions address the vendor's access to our customers' HIPPA, SSN, biometrics, and other personal identifying information as well as if the vendor has direct contact with the customer. Our risk assessment has been a collaborative effort with input from all departments within the company.