Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Contact Us
  • Home
  • User Guides
  • Third-Party Management
  • Risk Score

Engagement Risk Areas, Risk Score, & Risk Level

Written by Michelle Henley

Updated at January 7th, 2025

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Home
  • User Guides
    Approvals & Disclosures Third-Party Management Compliance Monitoring
  • Integrity Gateway Configuration Guide
    Approvals & Disclosures Request Types Configurable Components FAQ
  • Service Desk FAQ
  • Release Notes
    Release Notes - Approvals & Disclosures/ Third Party Management Release Notes - Compliance Monitoring
  • Roadmap
+ More
  • User Guides

    • Integrity Gateway Configuration Guide

      • Service Desk FAQ

        • Release Notes

          • Roadmap

            Each engagement created with a Third-Party within the Third Party Management (TPM) product is scored based on the responses to the questions in the Business Rationale Questionnaire (BRQ) and Due Diligence Questionnaire (DDQ). 

            Note: Depending on your organization’s specifications during our onboarding, variations in how Risk Scoring works for your organization may exist.  The instructions below are meant as a general guideline only.

             

            Risk Score Privilege

            In order to view the Risk Score/ Risk Level an approver or an admin must have the following privilege:

            Privilege Name Description
            Adjust engagement risk score Gives the user the capability to view and adjust the risk score assigned to a Third-Party engagement.
            View engagement risk score Gives the user the capability to view the risk score assigned to a Third-Party engagement.
             
             

            How to View Risk Score & Risk Level within a Request

            First, to locate the Risk Score of a particular engagement, click the Risk Score tab within the TPM request. 

            Answers from both the Business Rationale Questionnaire (BRQ) and the Due Diligence Questionnaire (DDQ) are used to calculate the score for the Risk Areas.

            Each Risk Area can be expanded by clicking on the Down Arrow to the left of the Risk Areas. When expanded, the Risk Area scores applied to each question of the BRQ and DDQ are displayed. The third column from the left shows which questionnaire the response was provided (Either the BRQ or Ethics and Integrity Questionnaire (DDQ). 

            The scores for the Risk Areas are then used to calculate the Overall Risk Score and Risk Level. 

            Note: The Risk Score on the left is used to calculate the Risk Level on the right. 0 being the lowest possible score and 5 being the highest possible score.

             
             

            How is the Risk Area, Risk Score, and Risk Level calculated?

            Note: Note the following configurations are possible within the system, however, specific methodology is configured for your organization during the onboarding process and may vary. 

             
            • Each Engagement in the Third-Party Management product must be risk scored. Risk scoring cannot be turned off in the system. 
            • Questions from both the Business Rationale Questionnaire (BRQ) and the Due Diligence Questionnaire (DDQ) are used to calculate the score for the Risk Areas.
            • The default risk scoring configuration takes into account the most commonly used questions across our multiple clients.
            • Conditional questions can be included in risk scoring. However, they will be treated as NULL/None.
            • Risk Score, Risk Level, or Risk Area cannot be adjusted by a user manually, unless the user has the Adjust Risk Score privilege. 

            Risk Areas, Profile%, and Profile+ Risk Score Configuration

            Tenants can have any number of Risk Areas, which can be named based on Tenant preference. 

            As a baseline, we offer the following Risk Areas:

            • Ethics & Compliance (combined or separated below)
            • Anti-Bribery & Anti-Corruption 
            • Animal Welfare
            • Competition
            • Patient Safety
            • Anti-Money Laundering
            • Trade & Export Controls
            • Off-Label Promotion
            • Privacy and Information Security (combined or separated below)
            • Privacy 
            • Information Security
            • Human Rights & Labor
            • Health & Safety
            • Environment & Sustainability
            • Operational & Financial
            • Legal 
            • Financial
            • Business Continuity
            • Political 

            Once the Risk Areas are selected by the tenant, the questions from the Business Rationale Questionnaire (BRQ) and the Due Diligence Questionnaire (DDQ) are then mapped to one or more selected Risk Areas. 

            Next, when configuring an organization's Profile% and Profile+ Risk Score, tenants will be asked to give a score to each Country, Third-Party Type, Business Unit, and more. 

            In addition to the score, Profile% and Profile+ can be configured to add absolute points to the weight score of answers provided within BRQ and DDQ. Giving a BRQ or DDQ element an additional score through the Profile+ Components ensures that higher risk scenarios are correctly identified. 

            The final Risk Results Score of the BRQ and DDQ answers are used to calculate the Risk Area score. Note: If the same question is scored in different Risk Areas the highest score is applied. 

            The Overall Risk Score is then calculated based on all the Risk Area scores. The weight of each Risk Area Score is determined by the tenant. For example, 25% Bribery & Corruption, 25% Sanctions & Trade, 30% Information Security & Data Privacy, and 20% Reputational & Legal. 

             The Overall Risk Score on the left is used to calculate the Risk Level on the right. 0 being the lowest possible score and 5 being the highest possible score.

             
             
            engagement rate risk rating

            Was this article helpful?

            Yes
            No
            Give feedback about this article
            Print to PDF

            Related Articles

            • Approving Third-Party Engagement Requests
            • How to Submit a Third-Party Engagement
            • Third-Party Due Diligence Making Changes on a Request Post - Submission
            • How can I identify the Third-Party an external user is associated with?

            Knowledge Base Software powered by Helpjuice

            Expand