Skip to main content

Risk Policy

Updated over 3 weeks ago

The Risk Policy in Panorays allows your organization to customize how third-party Cyber Risk Ratings are calculated. You can adjust weighting, apply additional factors, and create custom factors to ensure risk scores reflect your company’s policies and priorities.

✅Weighting Methodology

Customize the calculation of your bottom-line risk score by adjusting the weights assigned to the questionnaires and the cyber posture assessment.

Include or exclude questionnaires or cyber assessments from the final risk rating score.


✅Additional and Custom Factors Impact

The Additional Factors component lets you include items in the overall risk rating beyond the Cyber Posture Rating and Security Questionnaire. You can also create custom factors to add or reduce points based on your company’s risk policies.

Default Additional Factors

The following factors are included by default:

Factor

Single Event

Multiple Events

Impact of Critical Criteria

-8

-16

Impact of important questions answered out of policy

-6

-12

Impact of an expired questionnaire

-10

Critical Cyber Alerts

Last 12 months: -5

Last 3 months: -10

Certifications & Complience

Single Certification: +5

Multiple Certifications: +10


Custom Factors

You can create custom factors to adjust risk scores for specific suppliers:

  • Add or reduce points based on your policies

  • Assign the factor to specific suppliers

  • Optionally require a document upload for the factor

  • Enable impact overrides for individual suppliers

In a supplier’s profile, add the factor under “Custom Factor”.

Once applied, the points are automatically reflected in the supplier’s risk rating.

Custom factors also appear in the “View More” list of additional factors for easy reference.

Why use custom factors?

  • Align risk ratings with your company policies

  • Reflect real-world priorities and risk scenarios

  • Maintain flexibility in vendor assessment scoring


✅Risk Rating Matrix

The Panorays Cyber Risk Rating is calculated using a risk matrix that combines:

  • Impact – based on the supplier’s Business Impact

  • Combined Score – derived from both the Cyber Posture Rating and the Smart Questionnaire Rating

Together, these factors determine the final risk rating for each third party.

📘 For a detailed breakdown of how the Panorays Risk Rating is calculated, see this article.


❓When should you customize risk weights?

Some organizations choose to customize their risk rating to better align with internal risk appetite, policies, or regulatory requirements.

Customizing the weights allows you to adjust how the Risk Rating score is calculated by assigning greater importance to either the Cyber Posture Rating or the Smart Questionnaire Rating.


❓What happens when you change the weights?

  • The updated weighting applies to all third parties in your account

  • Risk ratings are recalculated to reflect the adjustments

  • This ensures consistency across your vendor risk assessments


🔍How to make these changes?

To customize the options mentioned above, please navigate to Risk Policy under Company Settings and adjust them accordingly.

Did this answer your question?