Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This page is part of the User Guides collection. Read it when you are choosing which packaged inherent risk questionnaire to start from, or when you want to see exactly what a template asks before you send it.
An inherent risk questionnaire (IRQ) rates a third party before any of their controls are taken into account. Its score decides how much due diligence the relationship earns and how often it comes back for reassessment, so it is deliberately short — the longest template here is fifteen questions, and the shortest takes about a minute. The IRQ library gives you six of them ready to use. Open it from the IRQ Library button at the top right of Configuration → Questionnaires → Inherent Risk, browse by category, and copy the one you want.
Copying a template produces an ordinary questionnaire you own and can edit — question wording, options, weights, reviewers, everything. Nothing syncs back: later changes to the Coverbase template do not reach your copy, and your edits never leave your workspace.

What ships

Choosing a starting point

Pick by what the engagement does to your risk, not by the industry you are in. A hospital buying a marketing analytics tool wants the Data Privacy set, not the Healthcare one — unless that tool will touch patient records.

Start with Standard

It is the default for a reason: it covers data, access, criticality, spend, geography and subcontracting without assuming anything about your sector.

Add Quick Triage alongside it

Point self-service intake at Quick Triage and reserve the longer templates for the vendors triage flags. Most requests never need fifteen questions.

Use a sector template when a regulator is watching

Financial Services and Healthcare exist because examiners expect specific determinations — critical activity, business associate status — that a generic questionnaire never asks for.

Run AI & Emerging Tech as a second pass

It answers a different question from the others: not how much of your data is exposed, but what the system decides on its own. Pair it with whichever template fits the underlying purchase.

Every template in detail

The industry-agnostic default. It covers data sensitivity and volume, network access, business criticality, customer contact, contract spend, regulatory exposure, offshoring, subcontracting and replaceability.Engagement Overview (no risk domain — context only, unscored)
  1. Describe the product or service the third party will provide. (free text)
  2. Who is the internal relationship or business owner for this engagement? (contacts)
Data Access and Sensitivity (Cybersecurity)
  1. Will the third party access, store, transmit or process any of our data?
  2. What is the most sensitive classification of data involved? — Public or de-identified · Private · Confidential · Restricted
  3. How many records will the third party access, store, transmit or process in aggregate? — five bands from under 1,000 to 500,000 or more
  4. Will the third party have access to our networks or internal systems? — via their own equipment · via company equipment or VDI · no
  5. Is this a hosted or cloud-delivered solution?
Business Impact (no risk domain)
  1. How critical is this product or service to the business? — High, unrecoverable process · Medium, recoverable with minor impact · Low
  2. Does the third party have direct or indirect contact with our customers?
  3. Does the third party support our critical infrastructure (software, hardware, data centre or network connectivity)?
  4. How long would it take to replace this third party if needed? — over 12 months · 6-12 months · under 6 months
  5. What is the expected spend over the life of the contract? — six bands from under US5,000tooverUS5,000 to over US1,000,000
Regulatory and Geographic Exposure (Compliance)
  1. Does this relationship present a regulatory risk? — Yes · Unknown · No
  2. Is any aspect of this product or service, including subcontracted work, performed offshore? — offshore with offshore data · offshore with onshore data · no
  3. Does the third party rely on a material subcontractor for any part of the product or service?
Heaviest weights: offshore processing and contract spend, each up to 20 points. No score floors — this template lets the answers speak for themselves.Typical use: New vendor intake triage; determining due diligence depth; setting reassessment cadence; annual re-tiering.
Written for a requester who is not a risk professional, so a software purchase request can be routed in under a minute. Six questions, one section, no free text.
  1. What is the most sensitive data this vendor will handle? — Regulated or restricted (health, financial, government ID) · Confidential business or customer records · Internal only · Public only · None
  2. Will the vendor connect to our systems, networks or accounts? — privileged/admin/write · read-only or limited integration · no
  3. If this vendor went down for a week, what would happen? — could not serve customers · a team significantly degraded · little or no impact
  4. What is the expected annual spend? — over US250,000US250,000 · US25,000-250,000 · under US$25,000
  5. Does the engagement fall under a regulation such as GDPR, HIPAA, PCI DSS, GLBA or SOX? — Yes · Unknown · No
  6. Will the vendor interact with our customers or process customer data? — directly · indirectly · no
No score floors. Every question is weighted evenly enough that no single answer dominates, which is what you want from a form a requester fills in about themselves.Typical use: Self-service vendor intake; fast-track approval for low-risk vendors; pre-screening before a full questionnaire.
Built around the pivotal determination in the 2023 Interagency Guidance on Third-Party Relationships: whether the relationship supports a critical activity.Criticality and Regulatory Designation (Compliance)
  1. Does this relationship support a critical activity, meaning one that could cause significant risk if the third party fails to perform, significant customer impact, or significant impact on operations? — Yes floors the score at 70
  2. Which regulatory regimes apply to this engagement? (select multiple) — GLBA / Regulation P · BSA / AML / OFAC · SOX · PCI DSS · SEC / FINRA · state money transmission licensing
  3. Will the third party’s outputs feed regulatory reporting or the financial statements?
Consumer Data and Funds (Financial)
  1. Will the third party access, store or process nonpublic personal information (NPI) under GLBA? — over 100,000 consumers · under 100,000 · no
  2. Will the third party hold, move or have authority over customer funds? — with discretion · pass-through only · no
  3. Will the third party perform a consumer-facing activity subject to UDAAP or fair lending oversight?
  4. Does the third party perform or support BSA/AML, sanctions screening or KYC obligations? — performs on our behalf · supporting data or tooling · no
  5. Does the third party have access to core banking, payment, trading or ledger systems? — transactional/write · read-only · no
Resilience and Concentration (no risk domain)
  1. What is the maximum tolerable downtime for this service? — under 4 hours · 4-24 hours · 1-3 days · over 3 days
  2. Does the third party rely on material subcontractors (fourth parties) to deliver the service? — yes, unidentified · yes, disclosed · no
  3. How readily could this third party be replaced?
  4. Where will our data be stored or processed relative to our primary regulator’s jurisdiction?
  5. What is the expected spend over the life of the contract?
Because the critical-activity answer sets a floor, a critical relationship cannot be diluted into a low rating by benign answers elsewhere — which is exactly the failure mode an examiner looks for.Typical use: Bank and credit union vendor onboarding; critical activity designation; examiner-ready tiering; fintech partner due diligence.
Leads with business associate status under HIPAA, then works outward through data, clinical proximity and supply chain.Protected Health Information (Compliance)
  1. Will the third party create, receive, maintain or transmit protected health information on our behalf, making it a business associate? — Yes floors the score at 60
  2. How many patient or member records will the third party handle? — five bands from none to 100,000 or more
  3. Which categories of sensitive data are involved? (select multiple) — PHI · substance use disorder records (42 CFR Part 2) · behavioral or mental health · genetic or genomic · payment card or billing · de-identified only
  4. Will PHI be stored or processed outside the country of collection?
Clinical and Patient Safety Impact (no risk domain)
  1. Does the service touch clinical care delivery or patient safety? — informs diagnosis or treatment · supports clinical workflow · administrative only
  2. Is the product a regulated medical device or software as a medical device (SaMD)? — FDA-regulated or CE-marked · under evaluation · no
  3. Will the third party have access to EHR or EMR systems? — write or integration · read-only · no
  4. Will the third party interact directly with patients or research subjects?
  5. What is the maximum tolerable downtime for this service?
Regulatory and Supply Chain (Compliance)
  1. Which regulatory regimes apply to this engagement? (select multiple) — HIPAA / HITECH · 42 CFR Part 2 · FDA 21 CFR Part 11 · GxP (GCP, GLP, GMP) · state health privacy laws
  2. Does the third party subcontract any part of the service? — subcontractors handle PHI · subcontractors without PHI access · no
  3. How long would it take to replace this third party if needed?
  4. What is the expected spend over the life of the contract?
Typical use: Business associate triage; digital health vendor onboarding; clinical system procurement; life sciences supplier qualification.
For any vendor whose product embeds AI, whether or not AI is what you are buying. Aligned with the NIST AI Risk Management Framework and the EU AI Act.AI Footprint (Cybersecurity)
  1. What role does AI play in the product or service? — core · optional or embedded feature · none
  2. Will our data be used to train, fine-tune or otherwise improve the vendor’s models? — across their customer base · unknown · within our tenant only · contractually prohibited
  3. What is the most sensitive data that will be sent to the model?
  4. Does the vendor disclose which foundation models and AI subprocessors it relies on? — not disclosed · partially · fully disclosed and contractually committed
Autonomy and Consequence (no risk domain)
  1. What degree of autonomy does the system have? — consequential actions without human review · actions subject to approval · recommends only · informational output only
  2. Will the system have access to our systems, tools or credentials, for example through agentic tool use or an API integration? — write or transactional · read-only · no
  3. Does the system make or materially inform decisions about people, such as hiring, credit, insurance, healthcare, housing or education? — Yes floors the score at 65
  4. Is AI-generated output shown to customers or the public? — without human review · with review · internal only
Governance and Regulatory Exposure (Compliance)
  1. Under the EU AI Act, how would this system most likely be classified? — prohibited or unclear · high-risk (Annex III) · limited risk with transparency obligations · minimal risk or out of scope
  2. Does the vendor maintain an AI governance programme, such as documented evaluations, model cards, red-teaming or ISO/IEC 42001 certification?
  3. Could the system’s output create intellectual property, defamation or copyright exposure?
  4. How critical is this AI system to the business?
Question 2 is the one that most often changes a purchase. “Unknown” is weighted almost as heavily as “yes, across the vendor’s customer base” on purpose — an unanswered training question is a live exposure, not a neutral one.
Typical use: AI vendor onboarding; shadow AI discovery triage; EU AI Act readiness screening; agentic tooling review.
Enough to decide whether a DPIA and a transfer mechanism are needed before the engagement proceeds. Aligned with the GDPR and the major US state regimes.Processing Role and Data (Compliance)
  1. What role will the third party play in processing personal data? — joint controller · independent controller · processor on our instructions · no personal data
  2. Which categories of personal data are involved? (select multiple) — contact details and identifiers · financial or payment · location or behavioural tracking · biometric · special category (health, race, religion, union membership, sexual orientation) · children’s data
  3. How many data subjects are affected? — five bands from under 1,000 to over 1,000,000
  4. Which privacy regimes apply to this engagement? (select multiple) — EU GDPR · UK GDPR · CCPA / CPRA · other US state privacy laws · LGPD, PIPEDA, APPI or similar
Transfers and Secondary Use (Compliance)
  1. Will personal data be transferred outside its jurisdiction of collection? — no adequacy decision or safeguards · adequacy, SCCs or DPF cover · no transfer
  2. Will the third party use personal data for its own purposes, such as analytics, marketing or model training? — yes · aggregated or de-identified only · limited to our instructions
  3. Will the third party carry out automated decision-making or profiling? — with legal or similarly significant effects · profiling without significant effects · no
  4. Does the third party engage sub-processors? — undisclosed · disclosed with a right to object · no
  5. How long will the third party retain personal data? — indefinitely or at their discretion · a defined period over three years · no longer than the contract term
  6. Does the engagement involve direct marketing, cookies or cross-site tracking on our behalf?
Typical use: DPIA screening; sub-processor approval; international transfer review; marketing and adtech vendor triage.

How the score works

Each answer option carries a weight. The inherent risk score is the total of the weights you selected, divided by the highest total those same questions could have produced, expressed as a percentage from 0 to 100. That score then maps to an inherent risk level through the scale configured under Configuration → Scales → Risk. Two things follow from that normalization:
  • Weights are relative. They only have to be right against each other, so you can add, remove or reword questions without rebalancing the whole questionnaire.
  • Context questions are free. Free-text, contact, country and currency questions never affect the score, so you can ask for the business owner or a service description without skewing the rating.
Some answers set a score floor instead of adding to the total. Three templates use one: When one of those answers is picked, the questionnaire cannot score below that floor no matter how the other questions are answered. Sections are mapped to risk domains — Cybersecurity, Compliance, Financial, Reputational — so a copied template also produces per-domain inherent risk scores alongside the overall one. Sections with no domain, such as Business Impact, still count toward the overall score.

Tailoring your copy

Everything is editable once you have copied a template. The adjustments worth making first:
  • Reword the spend bands to match your own thresholds and currency. The shipped bands are US dollars and will be wrong for most workspaces.
  • Adjust weights in the Value column on each option to reflect your risk appetite.
  • Add a score floor on any option that should guarantee a minimum rating — your own equivalent of the critical-activity question.
  • Delete what you will not act on. A question whose answer never changes the due diligence you run is a question that costs you response rates.
  • Wire it into intake from Actions → Intake Configuration so new vendor requests are rated automatically.
  • Set risk levels from Actions → Configure Risk Levels to control where the score lands.

Where to go next

Requesting a vendor

How an intake request flows through the questionnaire you wired in, and what the requester sees.

Running an assessment

What happens after the inherent risk score lands: scoping, sending, and reviewing the control assessment it triggers.

Zero touch assessments

Letting a low inherent risk score close out due diligence without a human in the loop.

Admin setup

Risk scales, risk levels and the configuration the inherent risk score maps into.