Help Center / Risk scoring

Risk scoring

Covenant's score is explainable by design: every point comes from a named factor with a visible delta. Change one questionnaire answer and you can see exactly which factor moved and by how much. There are no unexplained score changes.

The composite score (0–100)

The residual composite starts at 100 (safest) and subtracts itemized penalties. Higher is safer. It is shown on the vendor card, the detail header, the ledger, and on the Explainable composite score card with a full factor table.

FactorWhat it subtracts
Inherent exposureA baseline penalty by tier: Critical −20, High −12, Medium −6, Low 0. (Riskier vendors start lower.)
Security questionnaireUp to −45, scaled by the share of weighted controls the vendor failed.
External posture findingsSum of severity costs for open/disputed findings: critical −25, high −15, medium −8, low −3, info 0.
BAA gap−15 when a PHI vendor has no BAA on file.
Risk decision0 (recorded as a traceable factor; documenting an accepted/mitigated risk doesn't change raw posture).

The score is clamped to 0–100. The factor table on the score card lists each factor with its detail and signed delta, so the math is always auditable.

Letter grades

ScoreGrade
90–100A
80–89B
70–79C
60–69D
below 60F

Inherent vs residual

The score card shows both:

The arrow between them shows the buy-down delta — how much the vendor's controls have reduced (or, if findings dominate, increased) the risk. The ledger has an Inh→Res column showing this at a glance.

Risk decisions (accept / mitigate / transfer / avoid)

On the score card you can record a formal risk decision with a justification and a review-by date:

  1. Pick a decision: accept, mitigate, transfer, or avoid.
  2. Add a justification / compensating control and a Review by date.
  3. Click Record decision.

This is recorded as a zero-delta score factor (it documents ownership of the residual risk, it does not hide it) and counts as risk_acceptance evidence in framework coverage. If the review-by date passes, the factor is flagged EXPIRED — re-review.

Why explainability matters. A common complaint about rating services is "the score changed and nobody can tell us why." Covenant answers that directly: the factor table is the explanation, and it updates live as you work.