Step 5 of 10

Risk Scoring

Configure risk scoring and thresholds for automated risk assessment.

Understanding Risk Scoring

Risk scoring automatically calculates the overall risk level of an assessment based on the vendor's responses. Each answer can contribute points to the total risk score.

Assessment results showing risk score, risk level, and automation results

Screenshot placeholder

Assessment results showing risk score, risk level, and automation results
Assessment Results - Automatic risk calculation with score breakdown

Risk Threshold Configuration

Configure the score ranges for each risk level when creating your template:

Low Risk(0 - 30)

Minimal privacy concerns, standard monitoring

Medium Risk(31 - 60)

Some concerns requiring attention and mitigation

High Risk(61 - 80)

Significant risks requiring action before approval

Critical Risk(> 80)

Severe risks - may require rejection or major changes

Tip: You can adjust the threshold ranges using the sliders in the template builder. The maximum possible score is calculated automatically based on your questions.

Assigning Risk Scores to Questions

When adding questions to your template, assign risk scores to each possible answer:

Example: Yes/No Question

"Is personal data encrypted at rest?"

Yes

Risk Score: 0

No

Risk Score: 50

Example: Multiple Choice Question

"How often are security audits conducted?"

Annually or more frequently+0 points
Every 2-3 years+20 points
Rarely or never+50 points
Unknown+30 points

Risk Distribution Dashboard

The DPIA dashboard shows the risk distribution across all your assessments:

Risk Distribution

Low
2
Medium
1
High
1
Critical
3

Risk Scoring Best Practices

Weight critical questions higher

Questions about encryption, data breaches, and compliance should have higher scores

Use consistent scoring

Apply similar scoring logic across templates for comparable results

Consider cumulative impact

Multiple medium-risk answers can add up to a high-risk total

Leave room for judgment

Risk scores guide decisions but don't replace human review

Document scoring rationale

Record why certain answers receive specific scores