Help us improve
Share bugs, ideas, or general feedback.
From grc-tprm
Calculates vendor risk scores using inherent (data sensitivity, access level) and residual (certifications, audits) factors. Assigns Critical/High/Medium/Low ratings with comparisons, trends, and recommendations.
npx claudepluginhub grcengclub/claude-grc-engineering --plugin grc-tprmHow this skill is triggered — by the user, by Claude, or both
Slash command
/grc-tprm:tprm-scorerThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Calculates and manages vendor risk scores.
Scores vendor privacy risks with weighted factors: data volume, sensitivity, transfer locations, certifications, breach history, control maturity. Assigns tiers for processor oversight under GDPR.
Conducts vendor security assessments evaluating posture, risks, and generating reports with recommendations. Supports onboarding, periodic reviews, incident response, and due diligence.
Quantify risk using likelihood and impact, apply severity ratings, and prioritize mitigations. Use when prioritizing threats, allocating security budget, and communicating risk to leadership.
Share bugs, ideas, or general feedback.
Calculates and manages vendor risk scores.
| Factor | Weight |
|---|---|
| Data Sensitivity | 15% |
| System Access Level | 10% |
| Business Criticality | 10% |
| Regulatory Impact | 5% |
| Factor | Weight |
|---|---|
| Security Certifications | 15% |
| Questionnaire Score | 20% |
| Audit Findings | 15% |
| Incident History | 10% |
| Rating | Score Range | Review Frequency |
|---|---|---|
| Critical | 80-100 | Quarterly |
| High | 60-79 | Semi-Annual |
| Medium | 40-59 | Annual |
| Low | 0-39 | Biennial |