Applied Judgment Assessment
Applied skill assessment · procurement, security, risk and compliance teams · browse the full catalogue

Third-Party and Vendor Assurance Assessment for Procurement, Security and Risk TeamsThe question is never whether to check a supplier. It is where the twenty hours go.

Four arrangements, four areas of review, sixteen sliders — scored as a shape, so spreading the hours evenly earns nothing.

45 minutes36 scored exercisesEvidence-keyed scoringGlobal · INR & USD

The certifications gate on five years and then test the vocabulary

The recognised third-party risk credentials run from about a thousand to fifteen hundred dollars, with the practitioner programme at nearly five thousand, and most of them require five years in the field before you may sit them. All of them examine what you know about the process. None examines the decision that actually consumes the budget.

Nobody has enough review capacity to look at every supplier properly. Sixteen of these thirty-six exercises make the real decision explicit: four arrangements, each described in one line, and four sliders asking what share of the review you would spend on how they protect the data, what happens if they stop, who else they use, and whether they do what the contract says.

The four arrangements have genuinely different shapes. A payroll processor with nowhere to move to is not a marketing tool that passes data onward, and a single logistics partner with no customer data is neither. Your sixteen answers are scored as a SHAPE against a reference allocation, so spending more hours overall costs you nothing and earns you nothing — and an even twenty-five per cent everywhere has no shape at all, which the report says rather than scoring.

The reference profiles are printed in full, all four of them, because they are authored from published risk criteria rather than rated by a panel. A proper expert vector wants five or more raters with their agreement reported and no such panel has sat. Somebody who thinks a different profile is right for the payroll processor can now point at it and say why. That is the point of printing it.

Twenty further exercises cover what a certificate and a questionnaire actually establish, which contract terms shorten a recovery rather than decide who pays afterwards, and how concentration rises without anybody adding a supplier.

Four parts, each measured by at least six exercises:
Where the risk actually isWhat the assurance actually provesWhat you can require by contractWhat happens when it goes wrong

What you walk away with

A shape match with its band

Your sixteen allocations correlated with the reference, corrected by simulation against the answers people actually give.

The hours, kept apart from the aim

How much review you would spend in total, reported separately, because a correlation cannot see it and should not.

A quadrant with an action in it

Match against concentration, with all four quadrants written out so yours reads as a position rather than a type.

All four reference profiles, printed

Every slider beside the reference share, so the assumption is inspectable rather than asserted.

Four parts, placed not scored

What assurance proves, what a contract can require, and what happens when it goes wrong.

One if-then change

Aimed at whichever part of your own sitting sat lowest outside the allocation.

Inside your report

Illustrative sample — your report is generated from your own responses.

Where you sit, and what to do
decisive, wrong areasaimed, concentratedeven hours, no shaperight, still spreadinghow well the shape matches the exposure

Each quadrant carries an action rather than an adjective, and all four are printed in words, so the one you are in reads as a position rather than as a type.

Payroll processor, nowhere to move to
3530Protect3025If they stop2025Who else1520Contractdashed = reference · solid = you

The reference profile is printed for all four arrangements, because it is an authored assumption rather than an expert consensus and somebody who disagrees with it should be able to point at it.

Built for

  • Third-party risk, vendor management and procurement professionals
  • Security and compliance teams reviewing suppliers and subprocessors
  • Internal audit and operational resilience functions
  • Anybody who has been asked to review forty suppliers with capacity for eight

Find out whether your hours follow the exposure

36 exercises across six formats · about 45 minutes · the quadrant, the four reference profiles and the simulated null printed.

₹1,499 (incl. GST) · assessment and full report, nothing further to pay

Buy this assessment

No account needed to buy. Your name and email identify the purchase and Razorpay sends your receipt to that address.

Secure Razorpay payment · ₹1,499 includes 18% GST

Bought this already and lost the tab? Sign in and enter your purchase code under Claim a purchase on your dashboard.

Secure checkout · INR & USDFull report immediately after submission

Frequently asked questions

Do I need to know a particular standard or framework?

No. No standard, certification scheme, attestation report type or regulator is named anywhere in it. Every exercise turns on what an arrangement exposes you to and what a piece of evidence can establish, which is the same under any framework.

Does spending more hours score better?

No. The allocation is scored as a correlation, which is unchanged when every number moves up or down together. Allocating more everywhere earns nothing and costs nothing, and how much you would spend in total is reported separately as the resourcing decision it is.

What happens if I give every area the same share?

You get no figure and a sentence saying why. An even share is a legitimate answer with no shape in it, and a correlation needs the profile to vary before it can match anything. Scoring it in the middle would flatter an answer that expressed no judgement.

Where does the reference allocation come from?

It is authored from published risk criteria - data sensitivity, how replaceable the supplier is, whether their people reach live systems, and how far the work is passed onward. It is not an expert consensus, no panel has rated it, and all four profiles are printed on the report so you can disagree with them specifically.

How long is it and what does it cost?

About forty-five minutes for thirty-six exercises. ₹1,499 in India, inclusive of GST, or US$14.99 elsewhere, one time, for the sitting and the full report.

One of the AssessAll applied-judgment assessments

Each one takes a single capability, puts you inside the situations where it is actually tested, and scores your choices against published evidence — with a report designed for that capability alone, not a template. They span hiring, compliance, education, operations and personal skill.

Browse the catalogue

Methodology: Thirty-six original exercises across six formats: sixteen slider allocations across four arrangements, six keyed single-choice items, six select-every-that-applies exercises, four keyed claims, two matching exercises and two ordering exercises. The declared response instruction is applied judgement throughout - what share of a fixed review you would spend, and what a piece of evidence establishes - and one instruction covers the whole form. Construct statement: it measures whether somebody directs assurance effort at where the exposure actually is, what they take a certificate or a questionnaire to have established, which contract terms they treat as controls rather than as compensation, and how they respond when a third party fails. It does not test any named standard, framework, certification scheme or regulation, it does not certify anybody as an assessor, and it says nothing about whether any particular supplier is safe to use. Scoring is an expert-vector allocation match. The sixteen allocations are scored as the correlation between the respondent's profile and a reference allocation, so the level of effort drops out and only the shape is scored: allocating more everywhere costs nothing and earns nothing, and an even share across all sixteen has no shape, is given no figure, and is reported as such in plain words rather than placed at the middle of the scale. The correlation is chance-corrected by simulation against the authored answer distribution on each slider, in which the even twenty-five per cent carries the largest share of the mass because that is what people actually answer. The reference allocation is authored from published risk criteria - data sensitivity, substitutability, access and concentration - rather than from a panel of raters, and the report says so: an expert vector properly wants five or more raters with reported agreement, no such panel has sat, and until one has the reference is a declared assumption printed on the page with its four profiles visible. Every other strand is chance-corrected against the authored option priors. Constructs and sources: risk-based supplier segmentation by data sensitivity, criticality and substitutability; the distinction between assertion, description and test in assurance evidence, and the scope-and-date limits of a third-party attestation report; subprocessor disclosure and the transitivity of dependency; concentration risk and shared underlying dependencies across nominally independent suppliers; incident notification windows as a determinant of containment time rather than of liability; exit planning and the difference between a termination right and an available destination; expert-profile matching scored as a correlation so that elevation and scatter drop out (the profile-similarity literature on elevation, scatter and shape); and item-writing guidance from Haladyna, Downing and Rodriguez. All items are original works written for this instrument. No vendor, standard, certification scheme, attestation report type or regulator is reproduced, named or implied, and no endorsement or affiliation exists or is suggested.