A single calibrated risk signal per supplier - inside-out assessment evidence and outside-in scanning, fused and kept current.
A questionnaire result and an outside-in rating that never reconcile leave you with two half-truths and no single answer to give the board. Worse, every team scores suppliers a little differently, and the number freezes on the day it was set - blind to the threats that land afterwards.
The contrast below is the gap that matters: a posture nobody can stand behind, set against one calibrated signal you can trace to its inputs.
Most tools give you either a questionnaire score or an outside-in rating, and leave you to reconcile the two. The risk engine fuses both, plus the live threat picture, into one defensible number you can stand behind in front of a board or an auditor.
A single engine scores every supplier the same way - defensible, not a per-team guess.
A 9-surface outside-in rating - TLS, DNS, exposure, breach and reputation - folded in alongside the supplier’s own answers.
From a portfolio heat-map to the exact answer, control or finding driving the score.
Every contributing factor maps to CAF, ISO 27001 and NIST - evidence, not noise.
Re-scored as scans, threats and reassessments land - never a stale annual snapshot.
Sees shared and nth-party dependencies, so portfolio-level risk isn’t hidden.
Here is the engine at work on a single supplier. One calibrated score sits on top, with the four inputs that produced it - the SAQ v30 assessment, the outside-in rating, live threat exposure and criticality weighting - laid out underneath, each one a drill-down to the evidence behind it.
The score is not a black box. It is built from the supplier’s own SAQ v30 answers, a nine-surface outside-in rating, live threat matches and the criticality weighting from profiling and tiering - all run through one calibrated engine and re-scored whenever any input changes.
The six stages below trace that path, from first assessment through to continuous monitoring, so you can always point to what moved a number and why.
A questionnaire tells you what a supplier says it does; a ratings tool tells you what its perimeter looks like from outside. Each is half the picture, and neither alone is a position you can defend to a regulator.
The comparison below sets both approaches side by side with the fused signal, line by line - inside-out governance, outside-in attack surface, live threat exposure and continuous re-scoring in one calibrated number.
| Capability | Questionnaire alone | Ratings tool alone | E2ERisk |
|---|---|---|---|
| Inside-out governance | Yes | No | Yes |
| Outside-in attack surface | No | Yes | Yes |
| Live threat exposure | No | Limited | Built in |
| One calibrated score | Inside-out only | External only | Both, fused |
| Drill-down to evidence | Per answer | Per finding | Across both |
| Re-scored continuously | Annual | Continuous | Continuous |
The result is one calibrated engine, both inside-out and outside-in signals fused, re-scored continuously and traceable down to the evidence. The figures below are what that adds up to in practice.
A calibrated number is only useful if you can do something with it. In day-to-day use that means three things: a portfolio heat-map that surfaces the weakest and most critical suppliers first, a two-click path from any score to the evidence behind it, and a board-ready view drawn straight from live evidence.
Every supplier ranked by calibrated risk, with the weakest and the most critical surfaced first.
From a portfolio number to the exact answer, finding or threat driving it - in two clicks.
A defensible posture summary sourced from live evidence - no slide-building, no version drift.
Every factor that contributes to a score is mapped to the regimes a UK organisation is actually held to, so the number is evidence rather than noise. This is framework mapping and assurance evidence, not a certification claim.
A 30-minute walkthrough on your suppliers - the live risk engine, not slides.