What is the risk rating of not having the security review, or security testing, or vendor review?
How would you address such a bizarre question?
Accurate security risk rating is impossible without security assurance. It is only after we perform security design review, security testing and vendor review we can understand the context, identify security gaps and assess the risk rating. It is similar to division by 0 – the question does not have an answer – or any answer is possible.

Yet, what if we take the business impact metric, and assume the maximum likelihood of all potential security threats? That would yield the maximum risk rating. I bet that is not the answer your stakeholder was looking for. I bet the true meaning of the question was “Is it okay to bypass security assurance”?
No!
Yet, there are exceptions to every rule. For example – do not brush your teeth. Simplicity of the remediating action outweighs the risk assessment. However, if the hidden question under the question was “Is it okay to bypass security assurance, and not do any remediation as well?” I.e. no analysis and no action – then the answer is:
No!
Yet, I would make an exception for simple changes, where security assurance is just time and cost-prohibitive. If most of the change cost (or time) is spent on security risk analysis, then it is a strong indicator that the analysis is an overkill here. Simplified security review is warranted in this situation.