Knowella

Supplier Risk Assessment Template

Supplier risk assessment exists to answer one question: how much verification does this supplier warrant. Get it wrong in one direction and you audit a packaging supplier annually while a sole-source ingredient carrying a serious hazard is approved on a certificate. Get it wrong in the other and you spend the year auditing everyone equally, which is the same as not prioritising at all.

KnowQualityAssessmentQUA-045Pinned in navigationFull guide
Determines
Verification intensity per supplier
Two axes
Hazard and dependency

Summary

In short

  • Hazard and dependency are separate axes. Verification addresses the first; dual sourcing, stockholding and qualified alternatives address the second.
  • Under FSMA supply chain requirements the verification activity must be appropriate to the hazard, and an onsite audit is required for hazards with a reasonable probability of serious adverse health consequences unless a written determination supports otherwise.
  • Certification narrows what you need to verify; it does not answer whether the supplier can meet your specification, handle your allergen profile or trace your batch.
  • The tier below your supplier is usually where the exposure sits, and it is the tier nobody assesses. A single upstream source can serve several of your apparently independent suppliers.
  • Performance data you already hold, rejections, complaints, late deliveries, certificate lapses, is better risk information than most questionnaires and is rarely fed back into the assessment.
  • Reassess on change: new material, new site, ownership change, or a shift in the supplier's own supply base.

What it is

What it is

What is a supplier risk assessment?

An assessment of the risk a supplier presents across two largely independent dimensions: the hazard the material or service carries, and the organisation's exposure if that supplier fails. It concludes with the verification activity and approval conditions the supplier warrants.

Why two dimensions?

Because they are different risks with different controls. A material with a serious health hazard needs verification of the supplier's controls; a sole-source supplier with no alternative needs continuity arrangements. A material can be high on one axis and low on the other, and treating them as a single score conceals which control is needed.

When to use it

When to use it, and when not to

This assessment determines what verification a supplier warrants. It is not the verification itself.

Use it for

  • Approving a new supplier, or a new material from an existing supplier
  • Setting the verification activity and frequency proportionate to hazard and dependency
  • Reviewing after a quality failure, complaint pattern, delivery failure or ownership change
  • Establishing continuity exposure for sole-sourced or single-route materials
  • Where a regulatory regime requires the verification activity to be justified against the hazard

Not for

  • The supplier audit, which is one verification activity this assessment may specify
  • Incoming inspection and testing, which verifies the delivery
  • The approved supplier list, which records the decision this assessment informs
  • Supplier performance scorecards, which measure ongoing performance and feed back into this
  • Contract and commercial terms, which allocate liability rather than assess risk

Standards

What it is built against

Supplier risk sits under quality management control requirements, a risk management framework, and, for food, a statutory verification regime.

ClauseRequirementWhere it lands
ISO 9001 cl.8.4.1Determine controls for externally provided processes, products and services based on their impactHeader
ISO 9001 cl.8.4.2Type and extent of control based on the supplier's ability to meet requirementsResult
ISO 9001 cl.6.1Actions to address risks and opportunities, proportionate to the potential impact on conformityHeader
ISO 31000Risk management framework, principles and process applied consistently across the assessmentHeader
21 CFR 117.410Supplier verification activities appropriate to the hazard requiring a supply chain controlMaterial hazard
21 CFR 117.430Verification activities for hazards controlled by the supplier, with defined options and justificationResult
ISO 22301Business continuity management, addressing the dependency dimension of supplier riskBusiness continuity
BRCGS and SQFRaw material risk assessment determining approval and ongoing verification requirementsMaterial hazard

What it does not cover

  • The supplier audit, which is one verification activity this assessment may require.
  • Incoming inspection and testing, verifying what arrived rather than the system producing it.
  • The approved supplier list, which records the approval decision.
  • Supplier scorecards, which track ongoing performance between assessments.
  • Contractual terms and indemnities, which allocate liability without reducing exposure.

Filling it in

Filling it in well

Assess the two axes separately, use the data you already hold, and look one tier further than feels necessary.

Assess hazard from the material and its use

What could go wrong with this material, how severe would it be, and does your process control it downstream. An ingredient whose hazard your process eliminates is different from one that reaches the consumer as received, and the second warrants verification of the supplier's controls rather than reliance on your own.

Assess dependency separately

Sole source or multiple, qualified alternatives available or not, lead time to switch, single site or single route, and how long you could operate without it. This produces continuity actions rather than verification actions, and the two lists should look different.

Use the performance data you already hold

Rejection rates, complaint attribution, delivery reliability, certificate lapses, responsiveness on corrective actions. This is real behavioural data from the relationship and is a better predictor than any questionnaire, and it is routinely collected and never connected to the risk assessment.

Look one tier up on anything critical

Where a material is sole-sourced or a hazard is serious, ask where your supplier gets it. Several apparently independent suppliers frequently converge on one upstream source, one port or one region, and the diversification you believe you have does not exist below the first tier.

Audit findings

Common audit findings

Findings here concern proportionality and the tier below.

FindingClauseWhat fixes it
Hazard and dependency combined into a single score.ISO 31000Assess separately; they require different controls and one masks the other.
Verification activity uniform across suppliers regardless of risk.ISO 9001 cl.8.4.2Set intensity from the assessment; equal effort is the same as no prioritisation.
Onsite audit replaced with document review with no written determination.21 CFR 117.410Record the determination where an alternative activity is used for a serious hazard.
Certification treated as satisfying the assessment.ISO 9001 cl.8.4.1Certification narrows verification scope; it does not confirm fit to your specification.
Sub-tier exposure not assessed for sole-sourced materials.ISO 22301Ask where your supplier sources; apparent diversification frequently collapses one tier up.
Performance data held but not fed into the assessment.ISO 9001 cl.9.1Rejections, complaints and delivery failures are better predictors than questionnaires.
No reassessment after supplier ownership or site change.ISO 9001 cl.8.4.1Ownership, site and process changes at the supplier are all triggers.
Continuity exposure identified with no action taken.ISO 22301Qualify an alternative or hold stock; identifying dependency without acting changes nothing.
Service providers excluded from supplier risk assessment.ISO 9001 cl.8.4.1Calibration, laboratory, sanitation and logistics providers carry real risk and are rarely assessed.
Assessment not connected to the approval decision.BRCGS / SQFLink them; an assessment that does not affect approval status is documentation.

Worked case

Case in point: three suppliers, one factory

A manufacturer dual-sourced a critical ingredient deliberately, holding contracts with three suppliers in different countries and treating the material as low continuity risk on that basis. The risk assessment recorded multiple qualified sources and required only annual document review.

A production interruption at a single plant took all three offline within a fortnight. Two of the three suppliers were distributors buying from the same manufacturer, and the third had a supply agreement with it for part of its own volume.

The diversification existed at the tier the assessment looked at and nowhere below it. The question that would have found this, where does your supplier obtain this material, had never been asked because the material was already recorded as multi-sourced.

Definitions

Definitions and key terms

Supply chain control
Under FSMA, a preventive control applied to a hazard controlled before receipt, requiring supplier verification.
Sub-tier exposure
Risk arising below your direct supplier, where apparently independent sources converge on a common origin.
Qualified alternative
A second supplier already approved and validated, distinct from one that could be qualified given time.
Dependency
The organisation's exposure if a supplier fails, determined by sourcing options, lead time and stock position.
Written determination
The documented justification required under FSMA where an alternative to an onsite audit is used for a serious hazard.
Verification intensity
The depth and frequency of verification activity, which the assessment exists to set proportionately.
Approved supplier list
The record of suppliers approved to supply specified materials, updated by the outcome of this assessment.
Service provider risk
Exposure from calibration, laboratory, sanitation and logistics providers, routinely omitted from supplier assessment.

FAQ

Frequently asked questions

Why separate hazard from dependency?+

Because they require different responses. Hazard is addressed by verifying the supplier's controls; dependency is addressed by dual sourcing, stockholding or qualifying an alternative. A supplier can be high on one and low on the other, and a combined score lands them in the middle of a list where they receive an intervention that addresses neither.

Does certification reduce the assessment?+

It narrows what needs verifying rather than replacing the assessment. A GFSI-recognised certificate establishes that a scheme-accredited body found the system compliant when it visited. It does not establish that the supplier can meet your specification, is compatible with your allergen profile, or can trace your batch, which is what a second-party activity should address.

What does FSMA require?+

That the verification activity is appropriate to the hazard requiring a supply chain control. Where a hazard has a reasonable probability of causing serious adverse health consequences or death, the activity must be an onsite audit unless there is a written determination that other activities provide adequate assurance. That written determination is what is usually missing where document review has been substituted.

What is the most commonly missed exposure?+

Sub-tier convergence. Organisations dual-source deliberately and record the material as low continuity risk, without asking where each supplier obtains it. Multiple direct suppliers frequently trace to one manufacturer, one port or one region, and the diversification is real only at the tier the assessment examined.

Should service providers be assessed?+

Yes, and they usually are not. Calibration providers, laboratories, sanitation contractors and logistics providers all carry real risk to product safety and quality, and few appear in supplier risk assessments at all because the process was built around materials.

The agents

What the agents do with it

The assessment sets verification intensity. What fails is the single combined score and the tier nobody asked about.

KnowQuality

Holds hazard and dependency as separate dimensions, and drives verification activity and approval status from the assessment.

Ella

Feeds rejection, complaint and delivery data back into the assessment continuously, rather than waiting for an annual review.

KnowLogistics

Surfaces sub-tier and routing convergence, where apparently independent suppliers share an origin, a port or a corridor.

KnowContractor

Extends the same assessment logic to service providers, who carry real risk and are usually outside the supplier process.

This template lives in KnowQualityquality and food safety. HACCP, nonconformance, traceability, laboratory and customer complaints.

Sources

Sources

  • ISO 9001:2015 clauses 6.1, 8.4.1 and 8.4.2
  • 21 CFR 117 Subpart G, supply chain program, FDA
  • ISO 31000:2018, risk management guidelines
  • ISO 22301:2019, business continuity management systems
  • BRCGS Food Safety Issue 9 and SQF Edition 9, raw material risk assessment and supplier approval

KnowQuality

Also in Suppliers

6Browse the whole library
Record

Supplier Approval Record

Records the decision to approve a new supplier, with the evidence behind it. Completed before the first order. Approved by quality and procurement together. No material is accepted from an unapproved supplier, which this record enforces.

Assessment

Supplier Questionnaire

Collects information about a supplier's systems, certifications and controls. Sent before approval and refreshed yearly. Completed by the supplier and reviewed by quality. Scored, so suppliers can be compared on the same basis.

Audit

Supplier Audit

Audits a supplier's site against your requirements. Run on a risk based schedule, more often for higher risk materials. Carried out by a trained auditor. Findings become actions the supplier owns, tracked to closure the same as internal ones.

Review

Supplier Scorecard

Scores a supplier on quality, delivery, responsiveness and cost over a period. Run quarterly. Compiled by procurement with quality. Gives you something concrete to take into a supplier review meeting.

Record

Supplier Corrective Request

Asks a supplier to investigate and fix a problem with their material or service. Raised after a rejection or repeated issue. Sent by quality. Requires root cause and evidence from the supplier, not just an apology and a credit note.

Register

Material Specification Record

Holds the agreed specification for each material you buy, including tolerances and test methods. Created before first order and updated when the specification changes. Owned by quality. Incoming inspection checks against this record, so both sides know the standard.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.