Summary
In short
- Hazard and dependency are separate axes. Verification addresses the first; dual sourcing, stockholding and qualified alternatives address the second.
- Under FSMA supply chain requirements the verification activity must be appropriate to the hazard, and an onsite audit is required for hazards with a reasonable probability of serious adverse health consequences unless a written determination supports otherwise.
- Certification narrows what you need to verify; it does not answer whether the supplier can meet your specification, handle your allergen profile or trace your batch.
- The tier below your supplier is usually where the exposure sits, and it is the tier nobody assesses. A single upstream source can serve several of your apparently independent suppliers.
- Performance data you already hold, rejections, complaints, late deliveries, certificate lapses, is better risk information than most questionnaires and is rarely fed back into the assessment.
- Reassess on change: new material, new site, ownership change, or a shift in the supplier's own supply base.
What it is
What it is
What is a supplier risk assessment?
An assessment of the risk a supplier presents across two largely independent dimensions: the hazard the material or service carries, and the organisation's exposure if that supplier fails. It concludes with the verification activity and approval conditions the supplier warrants.
Why two dimensions?
Because they are different risks with different controls. A material with a serious health hazard needs verification of the supplier's controls; a sole-source supplier with no alternative needs continuity arrangements. A material can be high on one axis and low on the other, and treating them as a single score conceals which control is needed.
When to use it
When to use it, and when not to
This assessment determines what verification a supplier warrants. It is not the verification itself.
Use it for
- Approving a new supplier, or a new material from an existing supplier
- Setting the verification activity and frequency proportionate to hazard and dependency
- Reviewing after a quality failure, complaint pattern, delivery failure or ownership change
- Establishing continuity exposure for sole-sourced or single-route materials
- Where a regulatory regime requires the verification activity to be justified against the hazard
Not for
- The supplier audit, which is one verification activity this assessment may specify
- Incoming inspection and testing, which verifies the delivery
- The approved supplier list, which records the decision this assessment informs
- Supplier performance scorecards, which measure ongoing performance and feed back into this
- Contract and commercial terms, which allocate liability rather than assess risk
Standards
What it is built against
Supplier risk sits under quality management control requirements, a risk management framework, and, for food, a statutory verification regime.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 9001 cl.8.4.1 | Determine controls for externally provided processes, products and services based on their impact | Header |
| ISO 9001 cl.8.4.2 | Type and extent of control based on the supplier's ability to meet requirements | Result |
| ISO 9001 cl.6.1 | Actions to address risks and opportunities, proportionate to the potential impact on conformity | Header |
| ISO 31000 | Risk management framework, principles and process applied consistently across the assessment | Header |
| 21 CFR 117.410 | Supplier verification activities appropriate to the hazard requiring a supply chain control | Material hazard |
| 21 CFR 117.430 | Verification activities for hazards controlled by the supplier, with defined options and justification | Result |
| ISO 22301 | Business continuity management, addressing the dependency dimension of supplier risk | Business continuity |
| BRCGS and SQF | Raw material risk assessment determining approval and ongoing verification requirements | Material hazard |
What it does not cover
- The supplier audit, which is one verification activity this assessment may require.
- Incoming inspection and testing, verifying what arrived rather than the system producing it.
- The approved supplier list, which records the approval decision.
- Supplier scorecards, which track ongoing performance between assessments.
- Contractual terms and indemnities, which allocate liability without reducing exposure.
Filling it in
Filling it in well
Assess the two axes separately, use the data you already hold, and look one tier further than feels necessary.
What could go wrong with this material, how severe would it be, and does your process control it downstream. An ingredient whose hazard your process eliminates is different from one that reaches the consumer as received, and the second warrants verification of the supplier's controls rather than reliance on your own.
Sole source or multiple, qualified alternatives available or not, lead time to switch, single site or single route, and how long you could operate without it. This produces continuity actions rather than verification actions, and the two lists should look different.
Rejection rates, complaint attribution, delivery reliability, certificate lapses, responsiveness on corrective actions. This is real behavioural data from the relationship and is a better predictor than any questionnaire, and it is routinely collected and never connected to the risk assessment.
Where a material is sole-sourced or a hazard is serious, ask where your supplier gets it. Several apparently independent suppliers frequently converge on one upstream source, one port or one region, and the diversification you believe you have does not exist below the first tier.
Audit findings
Common audit findings
Findings here concern proportionality and the tier below.
| Finding | Clause | What fixes it |
|---|---|---|
| Hazard and dependency combined into a single score. | ISO 31000 | Assess separately; they require different controls and one masks the other. |
| Verification activity uniform across suppliers regardless of risk. | ISO 9001 cl.8.4.2 | Set intensity from the assessment; equal effort is the same as no prioritisation. |
| Onsite audit replaced with document review with no written determination. | 21 CFR 117.410 | Record the determination where an alternative activity is used for a serious hazard. |
| Certification treated as satisfying the assessment. | ISO 9001 cl.8.4.1 | Certification narrows verification scope; it does not confirm fit to your specification. |
| Sub-tier exposure not assessed for sole-sourced materials. | ISO 22301 | Ask where your supplier sources; apparent diversification frequently collapses one tier up. |
| Performance data held but not fed into the assessment. | ISO 9001 cl.9.1 | Rejections, complaints and delivery failures are better predictors than questionnaires. |
| No reassessment after supplier ownership or site change. | ISO 9001 cl.8.4.1 | Ownership, site and process changes at the supplier are all triggers. |
| Continuity exposure identified with no action taken. | ISO 22301 | Qualify an alternative or hold stock; identifying dependency without acting changes nothing. |
| Service providers excluded from supplier risk assessment. | ISO 9001 cl.8.4.1 | Calibration, laboratory, sanitation and logistics providers carry real risk and are rarely assessed. |
| Assessment not connected to the approval decision. | BRCGS / SQF | Link them; an assessment that does not affect approval status is documentation. |
Worked case
Case in point: three suppliers, one factory
A manufacturer dual-sourced a critical ingredient deliberately, holding contracts with three suppliers in different countries and treating the material as low continuity risk on that basis. The risk assessment recorded multiple qualified sources and required only annual document review.
A production interruption at a single plant took all three offline within a fortnight. Two of the three suppliers were distributors buying from the same manufacturer, and the third had a supply agreement with it for part of its own volume.
The diversification existed at the tier the assessment looked at and nowhere below it. The question that would have found this, where does your supplier obtain this material, had never been asked because the material was already recorded as multi-sourced.
Definitions
Definitions and key terms
- Supply chain control
- Under FSMA, a preventive control applied to a hazard controlled before receipt, requiring supplier verification.
- Sub-tier exposure
- Risk arising below your direct supplier, where apparently independent sources converge on a common origin.
- Qualified alternative
- A second supplier already approved and validated, distinct from one that could be qualified given time.
- Dependency
- The organisation's exposure if a supplier fails, determined by sourcing options, lead time and stock position.
- Written determination
- The documented justification required under FSMA where an alternative to an onsite audit is used for a serious hazard.
- Verification intensity
- The depth and frequency of verification activity, which the assessment exists to set proportionately.
- Approved supplier list
- The record of suppliers approved to supply specified materials, updated by the outcome of this assessment.
- Service provider risk
- Exposure from calibration, laboratory, sanitation and logistics providers, routinely omitted from supplier assessment.
FAQ
Frequently asked questions
Why separate hazard from dependency?+
Because they require different responses. Hazard is addressed by verifying the supplier's controls; dependency is addressed by dual sourcing, stockholding or qualifying an alternative. A supplier can be high on one and low on the other, and a combined score lands them in the middle of a list where they receive an intervention that addresses neither.
Does certification reduce the assessment?+
It narrows what needs verifying rather than replacing the assessment. A GFSI-recognised certificate establishes that a scheme-accredited body found the system compliant when it visited. It does not establish that the supplier can meet your specification, is compatible with your allergen profile, or can trace your batch, which is what a second-party activity should address.
What does FSMA require?+
That the verification activity is appropriate to the hazard requiring a supply chain control. Where a hazard has a reasonable probability of causing serious adverse health consequences or death, the activity must be an onsite audit unless there is a written determination that other activities provide adequate assurance. That written determination is what is usually missing where document review has been substituted.
What is the most commonly missed exposure?+
Sub-tier convergence. Organisations dual-source deliberately and record the material as low continuity risk, without asking where each supplier obtains it. Multiple direct suppliers frequently trace to one manufacturer, one port or one region, and the diversification is real only at the tier the assessment examined.
Should service providers be assessed?+
Yes, and they usually are not. Calibration providers, laboratories, sanitation contractors and logistics providers all carry real risk to product safety and quality, and few appear in supplier risk assessments at all because the process was built around materials.
The agents
What the agents do with it
The assessment sets verification intensity. What fails is the single combined score and the tier nobody asked about.
Holds hazard and dependency as separate dimensions, and drives verification activity and approval status from the assessment.
Feeds rejection, complaint and delivery data back into the assessment continuously, rather than waiting for an annual review.
Surfaces sub-tier and routing convergence, where apparently independent suppliers share an origin, a port or a corridor.
Extends the same assessment logic to service providers, who carry real risk and are usually outside the supplier process.
This template lives in KnowQuality — quality and food safety. HACCP, nonconformance, traceability, laboratory and customer complaints.
Sources
Sources
- ISO 9001:2015 clauses 6.1, 8.4.1 and 8.4.2
- 21 CFR 117 Subpart G, supply chain program, FDA
- ISO 31000:2018, risk management guidelines
- ISO 22301:2019, business continuity management systems
- BRCGS Food Safety Issue 9 and SQF Edition 9, raw material risk assessment and supplier approval