What this is
What is a supplier risk assessment?
What is a supplier risk assessment?
An assessment of the risk a supplier presents across two largely independent dimensions: the hazard the material or service carries, and the organisation's exposure if that supplier fails. It concludes with the verification activity and approval conditions the supplier warrants.
Why two dimensions?
Because they are different risks with different controls. A material with a serious health hazard needs verification of the supplier's controls; a sole-source supplier with no alternative needs continuity arrangements. A material can be high on one axis and low on the other, and treating them as a single score conceals which control is needed.
Scope
When is a supplier risk assessment required?
This assessment determines what verification a supplier warrants. It is not the verification itself.
Use this template when
- Approving a new supplier, or a new material from an existing supplier
- Setting the verification activity and frequency proportionate to hazard and dependency
- Reviewing after a quality failure, complaint pattern, delivery failure or ownership change
- Establishing continuity exposure for sole-sourced or single-route materials
- Where a regulatory regime requires the verification activity to be justified against the hazard
Do not use it for
- The supplier audit, which is one verification activity this assessment may specify
- Incoming inspection and testing, which verifies the delivery
- The approved supplier list, which records the decision this assessment informs
- Supplier performance scorecards, which measure ongoing performance and feed back into this
- Contract and commercial terms, which allocate liability rather than assess risk
Compliance mapping
Which ISO 9001 cl.6.1 requirements does this satisfy?
Supplier risk sits under quality management control requirements, a risk management framework, and, for food, a statutory verification regime.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 9001 cl.8.4.1 | Determine controls for externally provided processes, products and services based on their impact | Header |
| ISO 9001 cl.8.4.2 | Type and extent of control based on the supplier's ability to meet requirements | Result |
| ISO 9001 cl.6.1 | Actions to address risks and opportunities, proportionate to the potential impact on conformity | Header |
| ISO 31000 | Risk management framework, principles and process applied consistently across the assessment | Header |
| 21 CFR 117.410 | Supplier verification activities appropriate to the hazard requiring a supply chain control | Material hazard |
| 21 CFR 117.430 | Verification activities for hazards controlled by the supplier, with defined options and justification | Result |
| ISO 22301 | Business continuity management, addressing the dependency dimension of supplier risk | Business continuity |
| BRCGS and SQF | Raw material risk assessment determining approval and ongoing verification requirements | Material hazard |
What it does not cover
- The supplier audit, which is one verification activity this assessment may require.
- Incoming inspection and testing, verifying what arrived rather than the system producing it.
- The approved supplier list, which records the approval decision.
- Supplier scorecards, which track ongoing performance between assessments.
- Contractual terms and indemnities, which allocate liability without reducing exposure.
How to complete it
How to complete a supplier risk assessment, step by step
Assess the two axes separately, use the data you already hold, and look one tier further than feels necessary.
What could go wrong with this material, how severe would it be, and does your process control it downstream. An ingredient whose hazard your process eliminates is different from one that reaches the consumer as received, and the second warrants verification of the supplier's controls rather than reliance on your own.
Sole source or multiple, qualified alternatives available or not, lead time to switch, single site or single route, and how long you could operate without it. This produces continuity actions rather than verification actions, and the two lists should look different.
Rejection rates, complaint attribution, delivery reliability, certificate lapses, responsiveness on corrective actions. This is real behavioural data from the relationship and is a better predictor than any questionnaire, and it is routinely collected and never connected to the risk assessment.
Where a material is sole-sourced or a hazard is serious, ask where your supplier gets it. Several apparently independent suppliers frequently converge on one upstream source, one port or one region, and the diversification you believe you have does not exist below the first tier.
What auditors find
Most common supplier risk assessment findings
Findings here concern proportionality and the tier below.
| Finding | Clause | What fixes it |
|---|---|---|
| Hazard and dependency combined into a single score. | ISO 31000 | Assess separately; they require different controls and one masks the other. |
| Verification activity uniform across suppliers regardless of risk. | ISO 9001 cl.8.4.2 | Set intensity from the assessment; equal effort is the same as no prioritisation. |
| Onsite audit replaced with document review with no written determination. | 21 CFR 117.410 | Record the determination where an alternative activity is used for a serious hazard. |
| Certification treated as satisfying the assessment. | ISO 9001 cl.8.4.1 | Certification narrows verification scope; it does not confirm fit to your specification. |
| Sub-tier exposure not assessed for sole-sourced materials. | ISO 22301 | Ask where your supplier sources; apparent diversification frequently collapses one tier up. |
| Performance data held but not fed into the assessment. | ISO 9001 cl.9.1 | Rejections, complaints and delivery failures are better predictors than questionnaires. |
| No reassessment after supplier ownership or site change. | ISO 9001 cl.8.4.1 | Ownership, site and process changes at the supplier are all triggers. |
| Continuity exposure identified with no action taken. | ISO 22301 | Qualify an alternative or hold stock; identifying dependency without acting changes nothing. |
| Service providers excluded from supplier risk assessment. | ISO 9001 cl.8.4.1 | Calibration, laboratory, sanitation and logistics providers carry real risk and are rarely assessed. |
| Assessment not connected to the approval decision. | BRCGS / SQF | Link them; an assessment that does not affect approval status is documentation. |
Case in point
Case in point: three suppliers, one factory
A manufacturer dual-sourced a critical ingredient deliberately, holding contracts with three suppliers in different countries and treating the material as low continuity risk on that basis. The risk assessment recorded multiple qualified sources and required only annual document review.
A production interruption at a single plant took all three offline within a fortnight. Two of the three suppliers were distributors buying from the same manufacturer, and the third had a supply agreement with it for part of its own volume.
The diversification existed at the tier the assessment looked at and nowhere below it. The question that would have found this, where does your supplier obtain this material, had never been asked because the material was already recorded as multi-sourced.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- QUA-045
- Archetype
- Assessment
- Record ID
- RSK-2026-000
- Scoring
- Risk band
- Direction
- High is bad
- Singleton
- No
- Basis
- ISO 9001 cl.6.1, ISO 31000
- Links
- Links Vendor
- Tags
- Supplier, Risk
- Sections
- 5
- Fields
- 42
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 2
Header
8 fieldsAssessment ID*
Auto sequence. Format RSK-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date*
Completed By*
Supplier*
Vendor ID*
Format VEN-0000.
Links to FDN-005 Vendor ID
Materials Covered*
Assessment Trigger*
Material hazard
8 fieldsMaterial Risk Category*
- High risk raw material0 pts
- Medium risk ingredient1 pt
- Low risk ingredient2 pts
- Packaging2 pts
- Service3 pts
Ready To Eat Or Further Processed*
A material going into ready to eat product with no kill step carries far more risk.
- Further processed with kill step3 pts
- Ready to eat0 pts
Kill Step After Receipt*
- Yes, validated3 pts
- Partial1 pt
- None0 pts
Allergen Present*
- No3 pts
- Yes0 pts
Pathogen Risk*
- Low3 pts
- Medium1 pt
- High0 pts
Contaminant Risk*
- Low3 pts
- Medium1 pt
- High0 pts
Foreign Body Risk*
- Low3 pts
- Medium1 pt
- High0 pts
Detected By Our Systems*
- Yes3 pts
- Partly1 pt
- No0 pts
Supply chain
6 fieldsSupply Chain Length*
Every intermediary is a point where substitution or dilution can occur.
- Direct from producer3 pts
- One intermediary2 pts
- Two or more intermediaries0 pts
Country Of Origin Risk*
- Low3 pts
- Medium1 pt
- High0 pts
Agent Or Broker Involved*
- No3 pts
- Yes0 pts
Material Commonly Adulterated*
High value, commodity priced and hard to test materials are the usual targets.
- No3 pts
- Occasionally1 pt
- Yes, known target0 pts
Price Volatility*
- Stable3 pts
- Moderate1 pt
- High0 pts
Authenticity Testing Possible*
- Yes, routine3 pts
- Yes, specialist1 pt
- No0 pts
Business continuity
5 fieldsSingle Source*
- No3 pts
- Yes0 pts
Alternative Supplier Approved*
- Yes3 pts
- Identified not approved1 pt
- None0 pts
Lead Time Weeks
Supplier Financial Stability
- Strong3 pts
- Adequate2 pts
- Concerns0 pts
Geographic Or Climate Exposure
- Low3 pts
- Medium1 pt
- High0 pts
Result
15 fieldsInherent Band*
- Low, 1 to 45 pts
- Medium, 5 to 94 pts
- High, 10 to 142 pts
- Very high, 15 to 191 pt
- Extreme, 20 to 250 pts
Current Band*
- Low, 1 to 45 pts
- Medium, 5 to 94 pts
- High, 10 to 142 pts
- Very high, 15 to 191 pt
- Extreme, 20 to 250 pts
Residual Band*
- Low, 1 to 45 pts
- Medium, 5 to 94 pts
- High, 10 to 142 pts
- Very high, 15 to 191 pt
- Extreme, 20 to 250 pts
Risk Tier Assigned*
- Low3 pts
- Medium2 pts
- High1 pt
- Critical0 pts
Audit Frequency Set*
- Each visit4 pts
- Monthly3 pts
- Quarterly2 pts
- Annually1 pt
Inspection Level Set*
- Reduced3 pts
- Normal2 pts
- Tightened1 pt
- 100 percent0 pts
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Next Review Due*
Quality Manager*
Signature*
Procurement*
Second Signature*
QUA-045 · record IDs look like RSK-2026-000 · Links Vendor
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The assessment sets verification intensity. What fails is the single combined score and the tier nobody asked about.
Holds hazard and dependency as separate dimensions, and drives verification activity and approval status from the assessment.

Feeds rejection, complaint and delivery data back into the assessment continuously, rather than waiting for an annual review.
Surfaces sub-tier and routing convergence, where apparently independent suppliers share an origin, a port or a corridor.
Extends the same assessment logic to service providers, who carry real risk and are usually outside the supplier process.
This template lives in KnowQuality — quality and food safety. HACCP, nonconformance, traceability, laboratory and customer complaints.
Meet KnowQuality→Glossary
Supplier Risk Assessment definitions and key terms
- Supply chain control
- Under FSMA, a preventive control applied to a hazard controlled before receipt, requiring supplier verification.
- Sub-tier exposure
- Risk arising below your direct supplier, where apparently independent sources converge on a common origin.
- Qualified alternative
- A second supplier already approved and validated, distinct from one that could be qualified given time.
- Dependency
- The organisation's exposure if a supplier fails, determined by sourcing options, lead time and stock position.
- Written determination
- The documented justification required under FSMA where an alternative to an onsite audit is used for a serious hazard.
- Verification intensity
- The depth and frequency of verification activity, which the assessment exists to set proportionately.
- Approved supplier list
- The record of suppliers approved to supply specified materials, updated by the outcome of this assessment.
- Service provider risk
- Exposure from calibration, laboratory, sanitation and logistics providers, routinely omitted from supplier assessment.
FAQ
Frequently asked questions about supplier risk assessment
Why separate hazard from dependency?+
Because they require different responses. Hazard is addressed by verifying the supplier's controls; dependency is addressed by dual sourcing, stockholding or qualifying an alternative. A supplier can be high on one and low on the other, and a combined score lands them in the middle of a list where they receive an intervention that addresses neither.
Does certification reduce the assessment?+
It narrows what needs verifying rather than replacing the assessment. A GFSI-recognised certificate establishes that a scheme-accredited body found the system compliant when it visited. It does not establish that the supplier can meet your specification, is compatible with your allergen profile, or can trace your batch, which is what a second-party activity should address.
What does FSMA require?+
That the verification activity is appropriate to the hazard requiring a supply chain control. Where a hazard has a reasonable probability of causing serious adverse health consequences or death, the activity must be an onsite audit unless there is a written determination that other activities provide adequate assurance. That written determination is what is usually missing where document review has been substituted.
What is the most commonly missed exposure?+
Sub-tier convergence. Organisations dual-source deliberately and record the material as low continuity risk, without asking where each supplier obtains it. Multiple direct suppliers frequently trace to one manufacturer, one port or one region, and the diversification is real only at the tier the assessment examined.
Should service providers be assessed?+
Yes, and they usually are not. Calibration providers, laboratories, sanitation contractors and logistics providers all carry real risk to product safety and quality, and few appear in supplier risk assessments at all because the process was built around materials.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Supplier Quality Assurance
Modern Slavery and Labour Standards Assessment
Assesses the site and its labour supply chain for forced labour, debt bondage, withheld documents and unlawful deductions
Transport Provider Assessment
Assesses a haulier for licensing, driver management, vehicle standards, temperature capability and load security
Supplier Environmental Assessment
Assesses a supplier's environmental performance and certifications
Vendor and Contractor Register
Holds every supplier, contractor and service provider you work with, including their status and approval level
Material Rejection Report
Rejects incoming material that fails inspection
Supplier Approval Record
Records the decision to approve a new supplier, with the evidence behind it
More in Suppliers
Supplier Approval Record
Records the decision to approve a new supplier, with the evidence behind it
Supplier Questionnaire
Collects information about a supplier's systems, certifications and controls
Supplier Audit
Audits a supplier's site against your requirements
Supplier Scorecard
Scores a supplier on quality, delivery, responsiveness and cost over a period
Supplier Corrective Request
Asks a supplier to investigate and fix a problem with their material or service
Material Specification Record
Holds the agreed specification for each material you buy, including tolerances and test methods

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 9001:2015 clauses 6.1, 8.4.1 and 8.4.2
- 21 CFR 117 Subpart G, supply chain program, FDA
- ISO 31000:2018, risk management guidelines
- ISO 22301:2019, business continuity management systems
- BRCGS Food Safety Issue 9 and SQF Edition 9, raw material risk assessment and supplier approval
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.