Knowella

Supplier Risk Assessment Template

Supplier risk assessment exists to answer one question: how much verification does this supplier warrant. Get it wrong in one direction and you audit a packaging supplier annually while a sole-source ingredient carrying a serious hazard is approved on a certificate. Get it wrong in the other and you spend the year auditing everyone equally, which is the same as not prioritising at all.

KnowQualityAssessmentQUA-045Pinned in navigation42 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 9001 cl.6.1, ISO 31000
Workspace
KnowQuality
Form type
Assessment
Determines
Verification intensity per supplier
Two axes
Hazard and dependency

The short version

  • Hazard and dependency are separate axes. Verification addresses the first; dual sourcing, stockholding and qualified alternatives address the second.
  • Under FSMA supply chain requirements the verification activity must be appropriate to the hazard, and an onsite audit is required for hazards with a reasonable probability of serious adverse health consequences unless a written determination supports otherwise.
  • Certification narrows what you need to verify; it does not answer whether the supplier can meet your specification, handle your allergen profile or trace your batch.
  • The tier below your supplier is usually where the exposure sits, and it is the tier nobody assesses. A single upstream source can serve several of your apparently independent suppliers.
  • Performance data you already hold, rejections, complaints, late deliveries, certificate lapses, is better risk information than most questionnaires and is rarely fed back into the assessment.
  • Reassess on change: new material, new site, ownership change, or a shift in the supplier's own supply base.

What this is

What is a supplier risk assessment?

What is a supplier risk assessment?

An assessment of the risk a supplier presents across two largely independent dimensions: the hazard the material or service carries, and the organisation's exposure if that supplier fails. It concludes with the verification activity and approval conditions the supplier warrants.

Why two dimensions?

Because they are different risks with different controls. A material with a serious health hazard needs verification of the supplier's controls; a sole-source supplier with no alternative needs continuity arrangements. A material can be high on one axis and low on the other, and treating them as a single score conceals which control is needed.

Scope

When is a supplier risk assessment required?

This assessment determines what verification a supplier warrants. It is not the verification itself.

Use this template when

  • Approving a new supplier, or a new material from an existing supplier
  • Setting the verification activity and frequency proportionate to hazard and dependency
  • Reviewing after a quality failure, complaint pattern, delivery failure or ownership change
  • Establishing continuity exposure for sole-sourced or single-route materials
  • Where a regulatory regime requires the verification activity to be justified against the hazard

Do not use it for

  • The supplier audit, which is one verification activity this assessment may specify
  • Incoming inspection and testing, which verifies the delivery
  • The approved supplier list, which records the decision this assessment informs
  • Supplier performance scorecards, which measure ongoing performance and feed back into this
  • Contract and commercial terms, which allocate liability rather than assess risk

Compliance mapping

Which ISO 9001 cl.6.1 requirements does this satisfy?

Supplier risk sits under quality management control requirements, a risk management framework, and, for food, a statutory verification regime.

ClauseRequirementWhere it lands
ISO 9001 cl.8.4.1Determine controls for externally provided processes, products and services based on their impactHeader
ISO 9001 cl.8.4.2Type and extent of control based on the supplier's ability to meet requirementsResult
ISO 9001 cl.6.1Actions to address risks and opportunities, proportionate to the potential impact on conformityHeader
ISO 31000Risk management framework, principles and process applied consistently across the assessmentHeader
21 CFR 117.410Supplier verification activities appropriate to the hazard requiring a supply chain controlMaterial hazard
21 CFR 117.430Verification activities for hazards controlled by the supplier, with defined options and justificationResult
ISO 22301Business continuity management, addressing the dependency dimension of supplier riskBusiness continuity
BRCGS and SQFRaw material risk assessment determining approval and ongoing verification requirementsMaterial hazard

What it does not cover

  • The supplier audit, which is one verification activity this assessment may require.
  • Incoming inspection and testing, verifying what arrived rather than the system producing it.
  • The approved supplier list, which records the approval decision.
  • Supplier scorecards, which track ongoing performance between assessments.
  • Contractual terms and indemnities, which allocate liability without reducing exposure.

How to complete it

How to complete a supplier risk assessment, step by step

Assess the two axes separately, use the data you already hold, and look one tier further than feels necessary.

Assess hazard from the material and its use

What could go wrong with this material, how severe would it be, and does your process control it downstream. An ingredient whose hazard your process eliminates is different from one that reaches the consumer as received, and the second warrants verification of the supplier's controls rather than reliance on your own.

Assess dependency separately

Sole source or multiple, qualified alternatives available or not, lead time to switch, single site or single route, and how long you could operate without it. This produces continuity actions rather than verification actions, and the two lists should look different.

Use the performance data you already hold

Rejection rates, complaint attribution, delivery reliability, certificate lapses, responsiveness on corrective actions. This is real behavioural data from the relationship and is a better predictor than any questionnaire, and it is routinely collected and never connected to the risk assessment.

Look one tier up on anything critical

Where a material is sole-sourced or a hazard is serious, ask where your supplier gets it. Several apparently independent suppliers frequently converge on one upstream source, one port or one region, and the diversification you believe you have does not exist below the first tier.

What auditors find

Most common supplier risk assessment findings

Findings here concern proportionality and the tier below.

FindingClauseWhat fixes it
Hazard and dependency combined into a single score.ISO 31000Assess separately; they require different controls and one masks the other.
Verification activity uniform across suppliers regardless of risk.ISO 9001 cl.8.4.2Set intensity from the assessment; equal effort is the same as no prioritisation.
Onsite audit replaced with document review with no written determination.21 CFR 117.410Record the determination where an alternative activity is used for a serious hazard.
Certification treated as satisfying the assessment.ISO 9001 cl.8.4.1Certification narrows verification scope; it does not confirm fit to your specification.
Sub-tier exposure not assessed for sole-sourced materials.ISO 22301Ask where your supplier sources; apparent diversification frequently collapses one tier up.
Performance data held but not fed into the assessment.ISO 9001 cl.9.1Rejections, complaints and delivery failures are better predictors than questionnaires.
No reassessment after supplier ownership or site change.ISO 9001 cl.8.4.1Ownership, site and process changes at the supplier are all triggers.
Continuity exposure identified with no action taken.ISO 22301Qualify an alternative or hold stock; identifying dependency without acting changes nothing.
Service providers excluded from supplier risk assessment.ISO 9001 cl.8.4.1Calibration, laboratory, sanitation and logistics providers carry real risk and are rarely assessed.
Assessment not connected to the approval decision.BRCGS / SQFLink them; an assessment that does not affect approval status is documentation.

Case in point

Case in point: three suppliers, one factory

A manufacturer dual-sourced a critical ingredient deliberately, holding contracts with three suppliers in different countries and treating the material as low continuity risk on that basis. The risk assessment recorded multiple qualified sources and required only annual document review.

A production interruption at a single plant took all three offline within a fortnight. Two of the three suppliers were distributors buying from the same manufacturer, and the third had a supply agreement with it for part of its own volume.

The diversification existed at the tier the assessment looked at and nowhere below it. The question that would have found this, where does your supplier obtain this material, had never been asked because the material was already recorded as multi-sourced.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

42fields
5 sections
Reference
QUA-045
Archetype
Assessment
Record ID
RSK-2026-000
Scoring
Risk band
Direction
High is bad
Singleton
No
Basis
ISO 9001 cl.6.1, ISO 31000
Links
Links Vendor
Tags
Supplier, Risk
Sections
5
Fields
42
Follow up fields
3
Repeating sections
0
Links out
2
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

8 fields
Text

Assessment ID*

Generated on save

Auto sequence. Format RSK-2026-00000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date*

Users

Completed By*

Pick List

Supplier*

From FDN-005 Vendor NameFilter: Status is Approved
Text

Vendor ID*

Linked

Format VEN-0000.

Links to FDN-005 Vendor ID

Text

Materials Covered*

Single Choice

Assessment Trigger*

ComplaintPermit requirementPlant changePeriodicNew installationAfter an incident

Material hazard

8 fields
Single Choice

Material Risk Category*

Scored
  • High risk raw material0 pts
  • Medium risk ingredient1 pt
  • Low risk ingredient2 pts
  • Packaging2 pts
  • Service3 pts
Single Choice

Ready To Eat Or Further Processed*

Scored

A material going into ready to eat product with no kill step carries far more risk.

  • Further processed with kill step3 pts
  • Ready to eat0 pts
Single Choice

Kill Step After Receipt*

Scored
  • Yes, validated3 pts
  • Partial1 pt
  • None0 pts
Single Choice

Allergen Present*

Scored
  • No3 pts
  • Yes0 pts
Single Choice

Pathogen Risk*

Scored
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Contaminant Risk*

Scored
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Foreign Body Risk*

Scored
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Detected By Our Systems*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Supply chain

6 fields
Single Choice

Supply Chain Length*

Scored

Every intermediary is a point where substitution or dilution can occur.

  • Direct from producer3 pts
  • One intermediary2 pts
  • Two or more intermediaries0 pts
Single Choice

Country Of Origin Risk*

Scored
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Agent Or Broker Involved*

Scored
  • No3 pts
  • Yes0 pts
Single Choice

Material Commonly Adulterated*

Scored

High value, commodity priced and hard to test materials are the usual targets.

  • No3 pts
  • Occasionally1 pt
  • Yes, known target0 pts
Single Choice

Price Volatility*

Scored
  • Stable3 pts
  • Moderate1 pt
  • High0 pts
Single Choice

Authenticity Testing Possible*

Scored
  • Yes, routine3 pts
  • Yes, specialist1 pt
  • No0 pts

Business continuity

5 fields
Single Choice

Single Source*

Scored
  • No3 pts
  • Yes0 pts
Single Choice

Alternative Supplier Approved*

Scored
  • Yes3 pts
  • Identified not approved1 pt
  • None0 pts
Numeric Answer

Lead Time Weeks

OptionalScored
Single Choice

Supplier Financial Stability

OptionalScored
  • Strong3 pts
  • Adequate2 pts
  • Concerns0 pts
Single Choice

Geographic Or Climate Exposure

OptionalScored
  • Low3 pts
  • Medium1 pt
  • High0 pts

Result

15 fields
Single Choice

Inherent Band*

Scored
  • Low, 1 to 45 pts
  • Medium, 5 to 94 pts
  • High, 10 to 142 pts
  • Very high, 15 to 191 pt
  • Extreme, 20 to 250 pts
Single Choice

Current Band*

Scored
  • Low, 1 to 45 pts
  • Medium, 5 to 94 pts
  • High, 10 to 142 pts
  • Very high, 15 to 191 pt
  • Extreme, 20 to 250 pts
Single Choice

Residual Band*

Scored
  • Low, 1 to 45 pts
  • Medium, 5 to 94 pts
  • High, 10 to 142 pts
  • Very high, 15 to 191 pt
  • Extreme, 20 to 250 pts
Single Choice

Risk Tier Assigned*

Scored
  • Low3 pts
  • Medium2 pts
  • High1 pt
  • Critical0 pts
Single Choice

Audit Frequency Set*

Scored
  • Each visit4 pts
  • Monthly3 pts
  • Quarterly2 pts
  • Annually1 pt
Single Choice

Inspection Level Set*

Scored
  • Reduced3 pts
  • Normal2 pts
  • Tightened1 pt
  • 100 percent0 pts
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Date & Time

Next Review Due*

Users

Quality Manager*

Signature

Signature*

Users

Procurement*

Signature

Second Signature*

QUA-045 · record IDs look like RSK-2026-000 · Links Vendor

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The assessment sets verification intensity. What fails is the single combined score and the tier nobody asked about.

KnowQuality

Holds hazard and dependency as separate dimensions, and drives verification activity and approval status from the assessment.

Ella
Ella

Feeds rejection, complaint and delivery data back into the assessment continuously, rather than waiting for an annual review.

KnowLogistics

Surfaces sub-tier and routing convergence, where apparently independent suppliers share an origin, a port or a corridor.

KnowContractor

Extends the same assessment logic to service providers, who carry real risk and are usually outside the supplier process.

This template lives in KnowQuality — quality and food safety. HACCP, nonconformance, traceability, laboratory and customer complaints.

Meet KnowQuality→

Glossary

Supplier Risk Assessment definitions and key terms

Supply chain control
Under FSMA, a preventive control applied to a hazard controlled before receipt, requiring supplier verification.
Sub-tier exposure
Risk arising below your direct supplier, where apparently independent sources converge on a common origin.
Qualified alternative
A second supplier already approved and validated, distinct from one that could be qualified given time.
Dependency
The organisation's exposure if a supplier fails, determined by sourcing options, lead time and stock position.
Written determination
The documented justification required under FSMA where an alternative to an onsite audit is used for a serious hazard.
Verification intensity
The depth and frequency of verification activity, which the assessment exists to set proportionately.
Approved supplier list
The record of suppliers approved to supply specified materials, updated by the outcome of this assessment.
Service provider risk
Exposure from calibration, laboratory, sanitation and logistics providers, routinely omitted from supplier assessment.

FAQ

Frequently asked questions about supplier risk assessment

Why separate hazard from dependency?+

Because they require different responses. Hazard is addressed by verifying the supplier's controls; dependency is addressed by dual sourcing, stockholding or qualifying an alternative. A supplier can be high on one and low on the other, and a combined score lands them in the middle of a list where they receive an intervention that addresses neither.

Does certification reduce the assessment?+

It narrows what needs verifying rather than replacing the assessment. A GFSI-recognised certificate establishes that a scheme-accredited body found the system compliant when it visited. It does not establish that the supplier can meet your specification, is compatible with your allergen profile, or can trace your batch, which is what a second-party activity should address.

What does FSMA require?+

That the verification activity is appropriate to the hazard requiring a supply chain control. Where a hazard has a reasonable probability of causing serious adverse health consequences or death, the activity must be an onsite audit unless there is a written determination that other activities provide adequate assurance. That written determination is what is usually missing where document review has been substituted.

What is the most commonly missed exposure?+

Sub-tier convergence. Organisations dual-source deliberately and record the material as low continuity risk, without asking where each supplier obtains it. Multiple direct suppliers frequently trace to one manufacturer, one port or one region, and the diversification is real only at the tier the assessment examined.

Should service providers be assessed?+

Yes, and they usually are not. Calibration providers, laboratories, sanitation contractors and logistics providers all carry real risk to product safety and quality, and few appear in supplier risk assessments at all because the process was built around materials.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 9001:2015 clauses 6.1, 8.4.1 and 8.4.2
  • 21 CFR 117 Subpart G, supply chain program, FDA
  • ISO 31000:2018, risk management guidelines
  • ISO 22301:2019, business continuity management systems
  • BRCGS Food Safety Issue 9 and SQF Edition 9, raw material risk assessment and supplier approval

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.