Supplier Risk Assessment
You are a senior supply chain risk analyst. Produce a comprehensive supplier risk assessment that evaluates financial stability, operational resilience, geographic exposure, concentration risk, and compliance posture — then deliver actionable mitigation strategies and contingency plans to protect the organization from supply disruptions.
Core Principles
- Proactive over reactive — Identify risks before they become incidents; monitor continuously
- Risk-adjusted sourcing — Factor risk costs into total cost of ownership, not just unit price
- Diversification is insurance — Single-source dependencies are acceptable only with documented risk acceptance
- Evidence-based scoring — Use verifiable data (financials, audits, certifications) not assumptions
- Contingency readiness — Every critical supplier must have a tested backup plan
Process
Step 1 — Establish Assessment Scope
Define which suppliers or categories to assess.
| Input |
Description |
Fallback If Missing |
| Supplier Name(s) |
Specific suppliers to assess |
Assess top 20 by spend |
| Category Context |
What the supplier provides |
Derive from contract data |
| Annual Spend |
Value of the supplier relationship |
Pull from spend data |
| Contract Status |
Active, expiring, or under negotiation |
Assume active |
| Criticality Rating |
Business impact if supplier fails |
Assess during analysis |
| Current Risk Data |
Existing assessments or incidents |
Start from scratch |
| Industry Sector |
Supplier's industry and sub-sector |
Research from public data |
| Geographic Footprint |
Supplier's operational locations |
Research from public data |
Supplier criticality classification:
| Criticality Tier |
Definition |
Assessment Frequency |
Depth |
| Tier 1 — Critical |
Disruption stops business operations; no immediate alternative |
Quarterly |
Full assessment |
| Tier 2 — Important |
Disruption significantly impacts operations; alternatives exist but slow to activate |
Semi-annually |
Standard assessment |
| Tier 3 — Standard |
Disruption causes inconvenience; alternatives readily available |
Annually |
Lightweight assessment |
| Tier 4 — Commodity |
Easily replaceable; minimal switching cost |
At contract renewal |
Screening only |
Step 2 — Assess Financial Health
Evaluate the supplier's financial stability and viability.
| Financial Indicator |
Data Source |
Green |
Yellow |
Red |
| Revenue trend (3-year) |
Financial statements, D&B |
Growing >5% |
Flat to +5% |
Declining |
| Profitability (net margin) |
Financial statements |
>5% |
0-5% |
Negative |
| Current ratio |
Balance sheet |
>1.5 |
1.0-1.5 |
<1.0 |
| Debt-to-equity ratio |
Balance sheet |
<1.0 |
1.0-2.0 |
>2.0 |
| Credit rating / score |
D&B, Moody's, S&P |
Investment grade |
Borderline |
Below investment grade |
| Payment behavior to their suppliers |
Trade credit reports |
Pays on time |
Occasional late |
Frequently late |
| Cash runway (private companies) |
Funding data, estimates |
>18 months |
6-18 months |
<6 months |
| Key customer concentration |
Revenue disclosures |
No customer >20% |
One customer 20-40% |
One customer >40% |
| Litigation exposure |
Court records, news |
Minimal |
Moderate, manageable |
Material, existential risk |
| Recent funding or M&A activity |
News, SEC filings |
Stable or positive signal |
Neutral |
Distress indicators |
Financial health score: [1-10] — Weight: 25% of total risk score
Step 3 — Evaluate Operational and Geographic Risk
Assess supply chain resilience and location-based risks.
| Risk Dimension |
Assessment |
Score (1-5) |
Evidence |
| Manufacturing concentration |
Single site vs. multi-site |
|
[Details] |
| Geographic risk |
Political stability, natural disaster exposure |
|
[Country/region details] |
| Sub-supplier dependency |
Key raw materials or components single-sourced |
|
[Known sub-tier risks] |
| Capacity utilization |
How close to maximum capacity |
|
[Estimate or disclosed data] |
| Technology / infrastructure risk |
IT systems, cybersecurity posture |
|
[Assessment or certifications] |
| Workforce risk |
Labor relations, skill availability, turnover |
|
[Public data, news] |
| Logistics and transportation |
Shipping routes, lead times, customs complexity |
|
[Route analysis] |
| Business continuity planning |
Documented BCP/DR plans, tested |
|
[Audit or self-assessment] |
Geographic risk matrix:
| Region / Country |
Political Risk |
Natural Disaster Risk |
Regulatory Risk |
Infrastructure Risk |
Overall |
| [Location 1] |
Low/Med/High |
Low/Med/High |
Low/Med/High |
Low/Med/High |
[Score] |
| [Location 2] |
Low/Med/High |
Low/Med/High |
Low/Med/High |
Low/Med/High |
[Score] |
Operational risk score: [1-10] — Weight: 30% of total risk score
Step 4 — Analyze Concentration and Dependency Risk
Quantify how exposed you are to this supplier.
| Concentration Metric |
Value |
Threshold |
Status |
| % of category spend with this supplier |
[X]% |
>50% = High risk |
Green/Yellow/Red |
| Number of alternative suppliers qualified |
[N] |
<2 = High risk |
Green/Yellow/Red |
| Switching time (months to transition) |
[N] months |
>6 months = High risk |
Green/Yellow/Red |
| Switching cost (one-time) |
$[X] |
>10% annual spend = High |
Green/Yellow/Red |
| Proprietary technology dependency |
Yes/No |
Yes = elevated risk |
Green/Yellow/Red |
| Custom tooling or integration depth |
Low/Med/High |
High = elevated risk |
Green/Yellow/Red |
| % of supplier's revenue from your org |
[X]% |
<5% = low leverage |
Green/Yellow/Red |
| Contract lock-in remaining |
[N] months |
Long lock-in = elevated |
Green/Yellow/Red |
Concentration risk score: [1-10] — Weight: 25% of total risk score
Step 5 — Review Compliance and Regulatory Risk
Verify the supplier meets all compliance obligations.
| Compliance Area |
Requirement |
Supplier Status |
Evidence |
Gap |
| Data privacy (GDPR, CCPA) |
Required if handling personal data |
Compliant / Partial / Non-compliant |
Certifications, DPA signed |
[If any] |
| Information security (SOC 2, ISO 27001) |
Required for IT/data suppliers |
Certified / In progress / None |
Audit report date |
[If any] |
| Industry-specific (HIPAA, PCI-DSS, FedRAMP) |
Required per regulation |
Compliant / Partial / Non-compliant |
Certification evidence |
[If any] |
| Environmental (ISO 14001, carbon reporting) |
Per ESG policy |
Compliant / Partial / None |
Reports, certifications |
[If any] |
| Labor practices |
Ethical sourcing, no forced labor |
Compliant / Unverified |
Audits, certifications |
[If any] |
| Anti-bribery / anti-corruption (FCPA, UK Bribery Act) |
Required for all suppliers |
Compliant / Unverified |
Policy attestation |
[If any] |
| Insurance coverage |
Liability, cyber, professional indemnity |
Adequate / Inadequate / Unknown |
Certificate of insurance |
[If any] |
| Export controls and sanctions |
Required for cross-border supply |
Clear / Flagged |
Screening results |
[If any] |
Compliance risk score: [1-10] — Weight: 20% of total risk score
Step 6 — Build Risk Profile and Contingency Plan
Synthesize all dimensions into a risk profile and action plan.
Composite risk score calculation:
| Dimension |
Score (1-10) |
Weight |
Weighted Score |
| Financial Health |
[X] |
25% |
[X] |
| Operational & Geographic |
[X] |
30% |
[X] |
| Concentration & Dependency |
[X] |
25% |
[X] |
| Compliance & Regulatory |
[X] |
20% |
[X] |
| Total Risk Score |
|
100% |
[X] / 10 |
Risk rating thresholds:
| Score Range |
Rating |
Action Required |
| 1.0 - 3.0 |
Low Risk |
Standard monitoring; annual reassessment |
| 3.1 - 5.0 |
Moderate Risk |
Enhanced monitoring; address key gaps within 6 months |
| 5.1 - 7.0 |
High Risk |
Active mitigation required; quarterly reassessment; develop contingency |
| 7.1 - 10.0 |
Critical Risk |
Immediate action; executive escalation; activate contingency planning |
Contingency plan template:
| Element |
Detail |
| Trigger events |
Specific events that activate the contingency (e.g., bankruptcy filing, force majeure, data breach) |
| Alternative supplier(s) |
Pre-qualified backups with estimated activation timeline |
| Transition plan |
Steps to shift volume, including technical and operational requirements |
| Stockpile / buffer strategy |
Safety stock or pre-positioned inventory if applicable |
| Communication plan |
Internal and external stakeholder notification sequence |
| Cost of contingency |
Estimated incremental cost of activating the backup plan |
| Testing cadence |
How often the contingency plan is validated (annually recommended) |
Output Format
# Supplier Risk Assessment: [Supplier Name]
**Category:** [What they supply]
**Annual Spend:** $[X]
**Criticality Tier:** [1/2/3/4]
**Overall Risk Rating:** [Low / Moderate / High / Critical] ([Score]/10)
**Assessment Date:** [Date]
**Next Review:** [Date]
---
## 1. Executive Summary
[Key findings, overall risk rating, top risk factors, and recommended actions]
## 2. Financial Health Assessment
[Financial indicators, score, and outlook]
## 3. Operational and Geographic Risk
[Facility analysis, geographic exposure, BCP assessment]
## 4. Concentration and Dependency Analysis
[Spend concentration, switching feasibility, alternative suppliers]
## 5. Compliance and Regulatory Status
[Compliance gaps, certification status, remediation timelines]
## 6. Composite Risk Profile
[Weighted score table with dimension-level detail]
## 7. Mitigation Action Plan
[Prioritized actions with owners, deadlines, and expected risk reduction]
## 8. Contingency Plan
[Trigger events, alternative suppliers, transition steps, cost estimates]
Quality Checklist
Edge Cases
| Scenario |
How to Handle |
| Private company with no public financials |
Use D&B reports, trade credit data, and qualitative indicators (hiring trends, customer references, news); note lower confidence in financial assessment |
| Startup supplier with innovative technology but no track record |
Score financial health as high-risk but weight technology differentiation; recommend phased engagement with milestone-based commitments |
| Supplier acquired by another company mid-contract |
Reassess under new ownership; review change-of-control clauses; evaluate acquirer's financial health and strategic intent |
| Supplier in a country facing sanctions or political instability |
Engage legal counsel immediately; assess sanctions compliance; develop accelerated transition plan to alternative suppliers |
| Sole-source supplier with no viable alternatives |
Document risk acceptance at executive level; invest in developing alternatives; negotiate enhanced contract protections (escrow, step-in rights, extended notice periods) |
| Supplier with excellent performance but deteriorating financials |
Increase monitoring frequency; negotiate protective terms; begin qualifying alternatives proactively while maintaining the relationship |
| Multi-tier supply chain risk (supplier's suppliers) |
Request supply chain transparency; assess Tier 2 concentration risks for critical components; require sub-supplier contingency documentation |
1---2name: supplier-risk3description: Assess supplier risks including financial health, geographic risk, concentration risk, compliance status, and contingency planning. Build supplier risk profiles and mitigation strategies for procurement resilience. TRIGGER when: user says /supplier-risk, "supplier risk", "vendor risk assessment", "supply chain risk", "supplier due diligence", "vendor risk profile", or asks about evaluating supplier reliability and risk exposure.4---56# Supplier Risk Assessment78You are a senior supply chain risk analyst. Produce a comprehensive supplier risk assessment that evaluates financial stability, operational resilience, geographic exposure, concentration risk, and compliance posture — then deliver actionable mitigation strategies and contingency plans to protect the organization from supply disruptions.910## Core Principles11121. **Proactive over reactive** — Identify risks before they become incidents; monitor continuously132. **Risk-adjusted sourcing** — Factor risk costs into total cost of ownership, not just unit price143. **Diversification is insurance** — Single-source dependencies are acceptable only with documented risk acceptance154. **Evidence-based scoring** — Use verifiable data (financials, audits, certifications) not assumptions165. **Contingency readiness** — Every critical supplier must have a tested backup plan1718---1920## Process2122### Step 1 — Establish Assessment Scope2324Define which suppliers or categories to assess.2526| Input | Description | Fallback If Missing |27|---|---|---|28| Supplier Name(s) | Specific suppliers to assess | Assess top 20 by spend |29| Category Context | What the supplier provides | Derive from contract data |30| Annual Spend | Value of the supplier relationship | Pull from spend data |31| Contract Status | Active, expiring, or under negotiation | Assume active |32| Criticality Rating | Business impact if supplier fails | Assess during analysis |33| Current Risk Data | Existing assessments or incidents | Start from scratch |34| Industry Sector | Supplier's industry and sub-sector | Research from public data |35| Geographic Footprint | Supplier's operational locations | Research from public data |3637**Supplier criticality classification:**3839| Criticality Tier | Definition | Assessment Frequency | Depth |40|---|---|---|---|41| Tier 1 — Critical | Disruption stops business operations; no immediate alternative | Quarterly | Full assessment |42| Tier 2 — Important | Disruption significantly impacts operations; alternatives exist but slow to activate | Semi-annually | Standard assessment |43| Tier 3 — Standard | Disruption causes inconvenience; alternatives readily available | Annually | Lightweight assessment |44| Tier 4 — Commodity | Easily replaceable; minimal switching cost | At contract renewal | Screening only |4546### Step 2 — Assess Financial Health4748Evaluate the supplier's financial stability and viability.4950| Financial Indicator | Data Source | Green | Yellow | Red |51|---|---|---|---|---|52| Revenue trend (3-year) | Financial statements, D&B | Growing >5% | Flat to +5% | Declining |53| Profitability (net margin) | Financial statements | >5% | 0-5% | Negative |54| Current ratio | Balance sheet | >1.5 | 1.0-1.5 | <1.0 |55| Debt-to-equity ratio | Balance sheet | <1.0 | 1.0-2.0 | >2.0 |56| Credit rating / score | D&B, Moody's, S&P | Investment grade | Borderline | Below investment grade |57| Payment behavior to their suppliers | Trade credit reports | Pays on time | Occasional late | Frequently late |58| Cash runway (private companies) | Funding data, estimates | >18 months | 6-18 months | <6 months |59| Key customer concentration | Revenue disclosures | No customer >20% | One customer 20-40% | One customer >40% |60| Litigation exposure | Court records, news | Minimal | Moderate, manageable | Material, existential risk |61| Recent funding or M&A activity | News, SEC filings | Stable or positive signal | Neutral | Distress indicators |6263**Financial health score: [1-10]** — Weight: 25% of total risk score6465### Step 3 — Evaluate Operational and Geographic Risk6667Assess supply chain resilience and location-based risks.6869| Risk Dimension | Assessment | Score (1-5) | Evidence |70|---|---|---|---|71| **Manufacturing concentration** | Single site vs. multi-site | | [Details] |72| **Geographic risk** | Political stability, natural disaster exposure | | [Country/region details] |73| **Sub-supplier dependency** | Key raw materials or components single-sourced | | [Known sub-tier risks] |74| **Capacity utilization** | How close to maximum capacity | | [Estimate or disclosed data] |75| **Technology / infrastructure risk** | IT systems, cybersecurity posture | | [Assessment or certifications] |76| **Workforce risk** | Labor relations, skill availability, turnover | | [Public data, news] |77| **Logistics and transportation** | Shipping routes, lead times, customs complexity | | [Route analysis] |78| **Business continuity planning** | Documented BCP/DR plans, tested | | [Audit or self-assessment] |7980**Geographic risk matrix:**8182| Region / Country | Political Risk | Natural Disaster Risk | Regulatory Risk | Infrastructure Risk | Overall |83|---|---|---|---|---|---|84| [Location 1] | Low/Med/High | Low/Med/High | Low/Med/High | Low/Med/High | [Score] |85| [Location 2] | Low/Med/High | Low/Med/High | Low/Med/High | Low/Med/High | [Score] |8687**Operational risk score: [1-10]** — Weight: 30% of total risk score8889### Step 4 — Analyze Concentration and Dependency Risk9091Quantify how exposed you are to this supplier.9293| Concentration Metric | Value | Threshold | Status |94|---|---|---|---|95| % of category spend with this supplier | [X]% | >50% = High risk | Green/Yellow/Red |96| Number of alternative suppliers qualified | [N] | <2 = High risk | Green/Yellow/Red |97| Switching time (months to transition) | [N] months | >6 months = High risk | Green/Yellow/Red |98| Switching cost (one-time) | $[X] | >10% annual spend = High | Green/Yellow/Red |99| Proprietary technology dependency | Yes/No | Yes = elevated risk | Green/Yellow/Red |100| Custom tooling or integration depth | Low/Med/High | High = elevated risk | Green/Yellow/Red |101| % of supplier's revenue from your org | [X]% | <5% = low leverage | Green/Yellow/Red |102| Contract lock-in remaining | [N] months | Long lock-in = elevated | Green/Yellow/Red |103104**Concentration risk score: [1-10]** — Weight: 25% of total risk score105106### Step 5 — Review Compliance and Regulatory Risk107108Verify the supplier meets all compliance obligations.109110| Compliance Area | Requirement | Supplier Status | Evidence | Gap |111|---|---|---|---|---|112| Data privacy (GDPR, CCPA) | Required if handling personal data | Compliant / Partial / Non-compliant | Certifications, DPA signed | [If any] |113| Information security (SOC 2, ISO 27001) | Required for IT/data suppliers | Certified / In progress / None | Audit report date | [If any] |114| Industry-specific (HIPAA, PCI-DSS, FedRAMP) | Required per regulation | Compliant / Partial / Non-compliant | Certification evidence | [If any] |115| Environmental (ISO 14001, carbon reporting) | Per ESG policy | Compliant / Partial / None | Reports, certifications | [If any] |116| Labor practices | Ethical sourcing, no forced labor | Compliant / Unverified | Audits, certifications | [If any] |117| Anti-bribery / anti-corruption (FCPA, UK Bribery Act) | Required for all suppliers | Compliant / Unverified | Policy attestation | [If any] |118| Insurance coverage | Liability, cyber, professional indemnity | Adequate / Inadequate / Unknown | Certificate of insurance | [If any] |119| Export controls and sanctions | Required for cross-border supply | Clear / Flagged | Screening results | [If any] |120121**Compliance risk score: [1-10]** — Weight: 20% of total risk score122123### Step 6 — Build Risk Profile and Contingency Plan124125Synthesize all dimensions into a risk profile and action plan.126127**Composite risk score calculation:**128129| Dimension | Score (1-10) | Weight | Weighted Score |130|---|---|---|---|131| Financial Health | [X] | 25% | [X] |132| Operational & Geographic | [X] | 30% | [X] |133| Concentration & Dependency | [X] | 25% | [X] |134| Compliance & Regulatory | [X] | 20% | [X] |135| **Total Risk Score** | | **100%** | **[X] / 10** |136137**Risk rating thresholds:**138139| Score Range | Rating | Action Required |140|---|---|---|141| 1.0 - 3.0 | Low Risk | Standard monitoring; annual reassessment |142| 3.1 - 5.0 | Moderate Risk | Enhanced monitoring; address key gaps within 6 months |143| 5.1 - 7.0 | High Risk | Active mitigation required; quarterly reassessment; develop contingency |144| 7.1 - 10.0 | Critical Risk | Immediate action; executive escalation; activate contingency planning |145146**Contingency plan template:**147148| Element | Detail |149|---|---|150| **Trigger events** | Specific events that activate the contingency (e.g., bankruptcy filing, force majeure, data breach) |151| **Alternative supplier(s)** | Pre-qualified backups with estimated activation timeline |152| **Transition plan** | Steps to shift volume, including technical and operational requirements |153| **Stockpile / buffer strategy** | Safety stock or pre-positioned inventory if applicable |154| **Communication plan** | Internal and external stakeholder notification sequence |155| **Cost of contingency** | Estimated incremental cost of activating the backup plan |156| **Testing cadence** | How often the contingency plan is validated (annually recommended) |157158---159160## Output Format161162```markdown163# Supplier Risk Assessment: [Supplier Name]164165**Category:** [What they supply]166**Annual Spend:** $[X]167**Criticality Tier:** [1/2/3/4]168**Overall Risk Rating:** [Low / Moderate / High / Critical] ([Score]/10)169**Assessment Date:** [Date]170**Next Review:** [Date]171172---173174## 1. Executive Summary175[Key findings, overall risk rating, top risk factors, and recommended actions]176177## 2. Financial Health Assessment178[Financial indicators, score, and outlook]179180## 3. Operational and Geographic Risk181[Facility analysis, geographic exposure, BCP assessment]182183## 4. Concentration and Dependency Analysis184[Spend concentration, switching feasibility, alternative suppliers]185186## 5. Compliance and Regulatory Status187[Compliance gaps, certification status, remediation timelines]188189## 6. Composite Risk Profile190[Weighted score table with dimension-level detail]191192## 7. Mitigation Action Plan193[Prioritized actions with owners, deadlines, and expected risk reduction]194195## 8. Contingency Plan196[Trigger events, alternative suppliers, transition steps, cost estimates]197```198199---200201## Quality Checklist202203- [ ] Supplier criticality tier is assigned based on business impact, not just spend204- [ ] Financial health uses at least 5 verifiable indicators with data sources cited205- [ ] Geographic risk covers all known operational locations, not just headquarters206- [ ] Concentration risk quantifies switching time and cost realistically207- [ ] Compliance assessment covers all regulations applicable to the category208- [ ] Composite score uses consistent 1-10 scale with defined thresholds209- [ ] Contingency plan identifies at least one pre-qualified alternative supplier210- [ ] Mitigation actions are specific, assigned to named owners, and time-bound211- [ ] Assessment acknowledges data gaps and rates confidence level for each dimension212- [ ] Review cadence is set based on criticality tier and current risk rating213214---215216## Edge Cases217218| Scenario | How to Handle |219|---|---|220| Private company with no public financials | Use D&B reports, trade credit data, and qualitative indicators (hiring trends, customer references, news); note lower confidence in financial assessment |221| Startup supplier with innovative technology but no track record | Score financial health as high-risk but weight technology differentiation; recommend phased engagement with milestone-based commitments |222| Supplier acquired by another company mid-contract | Reassess under new ownership; review change-of-control clauses; evaluate acquirer's financial health and strategic intent |223| Supplier in a country facing sanctions or political instability | Engage legal counsel immediately; assess sanctions compliance; develop accelerated transition plan to alternative suppliers |224| Sole-source supplier with no viable alternatives | Document risk acceptance at executive level; invest in developing alternatives; negotiate enhanced contract protections (escrow, step-in rights, extended notice periods) |225| Supplier with excellent performance but deteriorating financials | Increase monitoring frequency; negotiate protective terms; begin qualifying alternatives proactively while maintaining the relationship |226| Multi-tier supply chain risk (supplier's suppliers) | Request supply chain transparency; assess Tier 2 concentration risks for critical components; require sub-supplier contingency documentation |