Free templateWord · Google Docs · PDF

Supply Chain Risk Assessment Template

A supply chain risk assessment template is a structured document for finding, scoring and planning around the risks your suppliers pose. It profiles each supplier, rates every risk by likelihood and impact, and assigns actions and owners to the highest scores.

  • Supplier profiles and a scored risk register
  • 5x5 likelihood and impact scoring matrix
  • Mitigation plan, security review and policy
Book a demo
Updated 7 Oct 20265 partsReviewed by the Spendflo procurement team
What's inside

Five parts, one supply chain risk management template

One document covers the assessment itself, the scoring matrix, a supply chain risk management plan, a security risk review and a policy outline. Click any card to jump to that part.
  1. 1Risk assessmentSix sections in order, with a filled risk register for five suppliers.
  2. 2Scoring matrixThe 5x5 likelihood and impact grid, both scales and the rating bands.
  3. 3Risk management planMitigation actions with owners and dates, plus a review cycle by supplier tier.
  4. 4Security assessmentQuestions in five areas for suppliers with access to your systems or data.
  5. 5Risk policySeven policy sections and a sample clause on when assessments are required.

Who it's for

  • Supply chain managers
  • Procurement leads
  • Category managers
  • Risk and compliance officers
  • Operations directors
  • Information security teams
Definition

What is a supply chain risk assessment template?

It is the working file behind supply chain risk management: a list of the suppliers you depend on, the ways each could let you down, and a score that shows which of those problems deserve attention first.

Procurement and operations teams use one when onboarding a critical supplier, before a sourcing decision, after a disruption, and on a fixed annual cycle. The output is a ranked register that tells leadership where a backup supplier, extra stock or a contract change would reduce exposure most.

Because the same scale is used for every supplier, the assessment also makes risks comparable: a freight delay and a data breach can sit in one list and be ranked against each other.

Key components

Supplier and asset profile

Supplier ID, contact, what they supply and a criticality tier for each one.

Risk categories

Operational and quality, financial and credit, geopolitical and environmental, and cybersecurity and compliance.

Risk scoring matrix

Likelihood from 1 to 5 multiplied by impact from 1 to 5, shaded by severity.

Mitigation and action plan

Backup suppliers and other actions, each with an owner and a due date.

Monitoring and review cycle

A full review every 12 months, and every 3-6 months for high-risk suppliers.

Get the supply chain risk assessment template free

Ready to use in Word, Google Docs and PDF. Fill it in, save it, reuse it.

For beginners

How a supply chain risk assessment works

You define which suppliers are in scope, gather facts about them, and score each risk by likelihood and impact. The highest scores get an action plan and a shorter review cycle.
  1. 1
    Define scope

    Pick the suppliers, sites and products to assess, starting with anything sole-sourced or revenue-critical.

  2. 2
    Collect data

    Gather supplier questionnaires, financial checks, certificates, locations and delivery history.

  3. 3
    Identify risks

    Work through the four categories for each supplier and write each risk as a specific event.

  4. 4
    Score and rank

    Rate likelihood and impact from 1 to 5, multiply them and sort the register by score.

  5. 5
    Mitigate and monitor

    Assign actions to every high score and set the next review date by tier.

Need something simpler?

The simplest usable version is one table: Supplier, Risk, Likelihood (1-5), Impact (1-5), Score, Action, Owner. Fill it for your ten most critical suppliers first.

Part 1 · Risk assessment

The supply chain risk assessment template

The assessment runs in six sections, from scope through to the review date. The filled register below shows how each risk is written, scored and ranked.

Fill the sections in order, because each one feeds the next. The profile sets the criticality tier, the tier decides how deep the review goes, and the register produces the scores the plan acts on.

  1. 01Scope and context

    Which suppliers, products and sites are covered, who led the assessment and the date.

  2. 02Supplier and asset profile

    Supplier ID, contact, commodity or service, annual spend, locations and a criticality tier from 1 to 3.

  3. 03Risk identification

    Each risk written as an event, tagged to one of the four risk categories.

  4. 04Risk scoring

    Likelihood and impact from 1 to 5, the product of the two and a severity rating.

  5. 05Mitigation and action plan

    For every high or critical risk: the action, owner, due date and target score.

  6. 06Monitoring and review

    Next review date, the triggers for an early review and sign-off by the risk owner.

Sample risk register

Five suppliers, one risk each, sorted by score.

SupplierRisk eventCategoryLIScoreRating
Northwind LogisticsPort congestion delays inbound freight by 2+ weeksOperational4416High
Kestrel DataShared admin accounts expose customer dataCybersecurity3515High
Cedar PackagingSole packaging supplier misses payments to its own suppliersFinancial3412High
Orbit MetalsNew tariff raises the landed cost of imported steelGeopolitical339Medium
Acme Office SupplySingle warehouse sits in a flood zoneEnvironmental224Low

Illustrative suppliers and scores. L = likelihood, I = impact, Score = L x I.

Part 2 · Scoring matrix

Risk scoring matrix: likelihood x impact

Score each risk from 1 to 5 for likelihood and for impact, then multiply to get a score from 1 to 25. The colour band sets how fast you act.

Agree the scales before anyone scores, or two people will rate the same risk differently. Impact should be judged on the worst realistic outcome for your business, not for the supplier. Write the reason for each score in the register so the next reviewer can test it.

Likelihood \ Impact1 Minimal2 Minor3 Moderate4 Major5 Severe
5 Almost certain510152025
4 Likely48121620
3 Possible3691215
2 Unlikely246810
1 Rare12345

Green 1-4 Low, amber 5-9 Medium, red 10-16 High and 20-25 Critical.

ScoreLikelihood meansImpact means
1Not expected in the next 5 yearsAbsorbed within a day, no customer effect
2Could happen once in 5 yearsA few days' delay, small extra cost
3Could happen in the next 2 yearsWeeks of delay or a noticeable cost increase
4Expected within 12 monthsLost orders, a missed customer commitment or a compliance finding
5Happening now or very soonProduction stops, a data breach or a regulatory breach

Illustrative scale definitions. Adjust the impact column to your own revenue and customers.

If you keep the register in a spreadsheetFormula
Score (L in D2, I in E2)=D2*E2
Rating=IF(F2>=20,"Critical",IF(F2>=10,"High",IF(F2>=5,"Medium","Low")))
Next review date (review date in H2)=IF(F2>=10,EDATE(H2,3),EDATE(H2,12))
Part 3 · Risk management plan

Supply chain risk management plan template

The plan turns every high or critical score into an action with an owner, a due date and a target score. It also sets how often each supplier tier is reviewed.

A register without a plan is a list of worries. For each red score, pick one of four responses: reduce the likelihood, reduce the impact, transfer the risk through a contract or insurance, or accept it with leadership sign-off. Read more on mitigating supply chain risk.

RiskActionOwnerDueTarget score
Northwind freight delay (16)Qualify a second carrier on the main laneLogistics manager30 Nov8
Kestrel data access (15)Require MFA and named admin accounts in the contractIT security lead31 Oct5
Cedar financial distress (12)Hold 6 weeks of packaging stock and start sourcing a backupCategory manager15 Dec6
Orbit tariff exposure (9)Add a price review clause at renewalProcurement lead31 Jan6

Illustrative actions for the sample register.

Supplier tierExampleFull reviewLight check
Tier 1: critical, sole-sourcedPackaging, freight, key data processorsEvery 3-6 monthsMonthly news and credit alerts
Tier 2: important, alternatives existComponents with a second sourceEvery 12 monthsQuarterly
Tier 3: low impactOffice supplies, cateringEvery 12 months or at renewalNone

Review cycle by tier. Also review early after any disruption, ownership change or new country of supply.

Part 4 · Security assessment

Supply chain security risk assessment template

Suppliers with access to your systems, data or software build need a separate security review. These questions cover five areas where a supplier can expose your business to a breach.

The cybersecurity and compliance category in the register only flags that a risk exists. This questionnaire gives the evidence to score it. Frameworks such as NIST SP 800-161 cover the topic in depth if you need a fuller control set.

AreaQuestions to askEvidence
AccessWho at the supplier can reach our systems? Is MFA enforced? How fast is access removed when staff leave?Access policy, user list
DataWhat data of ours do you hold, where is it stored, and is it encrypted at rest and in transit?Data flow diagram, DPA
Software integrityHow are updates signed and tested? Do you track open-source components?Release process, component list
Incident responseHow soon will you tell us about a breach, and who is our contact?Incident plan, contract clause
Sub-tier suppliersWhich of your own suppliers touch our data or product, and how do you assess them?Sub-processor list

Score each area 1-5 for likelihood of a breach, then use the highest as the supplier's cybersecurity likelihood.

For software and data suppliers, this review usually sits inside third-party risk management, run at onboarding and again before each renewal.

Part 5 · Risk policy

Supply chain risk management policy template

The policy makes the assessment mandatory and sets who does it, when and to what standard. Keep it to two pages and have the operations or procurement director own it.

Without a policy, assessments happen after a disruption instead of before one. These seven sections are enough for most mid-sized businesses. Review the policy once a year alongside the risk register.

  1. 01Purpose and scope

    Which suppliers, entities and spend the policy covers.

  2. 02Roles

    Who owns the register, who scores, who approves accepted risks.

  3. 03Supplier tiering

    How criticality tiers are set and who can change them.

  4. 04Assessment triggers

    New critical supplier, renewal, disruption, ownership change or new country of supply.

  5. 05Scoring standard

    The 5x5 matrix and the scale definitions in Part 2.

  6. 06Risk appetite

    Which ratings must be mitigated, and who may accept a high risk.

  7. 07Reporting and review

    How often the register goes to leadership and when the policy is reviewed.

Sample clause: assessment triggers
4. Assessment triggers

4.1 [Company name] will complete a supply chain risk assessment before contracting with any Tier 1 supplier and at least every [6] months while the contract is active.

4.2 An early assessment is required within [30] days of: a disruption affecting supply for more than [5] working days; a change of ownership at the supplier; or a new country of manufacture or data storage.

4.3 Any risk scored 10 or above must have an approved action plan within [20] working days. Only the [Chief Operating Officer] may accept a high risk without mitigation, in writing.

Spendflo's third-party risk management brings supplier risk reviews into onboarding and renewals.

See how it works
Risk categories

The four risk categories, explained

Every risk in the register belongs to one of four categories. Using the same four each time makes suppliers comparable and gaps easy to spot.
Operational and quality

Late deliveries, capacity limits, quality failures and single sites or sole sources.

Financial and credit

Falling credit scores, late payments to their own suppliers, heavy debt or dependence on one customer.

Geopolitical and environmental

Tariffs, sanctions, conflict, extreme weather and flood or fire exposure at key sites.

Cybersecurity and compliance

Access to your data or systems, weak security controls, and labour or environmental compliance gaps.

Best practices

Do this, avoid that

Start with your most critical suppliers, score against agreed scales and act on every red score. Most assessments fail because they are filed and never revisited.

Do

  • ✓
    Tier suppliers first

    Assess sole-sourced and revenue-critical suppliers before anyone else.

  • ✓
    Write risks as events

    A port closure delays freight by two weeks is scorable; logistics risk is not.

  • ✓
    Score with two people

    A buyer and an operations lead scoring together catch each other's blind spots.

  • ✓
    Record the reason

    One line on why each score was given makes the next review faster.

  • ✓
    Re-score after action

    Check the score actually fell once a mitigation is in place.

Avoid

  • ×
    Assessing every supplier equally

    A catering firm does not need the same review as a sole component source.

  • ×
    Only asking the supplier

    Questionnaires show what suppliers claim; add credit checks and delivery data.

  • ×
    Ignoring sub-tier suppliers

    Your supplier's sole source can stop you just as surely as your own.

  • ×
    Accepting risks by default

    An unmitigated high score should need a named person's written approval.

How to use it

Run your first assessment in two weeks

Tier your suppliers, assess the top ten, and agree actions for every high score. Then schedule reviews by tier so the register stays current.
  1. Step 1

    Tier the supplier list

    Export suppliers by spend and mark which are sole-sourced or critical to a product.

  2. Step 2

    Gather evidence

    Send the profile and security questions and run a credit check on each Tier 1 supplier.

  3. Step 3

    Score in a workshop

    Score all risks in one 90-minute session using the agreed 5x5 scales.

  4. Step 4

    Approve the plan

    Take the red scores and their actions to leadership and set review dates.

Example

One supplier, scored and mitigated

Cedar Packaging is the only source of a custom box and its own suppliers report late payments. A stock buffer and a second source cut the score from 12 to 6.

Cedar Packaging supplies every custom box for a homeware brand. A credit alert shows Cedar paying its suppliers late, so the team scores likelihood 3 and impact 4: a score of 12, rated High. The plan adds six weeks of buffer stock and qualifies a second packaging supplier by 15 December. Impact falls to 2 and the new score is 6. All figures are illustrative.

Ready to use it? Download the supply chain risk assessment template

Every part on this page, in Word, Google Docs and PDF, with the examples filled in.

Variants

Fit it to your supply chain

Manufacturers weight operational and geopolitical risk most heavily. Software and services businesses weight cybersecurity and data risk, and regulated firms add compliance evidence to every review.
Physical goods

Manufacturing and retail

Map sites and sole sources for every component, and review freight lanes and tariff exposure each quarter.

Software and data

Technology and services

Most risk sits with SaaS and data suppliers, so lead with the security questionnaire in Part 4.

Regulated sectors

Healthcare and finance

Add evidence columns to the register and keep signed copies of every accepted risk. See the guide to supply chain risk management.

Spendflo: $3.7B in software spend processed, 15,000+ agreements, 30% average savings.

See how it works
Bottom line

Score it, act on it, review it

A supply chain risk assessment is useful only if the high scores turn into actions and the register is revisited on schedule. Start with your ten most critical suppliers and widen the scope once the routine sticks.

FAQ

Frequently asked questions

Quick answers to what people ask most about the supply chain risk assessment template.

What are the 5 things a risk assessment should include?

A supply chain risk assessment should include a supplier profile, risk categories, a likelihood and impact score, a mitigation plan and a review cycle. Those five map to the sections of this template, which you can download in Word, Google Docs or PDF.

Can you provide an Excel spreadsheet template for risk assessment?

The register in this template is a plain table, so you can paste it into Excel or Google Sheets and use the score and rating formulas in Part 2. Download the Word version for the full document and copy the register tab across.

What are the potential risks for supply chains in 2026?

The main ones are trade and tariff changes, cyber attacks that enter through suppliers, extreme weather at key sites, supplier financial distress and over-reliance on single sources. Download the template to score each of these for your own suppliers rather than relying on general lists.

How to do a supplier risk assessment?

Profile the supplier, list specific risks under the four categories, score each by likelihood and impact, and agree actions for any high score. Then set a review date based on the supplier's tier. The download walks through each step with a filled example.

Where can I download a free supply chain risk assessment template?

You can download it from the buttons at the top of this page in Word, Google Docs or PDF. It includes the assessment, scoring matrix, risk management plan, security questionnaire and policy outline.

Template library

Browse all procurement templates

See all 60 templates →

Know which suppliers could stop you, before they do.

Spendflo brings third-party risk reviews, supplier onboarding and contract renewals into one place for software and services suppliers.

Book a demo
  • 5-part risk template
  • 5x5 scoring matrix
  • 4 risk categories
  • 5 security review areas