A supply chain risk assessment template is a structured document for finding, scoring and planning around the risks your suppliers pose. It profiles each supplier, rates every risk by likelihood and impact, and assigns actions and owners to the highest scores.
It is the working file behind supply chain risk management: a list of the suppliers you depend on, the ways each could let you down, and a score that shows which of those problems deserve attention first.
Procurement and operations teams use one when onboarding a critical supplier, before a sourcing decision, after a disruption, and on a fixed annual cycle. The output is a ranked register that tells leadership where a backup supplier, extra stock or a contract change would reduce exposure most.
Because the same scale is used for every supplier, the assessment also makes risks comparable: a freight delay and a data breach can sit in one list and be ranked against each other.
Supplier ID, contact, what they supply and a criticality tier for each one.
Operational and quality, financial and credit, geopolitical and environmental, and cybersecurity and compliance.
Likelihood from 1 to 5 multiplied by impact from 1 to 5, shaded by severity.
Backup suppliers and other actions, each with an owner and a due date.
A full review every 12 months, and every 3-6 months for high-risk suppliers.
Ready to use in Word, Google Docs and PDF. Fill it in, save it, reuse it.
Pick the suppliers, sites and products to assess, starting with anything sole-sourced or revenue-critical.
Gather supplier questionnaires, financial checks, certificates, locations and delivery history.
Work through the four categories for each supplier and write each risk as a specific event.
Rate likelihood and impact from 1 to 5, multiply them and sort the register by score.
Assign actions to every high score and set the next review date by tier.
The simplest usable version is one table: Supplier, Risk, Likelihood (1-5), Impact (1-5), Score, Action, Owner. Fill it for your ten most critical suppliers first.
Fill the sections in order, because each one feeds the next. The profile sets the criticality tier, the tier decides how deep the review goes, and the register produces the scores the plan acts on.
Which suppliers, products and sites are covered, who led the assessment and the date.
Supplier ID, contact, commodity or service, annual spend, locations and a criticality tier from 1 to 3.
Each risk written as an event, tagged to one of the four risk categories.
Likelihood and impact from 1 to 5, the product of the two and a severity rating.
For every high or critical risk: the action, owner, due date and target score.
Next review date, the triggers for an early review and sign-off by the risk owner.
Five suppliers, one risk each, sorted by score.
| Supplier | Risk event | Category | L | I | Score | Rating |
|---|---|---|---|---|---|---|
| Northwind Logistics | Port congestion delays inbound freight by 2+ weeks | Operational | 4 | 4 | 16 | High |
| Kestrel Data | Shared admin accounts expose customer data | Cybersecurity | 3 | 5 | 15 | High |
| Cedar Packaging | Sole packaging supplier misses payments to its own suppliers | Financial | 3 | 4 | 12 | High |
| Orbit Metals | New tariff raises the landed cost of imported steel | Geopolitical | 3 | 3 | 9 | Medium |
| Acme Office Supply | Single warehouse sits in a flood zone | Environmental | 2 | 2 | 4 | Low |
Illustrative suppliers and scores. L = likelihood, I = impact, Score = L x I.
Agree the scales before anyone scores, or two people will rate the same risk differently. Impact should be judged on the worst realistic outcome for your business, not for the supplier. Write the reason for each score in the register so the next reviewer can test it.
| Likelihood \ Impact | 1 Minimal | 2 Minor | 3 Moderate | 4 Major | 5 Severe |
|---|---|---|---|---|---|
| 5 Almost certain | 5 | 10 | 15 | 20 | 25 |
| 4 Likely | 4 | 8 | 12 | 16 | 20 |
| 3 Possible | 3 | 6 | 9 | 12 | 15 |
| 2 Unlikely | 2 | 4 | 6 | 8 | 10 |
| 1 Rare | 1 | 2 | 3 | 4 | 5 |
Green 1-4 Low, amber 5-9 Medium, red 10-16 High and 20-25 Critical.
| Score | Likelihood means | Impact means |
|---|---|---|
| 1 | Not expected in the next 5 years | Absorbed within a day, no customer effect |
| 2 | Could happen once in 5 years | A few days' delay, small extra cost |
| 3 | Could happen in the next 2 years | Weeks of delay or a noticeable cost increase |
| 4 | Expected within 12 months | Lost orders, a missed customer commitment or a compliance finding |
| 5 | Happening now or very soon | Production stops, a data breach or a regulatory breach |
Illustrative scale definitions. Adjust the impact column to your own revenue and customers.
| If you keep the register in a spreadsheet | Formula |
|---|---|
| Score (L in D2, I in E2) | =D2*E2 |
| Rating | =IF(F2>=20, |
| Next review date (review date in H2) | =IF(F2>=10, |
A register without a plan is a list of worries. For each red score, pick one of four responses: reduce the likelihood, reduce the impact, transfer the risk through a contract or insurance, or accept it with leadership sign-off. Read more on mitigating supply chain risk.
| Risk | Action | Owner | Due | Target score |
|---|---|---|---|---|
| Northwind freight delay (16) | Qualify a second carrier on the main lane | Logistics manager | 30 Nov | 8 |
| Kestrel data access (15) | Require MFA and named admin accounts in the contract | IT security lead | 31 Oct | 5 |
| Cedar financial distress (12) | Hold 6 weeks of packaging stock and start sourcing a backup | Category manager | 15 Dec | 6 |
| Orbit tariff exposure (9) | Add a price review clause at renewal | Procurement lead | 31 Jan | 6 |
Illustrative actions for the sample register.
| Supplier tier | Example | Full review | Light check |
|---|---|---|---|
| Tier 1: critical, sole-sourced | Packaging, freight, key data processors | Every 3-6 months | Monthly news and credit alerts |
| Tier 2: important, alternatives exist | Components with a second source | Every 12 months | Quarterly |
| Tier 3: low impact | Office supplies, catering | Every 12 months or at renewal | None |
Review cycle by tier. Also review early after any disruption, ownership change or new country of supply.
The cybersecurity and compliance category in the register only flags that a risk exists. This questionnaire gives the evidence to score it. Frameworks such as NIST SP 800-161 cover the topic in depth if you need a fuller control set.
| Area | Questions to ask | Evidence |
|---|---|---|
| Access | Who at the supplier can reach our systems? Is MFA enforced? How fast is access removed when staff leave? | Access policy, user list |
| Data | What data of ours do you hold, where is it stored, and is it encrypted at rest and in transit? | Data flow diagram, DPA |
| Software integrity | How are updates signed and tested? Do you track open-source components? | Release process, component list |
| Incident response | How soon will you tell us about a breach, and who is our contact? | Incident plan, contract clause |
| Sub-tier suppliers | Which of your own suppliers touch our data or product, and how do you assess them? | Sub-processor list |
Score each area 1-5 for likelihood of a breach, then use the highest as the supplier's cybersecurity likelihood.
For software and data suppliers, this review usually sits inside third-party risk management, run at onboarding and again before each renewal.
Without a policy, assessments happen after a disruption instead of before one. These seven sections are enough for most mid-sized businesses. Review the policy once a year alongside the risk register.
Which suppliers, entities and spend the policy covers.
Who owns the register, who scores, who approves accepted risks.
How criticality tiers are set and who can change them.
New critical supplier, renewal, disruption, ownership change or new country of supply.
The 5x5 matrix and the scale definitions in Part 2.
Which ratings must be mitigated, and who may accept a high risk.
How often the register goes to leadership and when the policy is reviewed.
4. Assessment triggers 4.1 [Company name] will complete a supply chain risk assessment before contracting with any Tier 1 supplier and at least every [6] months while the contract is active. 4.2 An early assessment is required within [30] days of: a disruption affecting supply for more than [5] working days; a change of ownership at the supplier; or a new country of manufacture or data storage. 4.3 Any risk scored 10 or above must have an approved action plan within [20] working days. Only the [Chief Operating Officer] may accept a high risk without mitigation, in writing.
Spendflo's third-party risk management brings supplier risk reviews into onboarding and renewals.
See how it worksLate deliveries, capacity limits, quality failures and single sites or sole sources.
Falling credit scores, late payments to their own suppliers, heavy debt or dependence on one customer.
Tariffs, sanctions, conflict, extreme weather and flood or fire exposure at key sites.
Access to your data or systems, weak security controls, and labour or environmental compliance gaps.
Assess sole-sourced and revenue-critical suppliers before anyone else.
A port closure delays freight by two weeks is scorable; logistics risk is not.
A buyer and an operations lead scoring together catch each other's blind spots.
One line on why each score was given makes the next review faster.
Check the score actually fell once a mitigation is in place.
A catering firm does not need the same review as a sole component source.
Questionnaires show what suppliers claim; add credit checks and delivery data.
Your supplier's sole source can stop you just as surely as your own.
An unmitigated high score should need a named person's written approval.
Export suppliers by spend and mark which are sole-sourced or critical to a product.
Send the profile and security questions and run a credit check on each Tier 1 supplier.
Score all risks in one 90-minute session using the agreed 5x5 scales.
Take the red scores and their actions to leadership and set review dates.
Cedar Packaging supplies every custom box for a homeware brand. A credit alert shows Cedar paying its suppliers late, so the team scores likelihood 3 and impact 4: a score of 12, rated High. The plan adds six weeks of buffer stock and qualifies a second packaging supplier by 15 December. Impact falls to 2 and the new score is 6. All figures are illustrative.
Every part on this page, in Word, Google Docs and PDF, with the examples filled in.
Map sites and sole sources for every component, and review freight lanes and tariff exposure each quarter.
Most risk sits with SaaS and data suppliers, so lead with the security questionnaire in Part 4.
Add evidence columns to the register and keep signed copies of every accepted risk. See the guide to supply chain risk management.
Best for formal assessments that need signatures.
Best when several teams fill in their own suppliers.
The 5x5 grid and scales on one page.
Spendflo: $3.7B in software spend processed, 15,000+ agreements, 30% average savings.
See how it worksA supply chain risk assessment is useful only if the high scores turn into actions and the register is revisited on schedule. Start with your ten most critical suppliers and widen the scope once the routine sticks.
Quick answers to what people ask most about the supply chain risk assessment template.
A supply chain risk assessment should include a supplier profile, risk categories, a likelihood and impact score, a mitigation plan and a review cycle. Those five map to the sections of this template, which you can download in Word, Google Docs or PDF.
The register in this template is a plain table, so you can paste it into Excel or Google Sheets and use the score and rating formulas in Part 2. Download the Word version for the full document and copy the register tab across.
The main ones are trade and tariff changes, cyber attacks that enter through suppliers, extreme weather at key sites, supplier financial distress and over-reliance on single sources. Download the template to score each of these for your own suppliers rather than relying on general lists.
Profile the supplier, list specific risks under the four categories, score each by likelihood and impact, and agree actions for any high score. Then set a review date based on the supplier's tier. The download walks through each step with a filled example.
You can download it from the buttons at the top of this page in Word, Google Docs or PDF. It includes the assessment, scoring matrix, risk management plan, security questionnaire and policy outline.
Purchase orders
Contracts
Vendor management
Sourcing and RFx
Budgets and business cases
Procurement
Accounts payable
Purchasing
Software buying
Spendflo brings third-party risk reviews, supplier onboarding and contract renewals into one place for software and services suppliers.
Enter your work email and we'll unlock every format.
Didn't start, or need another format? Pick one below.
Google Docs: upload the file to Google Drive, then open it with Google Docs.