Common questions
What is supplier risk management?
Supplier risk management is the continuous process of establishing how much exposure each supplier represents, treating what is unacceptable, and keeping that judgement current as the relationship changes. It runs as seven stages from intake through to exit, each with an entry condition and a named owner.
What are the stages of the supplier risk management process?
Intake, screening and tiering, assessment, treatment, contracting, monitoring, and exit. Each has an entry condition that must be met before a supplier moves into it, which is what makes it possible to see where a supplier is stuck.
Where does supplier risk management usually break down?
At three handoffs: assessment to treatment, where findings are noted but never become owned rows; treatment to contracting, where contractual leverage is spent before the requirements are known; and contracting to monitoring, where effort collapses after signature even though most supplier failures occur afterwards.
Should suppliers be tiered by spend?
No — by consequence. Spend correlates weakly with exposure: a small monitoring tool holding credentials into production carries more risk than a large facilities contract. Tier on whether the supplier processes personal data, holds system access, or supports a service you could not sustain without them.
Does supplier risk management software actually help?
With the handoffs, expiry tracking, reconciliation between systems and portfolio-level concentration views, yes. It does not supply tiering criteria, the organisational willingness to reject a supplier, or assessment quality — and automating a process with those problems produces a faster version of the same result.
How do you measure supplier risk management?
By register staleness, findings without owners, expired evidence still being relied on, time from request to tier, and tier 1 concentration against shared fourth parties — not by assessments completed, which measures activity rather than exposure.