What it means
A manufacturer buys a critical component from one supplier, and delivery has been reliable, but the vendor has limited spare capacity and depends on a single factory. A risk score can make that dependence visible before an outage.
Start by identifying critical suppliers and the assets they support, because a small spend can still be vital if the item stops a production line, and spend amount alone is not a sound measure of operational importance. CIPS recommends identifying critical assets and suppliers, analysing probability and severity, comparing risk with appetite, taking action and monitoring, and it describes scoring as one tool for ranking priorities, not the whole assessment.
Define factors before looking at individual vendors: financial stress, delivery performance, capacity, cyber exposure, regulatory obligations and concentration may all matter, and the factors and weights should reflect the buyer's actual business. Gather evidence from contracts, performance records, audited statements where available, questionnaires, external notices and direct discussion, and check self-reported answers when the consequence is large.
Separate inherent and residual risk: inherent risk describes exposure before controls, while residual risk reflects safeguards such as backup stock or a second source, so a supplier serving sensitive data may be inherently high risk even when strong controls reduce the current exposure. One simple method rates likelihood and impact from one to five and multiplies them, so a likelihood of four and impact of five gives twenty on a twenty-five-point scale.
The numbers are ordinal judgments, not measured probabilities or expected cash losses. Document what each rating means, because if "high likelihood" means a disruption expected within a year for one team and merely conceivable for another, a group ranking becomes inconsistent, so calibrate with example cases.
Weight dimensions only with care, since a high cyber risk should not vanish because excellent delivery scores lower an average, and minimum controls or escalation thresholds suit risks that cannot sensibly be traded off. NIST SP 800-161 revision 1 addresses cybersecurity supply-chain risk management and integrating it into organisational processes, but its focus is cyber and technology supply chains and it does not replace financial and physical-delivery analysis.
Consider second-tier suppliers, since a vendor may have two factories but obtain a unique material from one source, and ask about dependencies when the product or service is critical while recognising that visibility may be incomplete. Scores should lead to action such as a continuity plan, staged alternative sourcing, a stock buffer, an audit or contract changes, because recording a red cell without an owner does little to reduce exposure.
Review at a sensible cadence and after events, since a missed delivery, ownership change, cyber incident or regulatory action can make the prior score stale, and keep source dates and changes visible. An illustrative assessment coverage rate is critical suppliers with a current documented review divided by all inventoried critical suppliers, so if 45 of 50 have current reviews, coverage is 90%, which says nothing about whether the five missing suppliers are the most important.
Protect sensitive vendor data by limiting access to those who need it rather than copying financial statements, security findings and pricing details into a broadly shared spreadsheet, and avoid unjustified precision, as a supplier with a score of 72 is not necessarily safer than one at 74 when both scores rely on uncertain survey answers. For owners, risk scoring is a queue for attention that should reveal which relationships need deeper assessment and a response, with the goal of fewer avoidable surprises rather than a perfect-looking heat map.
In practice
Real-world examples.
Example
A single-source component receives high impact despite low annual spend. The buyer ranks it above several high-spend suppliers with easy substitutes. A continuity plan is requested within the next review cycle.
Example
A recent factory closure changes a supplier delivery-risk rating. The buyer raises the likelihood score and records the date and source of the news. It then asks the supplier which sites will cover the lost output.
Example
A second-source plan reduces residual risk without erasing inherent dependence. The buyer keeps the inherent score visible and records the new backup arrangement beside it. This shows reviewers why the residual score fell.
Formula
Calculation
Illustrative risk score = likelihood rating x impact rating under a defined one-to-five scheme.
Worked example. Four x five = twenty of twenty-five; ratings are judgments, not probabilities.
To compare two suppliers, score each on the same scale. A single-source packaging supplier rated likelihood 3 and impact 5 scores 3 x 5 = 15. A multi-source stationery supplier rated likelihood 4 and impact 1 scores 4 x 1 = 4. The first supplier is a higher priority for review even though the second is more likely to have a problem, because the consequence is far smaller.Case study
Seen in the real world.
This entirely fictional example follows Oakline Manufacturing, an invented business. Its low-spend packaging adhesive was essential to every shipment, yet never appeared in its top-spend supplier review. A criticality screen elevated the vendor and led to a backup-material test. The score helped prioritise work but did not guarantee continuity.
After the screen, the operations lead asked the adhesive supplier about its raw material sources and found that one resin came from a single plant. The team recorded that dependency, set a review date and agreed a modest safety stock while the backup material was tested. Oakline's finance team kept the effort proportionate by limiting the deeper reviews to suppliers above a defined criticality band. The invented example shows a method, and no cost or saving is claimed.
Watch out
Common mistakes.
- Ranking vendors only by annual spending.
- Averaging away a severe compliance risk with good delivery scores.
- Keeping a stale score after a material ownership or capacity change.
Questions
People also ask.
What is supplier risk scoring?
A defined comparison of vendor exposures to prioritise assessment and action.
Does a low score mean the supplier is safe?
No. Evidence can be incomplete and conditions can change.
What happens after a high score?
Investigate causes, assign controls or alternatives, and monitor the result.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
