Supplier risk assessment
Score a supplier across quality, delivery, technical capability, commercial position and business continuity. The weighting is applied for you, the strategic flags are added on top, and you get a band, an action and a review date you can put in front of a supplier approval meeting.
One supplier per record.
Rate each line honestly — 1 is nil risk, 5 is very high. Anything you rate a 4 or a 5 needs a short written reason before the record will print. That is the line an auditor will ask about.
Your details and logo — all optional
This is the organisation doing the assessing. Fill in what you want printed at the top of the record, or leave it blank. Signed-in users have this filled from their company details in account settings.
The supplier
Supply chain transparency
Quality risk — 30% weighted
Rate each line 1 (nil risk) to 5 (very high risk). A 4 or 5 needs a short written reason.
Quality systems and certifications (ISO, etc.)
1: Current third-party certification, audited annually · 5: No documented quality system or certification
NCR / defect history
1: No non-conformances on record · 5: Frequent or unresolved non-conformances
Traceability and documentation
1: Full batch/heat traceability with certificates · 5: No traceability or documentation provided
Process control maturity
1: Documented, monitored and capable processes · 5: Ad hoc processes, no control plans
Inspection capability
1: Calibrated equipment and trained inspectors · 5: No in-house inspection capability
Delivery capacity — 25% weighted
Rate each line 1 (nil risk) to 5 (very high risk). A 4 or 5 needs a short written reason.
OTIF performance reliability
1: Consistently on time and in full · 5: Regularly late or short-shipped
Production / supply capacity adequacy
1: Ample headroom for our volumes · 5: Capacity constrained or unknown
Lead time reliability
1: Stable, predictable lead times · 5: Volatile or frequently extended lead times
Supply stability
1: Stable long-term supply arrangements · 5: Frequent interruptions or allocation risk
Dependency on subcontractors
1: Little or no subcontracting · 5: Heavy reliance on uncontrolled subcontractors
Technical capability — 20% weighted
Rate each line 1 (nil risk) to 5 (very high risk). A 4 or 5 needs a short written reason.
Manufacturing / process capability
1: Proven capability for our product range · 5: Capability unproven or unsuitable
Engineering support availability
1: Responsive in-house engineering support · 5: No engineering support available
Equipment suitability
1: Modern, well-maintained, fit for purpose · 5: Unsuitable or poorly maintained equipment
Workforce competency
1: Trained, stable, competency records held · 5: Untrained or high-turnover workforce
Ability to consistently meet specification
1: Consistently meets specification first time · 5: Frequently deviates from specification
Commercial and financial — 15% weighted
Rate each line 1 (nil risk) to 5 (very high risk). A 4 or 5 needs a short written reason.
Financial stability
1: Strong, verified financial position · 5: Distressed or unverifiable financials
Trading history
1: Long, well-documented trading history · 5: New entity or no trading history
Credit risk perception
1: No credit concerns identified · 5: Known payment or credit issues
Customer concentration risk
1: Broad, diversified customer base · 5: Dependent on one or two customers
Financial resilience
1: Able to absorb shocks and fund growth · 5: No buffer against a downturn
Business continuity — 10% weighted
Rate each line 1 (nil risk) to 5 (very high risk). A 4 or 5 needs a short written reason.
Single site dependency
1: Multiple qualified sites · 5: Single site, no alternative
Disaster recovery readiness
1: Tested documented recovery plan · 5: No recovery planning
Key person dependency
1: Depth of capability across the team · 5: Business depends on one individual
Supply disruption resilience
1: Buffer stock and alternate inputs · 5: No buffer, single-source inputs
Strategic and audit flags
These add points on top of the weighted score, to a possible 24. The audit flags are set from your answers above — you can override any of them.
Strategic flags
Audit flags (auto-set)
Assessor notes and observations
Common questions
How is the score worked out?
Every line is rated 1 (nil risk) to 5 (very high risk). Each domain is converted to a percentage of its own maximum, then weighted — quality 30%, delivery 25%, technical 20%, commercial 15%, continuity 10%. Strategic and audit flags add points on top, capped at 100.
Why do high ratings need a written reason?
A 4 or a 5 is the line an auditor will ask about. Recording why at the time is the difference between a defensible supplier evaluation and a page of numbers nobody can explain six months later.
Why can a low-scoring supplier still come out as High?
If the supplier is a sole source, or feeds a critical structural or product component, the band cannot print below High. A well-behaved sole supplier of a critical part is still a business exposure.
Is anything stored with F4PS?
No. The assessment runs in your browser and prints on your own copy. If you create a free account you can save it to your workspace and share it with your team, but the record is yours.
More free tools on the tools page, and the background reading sits in the guides.
Want supplier evaluation built into your quality system?
admin@f4ps.com.au