Supplier risk assessment flowchart (decision tree)

Supplier risk assessment flowchart: a decision tree of data, access, spend, dependency and certification tests that set the tier and depth of due diligence.

Use this template

What the supplier risk assessment flowchart (decision tree) process is

Most third-party risk documents describe a sequence: request, review, contract, register entry. This one describes a judgement. The chart below is a decision tree, not a cross-functional process map. It answers a single question (given what we know about this supplier, which tier are they, how much due diligence do they get, and who is entitled to say so) and every path through it ends in a named outcome rather than returning to a common happy path.

That distinction matters because the two artefacts fail differently. A process map fails when a hand-off is undocumented and the file sits with nobody. A decision tree fails when the tests are unwritten, so the same supplier is tiered high by one assessor and low by another, and the register becomes a record of who ran the assessment rather than what the supplier is. If you need the end-to-end flow instead (the request form, the legal and finance reviews, contract signature, bank detail verification and the approved vendor register) use the vendor onboarding process template, which covers the same territory as a swimlane process. The vendor approval process template covers the related question of what a supplier is approved to supply.

The tree has nine decisions across four decision-rights lanes. Security and compliance answer the data, access, country and evidence questions; procurement and finance answer dependency and spend; the third-party risk committee holds the final gate and the critical-supplier outcome. Five endpoints come out of it: approve at low risk on a short questionnaire, approve at medium risk after the standard due diligence pack, approve at high risk after enhanced review and audit, approve as a critical supplier with an agreed continuity and exit plan, or decline. Criteria notes sit on the four pivotal tests, because a decision tree with undocumented thresholds is just an opinion with arrows.

What this flowchart covers

In this template

  • Four decision-rights lanes (Business owner, Security and compliance, Procurement and finance, Third-party risk committee) across five stages: Intake, Data and access, Spend and dependency, Country and evidence, and Tier and outcome.
  • The opening split at "Processes personal or regulated data?": Yes goes to "Data processing terms accepted?", where Refused terminates at "Decline the supplier"; No goes to "Access to systems, premises or IP?", which asks whether the supplier reaches your systems, sites or intellectual property even when no data moves.
  • The low-exposure arm, answered by procurement and finance: "Single source or hard to replace?" sends Yes to a continuity and exit plan and the critical-supplier outcome, while No goes to "Spend above the material threshold?", where Above threshold runs the standard due diligence pack and Below threshold gets only the short supplier questionnaire.
  • The sensitive arm, answered by security and compliance: "Country or sector high risk?" routes High risk to "Sanctions or adverse media hits?" (Hits found declines, Clear goes to enhanced review) while Standard routes to "Current certifications in place?", where Certified drops to the standard pack and None escalates to enhanced review and audit.
  • A final gate, "Enhanced review cleared?", that sends Cleared to approval at high risk with controls and Not cleared to the same decline endpoint, so enhanced review is a real test rather than a formality.
  • Five distinct endpoints (approve at low risk, approve at medium risk, approve at high risk, approve as a critical supplier, decline the supplier) plus criteria notes on the data, dependency, spend and certification tests.

When to use this template

  • Two people tier the same supplier differently, and you need the tests written down rather than argued each time.
  • You are setting the depth of due diligence by exposure rather than sending every supplier the same forty-page questionnaire.
  • A customer security questionnaire, ISO 27001 or SOC 2 readiness exercise has asked how you classify third parties and what each tier triggers.
  • You need to agree decision rights: which questions security answers, which procurement and finance answer, and where the risk committee has to be involved.
  • You already have a vendor onboarding or approval process and the risk tiering step inside it is a single unexplained box.

How it works

  1. Open the template and rename the decision-rights lanes

    Replace Business owner, Security and compliance, Procurement and finance, and Third-party risk committee with the roles that actually answer these questions in your organisation. Keep the lanes to the people with decision rights rather than mapping every department, or the tree turns back into a process map.

  2. Write your material spend threshold onto the node

    Pick one figure in your own currency, agree it with finance, and put it in the note on "Spend above the material threshold?". Apply it to committed annual spend rather than the first order, and state what happens when an existing supplier crosses it mid-term.

  3. Define what makes a country or sector high risk

    Name the sources you use rather than leaving it to judgement — corruption and sanctions indices, your own restricted-country list, sectors under specific regulation. Do the same for the sanctions and adverse media check, naming the lists screened and who runs the search.

  4. State which certifications are accepted, and their limits

    List the evidence that lets a supplier take the Certified branch: a valid ISO 27001 certificate whose scope covers the service you are buying, a recent SOC 2 Type II report, an accredited sector certification. Say explicitly that an expired certificate or one scoped to a different entity does not count.

  5. Fill in what each tier actually requires

    The four approval endpoints are only useful if the packs behind them exist. Write down what the short questionnaire asks, what the standard due diligence pack contains, what enhanced review and audit means in practice, and what an acceptable continuity and exit plan looks like for a critical supplier.

  6. Set reassessment triggers, then circulate for sign-off

    Attach a review interval to each tier and add event triggers that pull a supplier back through the tree: a change of ownership, a breach notification, a new data flow, a move above the spend threshold. Share the chart with security, procurement and finance, capture their approval, and keep it under version control so the diagram and the written policy do not drift apart.

Frequently asked questions

What is the difference between a supplier risk assessment and a vendor onboarding process?

They answer different questions. Onboarding is a process map: it shows what happens next and who does it, from the initial request through legal and finance review, contract signature, bank detail verification and the entry on the approved vendor register. A supplier risk assessment is a decision tree: it shows which option you choose and who is entitled to choose it, taking the facts about a supplier and returning a tier plus the depth of due diligence that tier requires. In most organisations the assessment is one node inside the onboarding flow. Documenting them separately keeps the onboarding chart readable and forces the tiering criteria to be written down instead of hidden in a box labelled "assess risk".

What criteria should a supplier risk assessment use?

Six tests cover most cases and are the ones in this tree: whether the supplier processes personal or regulated data, whether they receive access to systems, premises or intellectual property, annual spend against a material threshold, whether they are single-source or hard to replace, whether the country or sector carries elevated risk, and whether they hold current, in-scope certifications. Keep the list short enough that an assessor can answer it from the intake record, and write each threshold next to its question. Criteria that live in a separate policy document get approximated from memory, which is exactly how two assessors reach different tiers from the same facts.

How many supplier risk tiers should we have?

Three tiers plus a separate critical designation works for most organisations, which is the structure here: low, medium, high, and critical for suppliers you cannot readily replace. More tiers produce arguments about placement rather than better decisions. Critical is worth keeping distinct from high because it is driven by dependency rather than exposure — a low-data, low-spend supplier with no qualified alternative needs a continuity and exit plan, not a longer security questionnaire. The tier should drive two things: the evidence required before approval, and how often the supplier is reassessed afterwards.

Can a certification replace enhanced due diligence?

Partly, and only if you check it properly. A valid ISO 27001 certificate or a recent SOC 2 Type II report is independent evidence that a control environment was assessed, and in this tree the Certified branch drops a supplier from enhanced review to the standard pack. Three checks decide whether it counts: the scope statement has to cover the service you are actually buying, the certification body has to be accredited, and the date has to be current. A SOC 2 Type II report also has an audit window and a set of exceptions in it, so read the exceptions rather than the cover page. Certification never substitutes for a data processing agreement where personal data is involved.

Who should own the supplier risk assessment decision?

Split it by question rather than giving one team the whole assessment. Security and compliance are best placed to answer the data, access, country and certification questions because they hold the evidence. Procurement and finance answer spend and replaceability. The tier that results should be a calculation from those answers, not a negotiation. Reserve the risk committee for the two places where judgement genuinely sits: accepting a supplier at high risk after enhanced review, and signing off the continuity plan that makes a critical supplier acceptable. The person who ran the review should not be the person who accepts the residual risk.

Use this template

More in Procurement and supplier process templates

More in Process flowchart templates

Browse all Procurement and supplier process templates