Supplier risk assessment flowchart (decision tree)
Supplier risk assessment flowchart: a decision tree of data, access, spend, dependency and certification tests that set the tier and depth of due diligence.
How it works
Open the template and rename the decision-rights lanes
Replace Business owner, Security and compliance, Procurement and finance, and Third-party risk committee with the roles that actually answer these questions in your organisation. Keep the lanes to the people with decision rights rather than mapping every department, or the tree turns back into a process map.
Write your material spend threshold onto the node
Pick one figure in your own currency, agree it with finance, and put it in the note on "Spend above the material threshold?". Apply it to committed annual spend rather than the first order, and state what happens when an existing supplier crosses it mid-term.
Define what makes a country or sector high risk
Name the sources you use rather than leaving it to judgement — corruption and sanctions indices, your own restricted-country list, sectors under specific regulation. Do the same for the sanctions and adverse media check, naming the lists screened and who runs the search.
State which certifications are accepted, and their limits
List the evidence that lets a supplier take the Certified branch: a valid ISO 27001 certificate whose scope covers the service you are buying, a recent SOC 2 Type II report, an accredited sector certification. Say explicitly that an expired certificate or one scoped to a different entity does not count.
Fill in what each tier actually requires
The four approval endpoints are only useful if the packs behind them exist. Write down what the short questionnaire asks, what the standard due diligence pack contains, what enhanced review and audit means in practice, and what an acceptable continuity and exit plan looks like for a critical supplier.
Set reassessment triggers, then circulate for sign-off
Attach a review interval to each tier and add event triggers that pull a supplier back through the tree: a change of ownership, a breach notification, a new data flow, a move above the spend threshold. Share the chart with security, procurement and finance, capture their approval, and keep it under version control so the diagram and the written policy do not drift apart.
Frequently asked questions
What is the difference between a supplier risk assessment and a vendor onboarding process?
They answer different questions. Onboarding is a process map: it shows what happens next and who does it, from the initial request through legal and finance review, contract signature, bank detail verification and the entry on the approved vendor register. A supplier risk assessment is a decision tree: it shows which option you choose and who is entitled to choose it, taking the facts about a supplier and returning a tier plus the depth of due diligence that tier requires. In most organisations the assessment is one node inside the onboarding flow. Documenting them separately keeps the onboarding chart readable and forces the tiering criteria to be written down instead of hidden in a box labelled "assess risk".
What criteria should a supplier risk assessment use?
Six tests cover most cases and are the ones in this tree: whether the supplier processes personal or regulated data, whether they receive access to systems, premises or intellectual property, annual spend against a material threshold, whether they are single-source or hard to replace, whether the country or sector carries elevated risk, and whether they hold current, in-scope certifications. Keep the list short enough that an assessor can answer it from the intake record, and write each threshold next to its question. Criteria that live in a separate policy document get approximated from memory, which is exactly how two assessors reach different tiers from the same facts.
How many supplier risk tiers should we have?
Three tiers plus a separate critical designation works for most organisations, which is the structure here: low, medium, high, and critical for suppliers you cannot readily replace. More tiers produce arguments about placement rather than better decisions. Critical is worth keeping distinct from high because it is driven by dependency rather than exposure — a low-data, low-spend supplier with no qualified alternative needs a continuity and exit plan, not a longer security questionnaire. The tier should drive two things: the evidence required before approval, and how often the supplier is reassessed afterwards.
Can a certification replace enhanced due diligence?
Partly, and only if you check it properly. A valid ISO 27001 certificate or a recent SOC 2 Type II report is independent evidence that a control environment was assessed, and in this tree the Certified branch drops a supplier from enhanced review to the standard pack. Three checks decide whether it counts: the scope statement has to cover the service you are actually buying, the certification body has to be accredited, and the date has to be current. A SOC 2 Type II report also has an audit window and a set of exceptions in it, so read the exceptions rather than the cover page. Certification never substitutes for a data processing agreement where personal data is involved.
Who should own the supplier risk assessment decision?
Split it by question rather than giving one team the whole assessment. Security and compliance are best placed to answer the data, access, country and certification questions because they hold the evidence. Procurement and finance answer spend and replaceability. The tier that results should be a calculation from those answers, not a negotiation. Reserve the risk committee for the two places where judgement genuinely sits: accepting a supplier at high risk after enhanced review, and signing off the continuity plan that makes a critical supplier acceptable. The person who ran the review should not be the person who accepts the residual risk.