# Supplier Risk Assessment: Checklist and Practical Example

*Source: https://eximagent.ai/blog/supplier-risk-assessment-trading-relationships · Published: October 8, 2026 · Category: Global Trade*

> Use a practical supplier risk assessment checklist to verify evidence, identify gaps and decide the next sourcing step.

A supplier risk assessment helps you decide whether a supplier can meet your requirements, what could interrupt supply and which evidence you still need. Start with identity, product quality, delivery, financial exposure and continuity. Record each finding, its source and the action required before approving an order.

For an importer or a small procurement team, the useful outcome is a sourcing decision: proceed, proceed with conditions, pause for evidence or choose an alternative. This guide gives you a checklist, a repeatable process and a fictional example you can adapt to your next supplier review.

## What is a supplier risk assessment?

It is a structured review of the ways a supplier relationship could affect your business. A low quote is one input; so are delivery reliability, replacement difficulty, product requirements, payment exposure and evidence about the business you are dealing with.

Supplier evaluation asks whether a supplier fits your requirements. Risk assessment asks what could go wrong, how serious the impact would be and what you will do about it. The two belong in the same sourcing conversation, but a supplier can perform well today and still create a dependency that deserves a contingency plan.

Keep the review proportionate. A replaceable office-supply vendor needs a different level of scrutiny from the sole producer of a component that stops your production line. The [EcoVadis supplier risk assessment guide](https://ecovadis.com/blog/supplier-risk-assessment/) provides broader context on operational, financial and sustainability categories. Use your own product, market and exposure to decide which categories require specialist review.

## Supplier risk assessment checklist: what to verify

Use this checklist as a starting point, not a universal certification. For each row, record the evidence date, reviewer and unresolved questions. “No information” means unverified; it does not mean low risk.

![Supplier review worksheet with identity evidence, delivery checks and an alternative supply option](https://assets.eximagent.ai/media/supplier-risk-feature.avif)

| Area | Question to answer | Evidence to collect | Action if unresolved |
| --- | --- | --- | --- |
| Business identity | Who contracts, manufactures, invoices and receives payment? | Registration record, legal name, address, website and explanation of trading names or intermediaries | Resolve mismatches before placing the order |
| Product quality and capacity | Can the supplier make the required specification at the agreed volume? | Approved samples, inspection results, relevant test reports and capacity discussion | Arrange testing or a pilot order with agreed acceptance criteria |
| Delivery performance | Can the supplier meet the required schedule, and how are exceptions handled? | Your purchase-order history, promised versus actual dates and verified references | Confirm a recovery plan and realistic lead time |
| Financial and payment exposure | How much money and inventory would be exposed if performance failed? | Payment terms, maximum advance exposure and financial evidence appropriate to the relationship | Seek finance review and negotiate suitable protections |
| Concentration and continuity | What would happen if this supplier, plant or upstream source became unavailable? | Spend or volume dependency, replacement lead time, backup capacity and continuity plan | Qualify alternatives and assign a contingency owner |
| Compliance and responsible sourcing | Which product, destination, party and sourcing requirements apply? | Relevant certificates, traceability documents and review by the responsible specialists | Pause the affected decision until required checks are complete |
| Data and system access | Will the supplier access sensitive data or business systems? | Access scope, security evidence, contractual controls and internal security review | Restrict access until requirements are met |

For a deeper identity check, use the [business identity checks for trade partners](https://eximagent.ai/blog/business-identity-checks-export-trade-partners) guide. Keep the entity you verify consistent with the entity used in your contract and payment process.

## How to assess supplier risk in five steps

### 1. Define the purchase and its business impact

Record the product, specification, expected volume, delivery window and internal owner. Ask how long your business could operate without this supply. Identify whether another qualified supplier could substitute immediately or would need tooling, testing or customer approval.

This establishes the depth of review. A supplier's size alone does not determine your exposure: a small source of a hard-to-replace part can be more critical than a large source of a standard item.

### 2. Gather evidence and separate statements from facts

Use supplier documents, independent records and your own transaction history. Note who provided each item, what period it covers and whether it applies to the correct entity, product and site.

A supplier's statement that it has “many international customers” is a claim to check. A shipment record is an observation within a dataset. Neither proves current production capacity, cash flow or compliance with your particular requirements.

### 3. Prioritize risks without hiding unknowns in a score

For each risk, describe the potential impact, the evidence that makes it plausible and the effectiveness of existing controls. Keep an evidence-confidence field separate from the risk rating.

A practical review can use low, medium, high and unverified labels, with definitions agreed by your team. Do not average an unresolved identity or mandatory product check into a reassuring overall score. If you use numerical scoring, document the weights and escalation rules; the worksheet here is not a validated scoring model.

### 4. Decide the action and who owns it

Choose a supported decision: proceed, proceed with conditions, hold pending evidence or seek an alternative. Make each condition measurable, give it an owner and record a due date. “Monitor supplier” is less useful than “procurement confirms backup capacity before approving the production order.”

### 5. Set review dates and change triggers

Review critical relationships at an interval appropriate to your business. Also reopen the assessment after material changes such as a new factory, revised bank details, repeated late deliveries, a change of ownership or a different product specification.

A previous approval covers the evidence and scope assessed at that time. It does not automatically cover a new entity, plant or supply arrangement.

## What trading relationships can tell you—and what they cannot

Company and trade records help you frame better questions. Review entity matches, recorded products, counterparties, shipment dates and the direction of observed activity. These can highlight an apparent dependency or a change worth discussing with the supplier.

EximAgent's [company intelligence for trade partners](https://eximagent.ai/docs/guides/company-intelligence) guide documents entity resolution, trade profiles, trajectories, relationship mapping and shipment evidence. These are research inputs; they are not a complete supplier approval or financial-risk assessment.

- **Observed concentration:** one counterparty may dominate the records you can see. Ask whether that reflects the business or the dataset's coverage.
- **Activity changes:** fewer recorded shipments may reflect seasonality, routing changes, reporting delay or incomplete coverage. Investigate before interpreting the change as distress.
- **Continuity:** previous shipments demonstrate recorded activity, not a guarantee that the next order will arrive on time.

For your own dependency, calculate supplier share from your purchasing records using a consistent basis: units, spend or a specific product's requirements over a defined period. Do not mix those denominators. Customs shipment counts are not automatically equivalent to revenue, capacity or your spend share.

The [company data provider evaluation checklist](https://eximagent.ai/blog/company-intelligence-report-checklist) helps you assess source quality, identity matches and coverage before using a company profile in the review.

## Practical example: assessing a packaging supplier

**Fictional example:** Harbor Imports is considering Meridian Packaging for printed cartons. All names, figures and findings below are invented to illustrate the process, not an EximAgent customer result.

Meridian would supply 70% of Harbor's planned carton units next quarter. An alternative would need six weeks for artwork approval and testing. Harbor's purchase plan establishes the dependency; a trade profile alone would not establish either figure.

| Finding | Evidence/status | Decision or next action |
| --- | --- | --- |
| Trading name differs from contract name | Entity match unresolved | Hold contract approval until identity is verified |
| Sample matches the agreed specification | Approved sample; production consistency unverified | Agree inspection and acceptance criteria for the initial order |
| 70% planned unit dependency | Internal purchasing plan; high interruption impact | Qualify a backup and confirm recovery capacity |
| Supplier promises four-week delivery | Statement only; no order history | Confirm a pilot schedule and references before relying on it |
| Financial and required compliance checks incomplete | Unverified | Obtain evidence and specialist review before approval |

The result is a conditional assessment, not a “safe supplier” badge. Harbor first resolves identity and required checks. It can then decide whether a limited initial order, inspection and a backup plan sufficiently reduce its exposure.

## Copy this supplier review worksheet

Create one row for each finding. Reuse this structure in a spreadsheet or your procurement system:

| Field | What to enter |
| --- | --- |
| Supplier and scope | Legal entity, site, product, order or review period |
| Risk and impact | What could fail and the consequence for your business |
| Evidence | Source link/document, date, observed fact and coverage limits |
| Status and confidence | Risk priority plus verified, partial or unverified evidence |
| Control and action | Existing protection, remaining gap and next step |
| Accountability | Owner, due date, approver and next review trigger |

## Frequently asked questions

### When should you assess a supplier?

Before committing to a new relationship, when a material change occurs and during periodic reviews of critical suppliers. The review depth should reflect the purchase and potential interruption.

### What if the supplier will not provide information?

Record the gap and its consequence. Seek an alternative source of evidence where appropriate. If the missing information is necessary for your approval, pause that decision rather than treating the absence as a pass.

### Can shipment records prove a supplier is reliable?

No. They can support observations about recorded trade activity and counterparties. Delivery performance for your orders, production quality, financial capacity and applicable compliance require additional evidence.

### Is a checklist enough to approve a supplier?

A checklist organizes the review. Approval depends on the findings, the controls, your organization's requirements and the people authorized to make the decision.

## Research the supplier before the next sourcing decision

Start by confirming the entity and reviewing available trade activity and relationships. Use the [EximAgent Company Intelligence workflow](https://eximagent.ai/docs/guides/company-intelligence) to organize those research inputs, then use the worksheet above to document missing evidence, actions and ownership before approving the next step.
