How Should We Prioritise Supplier Assessments?

How to prioritise supplier assessments using business criticality, risk and operational impact - not every supplier requires the same level of review.
Risk Ledger
|
Company
August 3, 2026
11
mins read
How Should We Prioritise Supplier Assessments?

What prioritising an assessment actually means

Prioritising a supplier assessment means matching how much scrutiny a supplier gets, and how often, to how much risk they actually carry.

That may sound obvious, but it's a different call from working out which suppliers are risky in the first place. A supplier can come out of a proper risk assessment correctly flagged as high risk, and still sit on exactly the same annual check as a supplier that barely registers. Nobody decided that on purpose. It's just what happens when the risk assessment gets treated as the finish line rather than the input to a second decision.

The highest risk suppliers get looked at more often, because it matters more that your current view of them is still accurate. A supplier that came out of its first review as low risk, with nothing pointing to it changing, can go a full year without another look, or longer. Not because it's been forgotten, but because there's genuinely nothing pulling it forward.

The mistake isn't reviewing low risk suppliers infrequently. It's applying that same infrequent rhythm to everyone, including the suppliers where a stale view is the whole problem.

That's the part worth sitting with before anything else - risk should set the clock but for a lot of programmes, a fixed calendar sets it instead.

Why one calendar for every supplier breaks down

A periodic checkpoint has real value. Having a person sit down and ask whether a supplier's risk level still looks the way it did last time is a genuinely useful piece of judgement, and it shouldn't go away.

Where it goes wrong is treating that checkpoint as something that happens on the same interval for everyone, regardless of what came out of the risk assessment. 

A supplier that's already been through review and come out low risk, with nothing about the relationship suggesting that's about to change, can reasonably go a year without another look, or longer. A supplier sitting in the highest risk band needs a shorter interval than that, because it matters more that the view you hold of them is still current.

Reviews don't have to be triggered by a date. A change in the supplier relationship, technology or threat landscape may justify bringing the review forward.
Emily Hodges Emily Hodges COO, Risk Ledger

Reviews also don't have to be tied to a date at all. A contract change, a shift in what a supplier actually does for you, a new use of AI somewhere in their service, are all reasons to bring a review forward regardless of where that supplier sits in the schedule. None of those show up on a calendar, they show up when something changes - and the only way to catch them is to have a process that's actually watching for the change rather than waiting for the next fixed date to roll round.

Risk Cadence Chart

The part of "review" that quietly gets expensive

Review gets treated as one job, but it's actually two, and only one of them needs a person's judgement.

The first part is keeping the picture of a supplier current, having something accurate to look at when the time comes. The second part is a person actually looking at that picture and deciding whether the risk level still holds.

Those get bundled together because in most programmes doing the second thing means doing the first thing from scratch, sending the questionnaire out again, waiting for it back, reading through the answers and deciding what's changed since last time.

That's what makes review expensive, and expense is what shrinks it. When refreshing the data and applying judgement to it are the same piece of work, the honest response under time pressure is to do less of it, on fewer suppliers, less often, and that's exactly how a well-designed risk tier ends up back on a flat annual cycle regardless of what it was supposed to get.

None of this means the data matters less. It means the two jobs are worth separating on purpose, so the person doing the judging isn't also the person doing the chasing.

Supplier Count Chart

Matching depth to risk, not just frequency

Prioritisation isn't only about how often a supplier gets looked at. It's also about how much looking.

A supplier's risk tier should decide the shape of the assessment, not just its position on the calendar. A high risk supplier and a low risk supplier reviewed on the same date shouldn't get the same depth of scrutiny just because the date happens to line up.

What decides that depth is the same three questions used to assess the risk in the first place, what does this supplier do for us, what data do they hold, what access do they have. Those questions don't just tell you whether a supplier is high risk overall. They point to which of the three areas actually needs the closer look for that particular supplier, which is a different decision to how often you come back and check.

Supplier Review Chart

Matching depth to risk, not just frequency

Prioritisation isn't only about how often a supplier gets looked at… it's also about how much looking should be done.

A supplier's risk tier should decide the shape of the assessment, not just its position on the calendar. A high risk supplier and a low risk supplier reviewed on the same date shouldn't get the same depth of scrutiny just because the date happens to line up.

What decides that depth is the same three questions used to assess the risk in the first place: what does this supplier do for us, what data do they hold, what access do they have. 

Those questions don't just tell you whether a supplier is high risk overall. They point to which of the three areas actually needs the closer look for that particular supplier, which is a different decision to how often you come back and check.

Put this into practice

A consistent assessment schedule starts with a consistent way of identifying which suppliers matter most.

Use our Supplier Criticality Matrix to score suppliers based on business impact and likelihood before deciding how often they should be assessed.

Where the backlog gets in the way of scheduling

Splitting this into two separate problems is what makes it solvable. There's the backlog of suppliers you already have, and there's every new supplier coming in from this point on, and they need different treatment.

Trying to schedule both at once is where most attempts stall. If you've already got ten thousand suppliers sitting on the books, sitting down and deciding a cadence for all of them in one go is overwhelming enough that it's hard to know where to even start.

The way through isn't clearing the backlog first, it's building a solid process for every new supplier coming in, one that assesses risk and sets the right cadence from day one, and letting that process do the work going forward.

Over time, suppliers move out of the backlog and into that properly scheduled group, not because the backlog got tackled directly, but because the new process is what's actually improving the picture. The backlog doesn't need solving in one sitting, it needs a route out of it that doesn't depend on solving it in one sitting.

What a working prioritisation process looks like end to end

Put together, this is a fairly short list, and each part builds on what's already been covered.

Start by knowing your full list of suppliers, because you can't prioritise a list you don't have in front of you. From there, have enough of a picture of the business to actually assess impact, which is what the earlier work on criticality and risk is there to support.

Look at both impact and likelihood across every supplier on that list, not just the ones that would hurt the most if something went wrong. Set a risk appetite, drawing the line wherever the organisation is comfortable drawing it, whether that's only the very highest risk suppliers or a wider group.

Then let that risk tier decide two things together, how much depth the assessment needs and how often it gets revisited, rather than treating either one as fixed.

Most programmes are already doing some of this. What tends to be missing is the last step, letting tier and appetite drive both depth and frequency at once, rather than defaulting back to one calendar because that's the part that was easiest to set up first.

Working Prioritisation Process

A fixed schedule versus one that actually keeps up

Most of what's described here can be built with a spreadsheet and a genuine commitment to using it. Knowing your supplier list, assessing impact and likelihood, setting tiers, deciding depth and frequency by tier, all of that is process and judgement before it's tooling.

Where it tends to fall apart isn't the model. It's what happens between the scheduled points. A contract will often say a supplier has to tell you if they change who they use underneath them. That clause sits in a legal document somewhere, and there's rarely a working process that actually catches the change when it happens and routes it back to whoever owns the decision. The schedule looks right on paper, but problems show up in the months between reviews, not in the reviews themselves.

That's the real difference between a prioritisation model that's well designed and one that's actually keeping pace with the risk it's meant to track. It isn't a bigger version of the same annual exercise, reviewing more suppliers, more often, with more people. It's building around noticing change as it happens, rather than scheduling the next point at which someone might happen to notice it.

What security teams ask next

Key takeaways

How should we prioritise supplier assessments, in short

Once a supplier's risk level is known, prioritisation is a separate decision about how much scrutiny they get and how often. Here's the shape of it, and where it tends to break down.

  • Depth and cadence are a separate decision

    Knowing a supplier is high risk doesn't automatically decide how deep the assessment goes or how often it repeats. That's a second decision, not a given.

  • Risk should set the clock

    The highest risk suppliers need shorter intervals because it matters more that the view held of them is current. A low risk supplier with nothing pointing to change can reasonably go a year or longer.

  • Reviews don't need a date to happen

    A contract change, a shift in what a supplier does, or a new use of AI in their service are all reasons to bring a review forward, regardless of where that supplier sits on the schedule.

  • Review is two jobs bundled as one

    Keeping a supplier's data current and applying judgement to it get treated as a single task. That's what makes review expensive, and expense is what shrinks how much gets reviewed.

  • Depth follows the same three questions as risk

    What a supplier does for you, what data they hold, and what access they have don't just set the risk level. They point to which area actually needs the closer look.

  • Backlog and new intake need different processes

    Trying to schedule thousands of existing suppliers and every new one with the same process is where most attempts stall. Build the new supplier process first, and let the backlog move into it over time.

Where to start

Let a supplier's risk tier decide both how deep the assessment goes and how often it repeats, and build a solid process for new suppliers before trying to solve the whole backlog in one sitting.

Pattern Trapezoid Mesh

Get the security manager's briefing

Monthly research, case studies and practical guides you won't find anywhere else.

Join thousands of security managers turning their TPRM programmes into success stories.