Find AI Prompts
HomeOperations & Supply ChainSupplier Risk Assessment
Operations & Supply ChainProcurement & Suppliers

AI Prompts for Supplier Risk Assessment

Supplier risk is not one thing. A supplier can be financially sound but geographically exposed, operationally excellent but dependent on a single sub-tier source, compliant on paper but unable to scale. Assessing risk means looking at each dimension separately, scoring likelihood and impact honestly, and then concentrating attention where the combination of probability and consequence is highest — not where the supplier is simply the largest.

These prompts build the per-supplier profile, quantify concentration and single-source exposure across the base, and design mitigations proportionate to the risk. They structure your knowledge; they do not know your suppliers, and any external fact the model suggests must be verified.

Before you use these

Have these ready to replace the highlighted [variables]:

The prompts

1. Build the supplier risk profile

Best forA structured, dimension-by-dimension risk view of a critical supplier.
Inputs needed
  • Supplier facts
  • Incident history
  • Financial signals
How to use itOne supplier at a time for critical ones. Ask for the evidence quality on each score so you know where you are guessing.
Expected outputRisk profile with likelihood, impact, evidence quality and rationale per dimension, an overall rating and the top three risks.
Act as a supply chain risk analyst assessing [supplier].

Facts: [what they supply, annual spend, share of our requirement they cover, single/dual source, locations of their sites, their key sub-tier inputs if known, contract terms]
Financial signals: [payment behavior, credit rating, public results, ownership changes]
Operational history: [OTIF, quality events, capacity constraints, incidents]
Context: [region risks, regulatory exposure, our dependency and switching time]

Assess each dimension with likelihood (1–5), impact on us (1–5), evidence quality (strong/partial/assumed) and a two-sentence rationale:
1. Financial: insolvency, distress, ownership change.
2. Operational: capacity, quality, key-person, IT/cyber.
3. Geographic and geopolitical: natural hazard, political, logistics corridor, tariff exposure.
4. Sub-tier: their dependence on single sources we cannot see.
5. Compliance and ESG: regulatory, labor, environmental, sanctions.
6. Commercial and relationship: our importance to them, contract protection, exit terms.
7. Concentration: how much of our requirement they hold and the time to replace them.

Then: overall rating with the method, the top three risks by likelihood × impact, the risks where evidence is weakest and how to strengthen it, and whether the assessment should trigger a mitigation plan now.

Do not infer financial health from size or reputation. Mark anything not in the inputs as an assumption.

2. Quantify concentration and single-source exposure

Best forSeeing across the whole supplier base where dependency is highest relative to the time to recover.
Inputs needed
  • Supplier list with spend and sourcing status
  • Items and their criticality
  • Time to qualify alternatives
How to use itGive the model the items, not just the suppliers. Exposure lives at the item level — a small supplier can be a sole source for a critical part.
Expected outputExposure table ranked by revenue at risk × time to recover, concentration metrics, and the items where dual sourcing or buffer stock pays off.
You are analyzing supply base concentration and single-source exposure.

Data: [item, supplier, annual spend, sourcing status (sole/single/dual/multi), item criticality (products or revenue it supports), current inventory in weeks, time to qualify an alternative]

1. Compute concentration: spend share of top 5 and top 10 suppliers; count of single- and sole-sourced items; share of critical items that are single-sourced.
2. For each single/sole-sourced critical item: revenue at risk per week of disruption (state the basis), weeks of inventory cover, time to qualify an alternative, and the exposure window (qualification time minus cover).
3. Rank items by revenue at risk × exposure window. This is the priority list.
4. For the top items, estimate the cost of the standard mitigations — buffer inventory to close the window, pre-qualifying a second source, dual sourcing with a volume split — and compare to the expected loss (probability × impact, with stated probability assumptions).
5. Identify hidden concentration: different suppliers that share a region, a parent company, or a likely sub-tier source.

Present the results as a ranked table and a short narrative for a risk committee. Where item criticality or revenue linkage is missing, mark the row as incomplete rather than estimate it.

3. Design mitigation and monitoring

Best forA mitigation plan proportionate to each risk, with indicators that would show it materializing.
Inputs needed
  • Prioritized risks
  • Mitigation options and costs
  • Data sources for monitoring
How to use itAsk for indicators with sources and thresholds. Risk assessments that are not monitored are done once and forgotten.
Expected outputMitigation plan per risk with option, cost, owner and timeline, a monitoring set with triggers, and a review cadence.
Act as a supplier risk manager converting a risk assessment into a mitigation and monitoring plan.

Prioritized risks: [risk, supplier/item, likelihood, impact, exposure window]
Options: [buffer stock, dual source, contractual protection, supplier development, financial support, redesign/de-spec, insurance, exit]
Constraints: [budget, engineering capacity for re-qualification, inventory space]

For each risk:
1. Mitigation options with cost, time to implement, residual risk after implementation, and side effects (e.g. buffer stock increases obsolescence risk).
2. Recommended option and why it is proportionate to likelihood × impact. Include 'accept and monitor' as a legitimate choice for lower risks.
3. Owner, milestones and completion date.

Monitoring:
4. For each risk, 2–3 leading indicators with source, threshold and check frequency (e.g. supplier payment terms requests, OTIF drift, credit rating changes, regional alerts, sub-tier news).
5. Escalation: who is notified when a threshold is crossed and the pre-agreed first action.
6. Review cadence for the assessment itself and the events that trigger an out-of-cycle review.

Present as a plan table plus a monitoring dashboard specification. Do not propose indicators we cannot actually observe.

Illustrative risk profile

The output of the first prompt for a single-sourced packaging supplier. Numbers are illustrative; the point is the evidence-quality column.

DimensionLikelihoodImpactEvidenceRationale
Financial24PartialAccounts filed on time; leverage rising; no credit report obtained
Operational34StrongOTIF fell from 96% to 89% over two quarters; one quality escape
Geographic25StrongSingle site in a flood-exposed zone; no secondary site
Sub-tier43AssumedResin source unknown; supplier has not answered the question
Compliance / ESG13PartialCertifications current; no audit in 3 years
Concentration55Strong100% of requirement; 26 weeks to qualify an alternative; 6 weeks of cover
Two of the three highest-scoring risks rest on assumed or partial evidence. The mitigation plan should start by converting those into facts (a credit report, a sub-tier disclosure) before spending on buffers.

Related prompts

Logical next step

After this, most operations teams move on to a Supply Chain Risk Register.

Get the free Operations & Supply Chain AI Starter Kit → Nine of these prompts as a diagnose → analyze → plan workflow with an intake worksheet, delivered by email. See what's inside

All Operations & Supply Chain prompts · Search the full library