AI Prompts for Supplier Risk Assessment
Supplier risk is not one thing. A supplier can be financially sound but geographically exposed, operationally excellent but dependent on a single sub-tier source, compliant on paper but unable to scale. Assessing risk means looking at each dimension separately, scoring likelihood and impact honestly, and then concentrating attention where the combination of probability and consequence is highest — not where the supplier is simply the largest.
These prompts build the per-supplier profile, quantify concentration and single-source exposure across the base, and design mitigations proportionate to the risk. They structure your knowledge; they do not know your suppliers, and any external fact the model suggests must be verified.
Before you use these
Have these ready to replace the highlighted [variables]:
- Supplier list with spend, what they supply, location(s), and whether they are single or sole source
- Financial information available (payment behavior, credit reports, public accounts)
- Known incidents or near misses
- Time to qualify an alternative for each critical item
The prompts
- 1. Build the supplier risk profile
- 2. Quantify concentration and single-source exposure
- 3. Design mitigation and monitoring
1. Build the supplier risk profile
Act as a supply chain risk analyst assessing [supplier]. Facts: [what they supply, annual spend, share of our requirement they cover, single/dual source, locations of their sites, their key sub-tier inputs if known, contract terms] Financial signals: [payment behavior, credit rating, public results, ownership changes] Operational history: [OTIF, quality events, capacity constraints, incidents] Context: [region risks, regulatory exposure, our dependency and switching time] Assess each dimension with likelihood (1–5), impact on us (1–5), evidence quality (strong/partial/assumed) and a two-sentence rationale: 1. Financial: insolvency, distress, ownership change. 2. Operational: capacity, quality, key-person, IT/cyber. 3. Geographic and geopolitical: natural hazard, political, logistics corridor, tariff exposure. 4. Sub-tier: their dependence on single sources we cannot see. 5. Compliance and ESG: regulatory, labor, environmental, sanctions. 6. Commercial and relationship: our importance to them, contract protection, exit terms. 7. Concentration: how much of our requirement they hold and the time to replace them. Then: overall rating with the method, the top three risks by likelihood × impact, the risks where evidence is weakest and how to strengthen it, and whether the assessment should trigger a mitigation plan now. Do not infer financial health from size or reputation. Mark anything not in the inputs as an assumption.
2. Quantify concentration and single-source exposure
You are analyzing supply base concentration and single-source exposure. Data: [item, supplier, annual spend, sourcing status (sole/single/dual/multi), item criticality (products or revenue it supports), current inventory in weeks, time to qualify an alternative] 1. Compute concentration: spend share of top 5 and top 10 suppliers; count of single- and sole-sourced items; share of critical items that are single-sourced. 2. For each single/sole-sourced critical item: revenue at risk per week of disruption (state the basis), weeks of inventory cover, time to qualify an alternative, and the exposure window (qualification time minus cover). 3. Rank items by revenue at risk × exposure window. This is the priority list. 4. For the top items, estimate the cost of the standard mitigations — buffer inventory to close the window, pre-qualifying a second source, dual sourcing with a volume split — and compare to the expected loss (probability × impact, with stated probability assumptions). 5. Identify hidden concentration: different suppliers that share a region, a parent company, or a likely sub-tier source. Present the results as a ranked table and a short narrative for a risk committee. Where item criticality or revenue linkage is missing, mark the row as incomplete rather than estimate it.
3. Design mitigation and monitoring
Act as a supplier risk manager converting a risk assessment into a mitigation and monitoring plan. Prioritized risks: [risk, supplier/item, likelihood, impact, exposure window] Options: [buffer stock, dual source, contractual protection, supplier development, financial support, redesign/de-spec, insurance, exit] Constraints: [budget, engineering capacity for re-qualification, inventory space] For each risk: 1. Mitigation options with cost, time to implement, residual risk after implementation, and side effects (e.g. buffer stock increases obsolescence risk). 2. Recommended option and why it is proportionate to likelihood × impact. Include 'accept and monitor' as a legitimate choice for lower risks. 3. Owner, milestones and completion date. Monitoring: 4. For each risk, 2–3 leading indicators with source, threshold and check frequency (e.g. supplier payment terms requests, OTIF drift, credit rating changes, regional alerts, sub-tier news). 5. Escalation: who is notified when a threshold is crossed and the pre-agreed first action. 6. Review cadence for the assessment itself and the events that trigger an out-of-cycle review. Present as a plan table plus a monitoring dashboard specification. Do not propose indicators we cannot actually observe.
Illustrative risk profile
The output of the first prompt for a single-sourced packaging supplier. Numbers are illustrative; the point is the evidence-quality column.
| Dimension | Likelihood | Impact | Evidence | Rationale |
|---|---|---|---|---|
| Financial | 2 | 4 | Partial | Accounts filed on time; leverage rising; no credit report obtained |
| Operational | 3 | 4 | Strong | OTIF fell from 96% to 89% over two quarters; one quality escape |
| Geographic | 2 | 5 | Strong | Single site in a flood-exposed zone; no secondary site |
| Sub-tier | 4 | 3 | Assumed | Resin source unknown; supplier has not answered the question |
| Compliance / ESG | 1 | 3 | Partial | Certifications current; no audit in 3 years |
| Concentration | 5 | 5 | Strong | 100% of requirement; 26 weeks to qualify an alternative; 6 weeks of cover |
Related prompts
- a Supply Chain Risk Register
- Supply Chain Disruption Response
- Supplier Evaluation
- Supplier Scorecards and SLAs
- Sourcing Strategy
- Safety Stock Calculation
Logical next step
After this, most operations teams move on to a Supply Chain Risk Register.
All Operations & Supply Chain prompts · Search the full library
Want the free Operations & Supply Chain AI Starter Kit? Nine prompts as a diagnose → analyze → plan workflow, delivered by email. See what's inside
✓ On its way — check your inbox in the next few minutes.
Send me this starter kit and occasional useful AI workflow updates. Unsubscribe anytime. Privacy Policy.