What this template is for
A self-assessment risk questionnaire for suppliers to complete. Covers financial, operational, compliance, and cybersecurity risk areas. This downloadable template helps procurement professionals streamline their risk assessment process — no need to build complex spreadsheets from scratch.
You cannot visit 200 suppliers in person — but ignoring their risk posture isn't an option
Procurement teams managing a large supply base face an impossible triage problem: every supplier carries risk, but only a fraction can receive an on-site assessment each year. A self-assessment questionnaire scales risk evaluation across your entire supplier base by letting suppliers self-report their controls, certifications, and risk exposures before you invest in a site visit. This approach is standard practice in financial services third-party risk management and is increasingly expected in manufacturing and technology supply chains. It lets you identify the 10-15% of suppliers that warrant deeper investigation while documenting baseline risk awareness for the remaining 85%.
Inherent-to-residual risk progression aligned with industry risk frameworks
Most supplier questionnaires stop at collecting answers — they do not help you calculate what the answers mean. This template includes a built-in methodology for calculating both Inherent Risk (the raw risk level before any controls) and Residual Risk (what remains after the supplier's controls are applied). This distinction is critical because a supplier in a high-risk geography with strong operational controls may have acceptable residual risk, while a supplier in a low-risk geography with weak controls may not. The evidence request checklist tells you exactly which documents to collect per risk domain — financial statements, insurance certificates, penetration test reports — so your validation process is systematic, not ad-hoc.
What's included
- 40+ risk assessment questions organized by risk domain
- Supplier self-rating scales for each question
- Evidence/documentation request checklist per domain
- Inherent risk calculation worksheet
- Residual risk assessment after controls consideration
Who should use this
- Procurement teams collecting risk information from suppliers before on-site assessment.
- Third-party risk managers conducting initial supplier risk screening.
How to use it
- Send the PDF questionnaire to suppliers for completion
- Suppliers self-rate their controls and provide supporting evidence
- Calculate the Inherent Risk score using the worksheet
- Apply control effectiveness ratings to determine Residual Risk
- Use results to prioritize which suppliers need deeper assessment