SCRM Supplier Compliance & Risk Management

Explainer · method

How a risk assessment is built – and where a matrix helps.

A matrix makes risks comparable. It does not make them measurable. That difference decides whether the result holds or merely looks colourful.

A risk assessment follows the same sequence everywhere: establish the context, collect risks, analyse, evaluate, treat, monitor. ISO 31000 describes this cycle as guidance without prescribing a method.

The matrix enters at the analysis step. It assigns two values to each risk – how likely it is and how severely it would act – and turns them into a position in a grid. Its value lies in comparability: twenty risks can be prioritised in one meeting without everyone holding all twenty in mind.

Its danger is false precision. Two estimates become a product that looks like a measurement. Without described levels you produce a number without meaning – and then make decisions on that basis.

The sequence in five steps

  1. Establish contextWhat is to be protected, and from what point is a risk no longer bearable?The acceptance threshold is set before the assessment, not after. Otherwise it gets adjusted to the result.
  2. Collect risksWhat could endanger your objectives?From several sources: past incidents, processes, suppliers, dependencies, regulation. Not only from the memory of the management meeting.
  3. AnalyseHow likely, how severe?Both axes need described levels. A “3” must mean the same to everyone, otherwise assessments are not comparable.
  4. EvaluateAbove or below the threshold?Only here is it decided whether treatment is required. The position in the grid is the basis, not the outcome.
  5. Treat and monitorAvoid, reduce, transfer or consciously carry.Every measure gets an owner and a date. The residual risk is assessed again.

How the matrix is built

Both axes need described levels. Without a description, a five is not an assessment but a feeling.

LevelLikelihoodImpact, example business interruption
1 — very lowNot known in the sector, theoretically conceivableBarely noticeable, absorbed in daily work
2 — lowLess often than every five yearsUnder one day, no customer effect
3 — mediumRoughly every one to five yearsUp to a week, delivery delays towards customers
4 — highPossible several times a yearUp to four weeks, penalties or loss of customers
5 — very highRegularly, or already occurredOver four weeks, the business line itself at stake

Impact needs more than one dimension. Alongside interruption, at least people, legal exposure and reputation belong in – and the highest one counts, not the average.

A worked example

A single source for a casting, with no qualified alternative.

StepAssessmentReasoning
Likelihood3 — mediumTwo supply shortages in the sector over five years, one plant with a known capacity peak.
Impact5 — very highWithout the part, final assembly stops. Bringing up a new source including first article inspection: about three months.
Gross risk15 — above the thresholdThe acceptance threshold sits at 8. Treatment is therefore not optional.
MeasureQualify a second sourceOwner: purchasing, deadline: six months, interim step first article inspection after four.
Residual risk6 — below the thresholdLikelihood unchanged at 3, impact falls to 2 because an approved alternative exists.

Six pitfalls

Undescribed scales
A 5×5 matrix without described levels produces numbers that are not comparable between two people.
Everything is medium
When nobody wants to rate high, everything gathers in the middle. One remedy is requiring a top risk to be named per category.
Averaging across dimensions
A risk with low financial damage and danger to life is not “medium”. The highest affected dimension governs.
Assessing without a threshold
Without a pre-set acceptance threshold, what is bearable gets decided afterwards – and that is visible in an audit.
Residual risk not assessed
Reassessment after treatment is rare. That leaves open whether the measure sufficed.
Nobody decides
Who may consciously carry a risk must be defined. Otherwise nobody carries it in fact and everybody formally.

The matrix is a tool for shared understanding, not a calculator. Its value arises in the conversation about the rating – not in the number that ends up on the page.

Supplier risk from data rather than estimates

Criticality, incident history, single sources and deadlines exist as data in SCRM. Assessment then rests on observation rather than memory – and can be compared year on year.

Request a consultation What risk-based thinking means Go to risk management