Back to skills
Procurement

Supplier Risk

Supplier Risk: Assess operational and security dependencies. Review business need, spend, supplier options, policy, contract terms, and stakeholders and produce a supplier risk register.

---
name: procurement-supplier-risk
description: Use for supplier risk when asked to assess operational and security dependencies; produce a supplier risk register.
license: MIT
metadata:
  author: Thrive
  category: procurement
---

# Supplier Risk

## When to use

Use this skill for supplier risk when you need to assess operational and security dependencies. The expected result is a supplier risk register.

## Boundaries

Work within the requested task and its stated acceptance criteria. Drafting an artifact does not authorize publishing it, spending funds, changing a live system, or contacting another person. Identify any such action separately before taking it.

## Inputs

Inspect business need, spend, supplier options, policy, contract terms, and stakeholders. Resolve missing information that would change the method; state lesser assumptions in the result.

## Method

1. **Diagnose.** Define mandatory requirements, spend, timeline, supplier market, approval route, and contract exit terms.
2. **Decide.** Compare total cost, service, risk, and switching effort.
3. **Produce.** Build a supplier risk register from the inspected material; keep assumptions distinguishable from observed facts.

## Decision rules

- Compare suppliers on total cost, service, security, concentration risk, and implementation effort.
- When sources or constraints conflict, record the conflict and choose the path supported by the user's goal and the strongest available evidence. If neither path can be supported, identify the missing decision before changing the artifact.

## Domain rules

- Document conflict-of-interest and supplier due diligence checks.
- Record the decision owner and renewal or exit conditions.

## Verification

Confirm mitigation owners and review dates. Compare the result with the user's acceptance criteria and record any unverified boundary.

Return a weighted comparison with evidence, exceptions, decision owner, and renewal or exit checkpoint.

## Stop conditions

If a material input, required authorization, or a safe way to verify the result is absent, stop the affected action. Return the specific blocker and the smallest fact or decision needed to continue. Do not report an unrun check as passed.

## Output

Provide a supplier risk register. Include the decisive evidence and actual verification result. Name any artifact location and unresolved issue that affects its use.

<!--
MIT License

Copyright (c) 2026 Thrive

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
-->