Risk-Based Supplier Control

Matching the level of control to what could go wrong.

12 min

The extent of control applied to an external provider should reflect the effect of their output on the organisation's ability to meet requirements. Applying the same regime to a critical machined component and a box of stationery wastes effort on one and under-controls nothing on the other.

Factors that determine the level of control

  • Criticality of the supplied item to safety, function, compliance or the customer.
  • Complexity and how easily nonconformity could be detected on receipt.
  • Availability of alternatives — a sole source requires more attention, because you cannot simply stop buying.
  • Supplier's track record and demonstrated capability.
  • Whether the process is special — welding, heat treatment, plating, non-destructive testing — where conformity cannot be verified by subsequent inspection.

Special processes

Where the result cannot be fully verified afterwards, control must be applied to the process rather than to the output: approved procedures, qualified operators, calibrated and monitored equipment, and process records. Buying a heat-treated part and inspecting its dimensions verifies nothing about the metallurgy, and this is one of the most common gaps in supplier control.

Selection criteria

Define, apply and record criteria for evaluation, selection, monitoring and re-evaluation. Quality system certification is evidence, not a substitute for assessment — a certificate confirms a system exists, not that it delivers your specific requirements.

1 of 9

Checking your enrolment…