All Posts

Procure Tech

How Supplier Risk Scoring Works and What to Check Before Buying It

How Supplier Risk Scoring Works and What to Check Before Buying It

Bhavika J

Techshorts Editorial Team

What these platforms actually do

A supplier risk platform keeps a record of who a company buys from and attaches evidence to each of those records. The evidence usually falls into four groups: financial health, cybersecurity posture, compliance and sanctions screening, and operational or geographic exposure. Most products then compress that evidence into a score, or a set of scores, so suppliers can be ranked against each other.

The score is a summary, not a finding. Two platforms looking at the same supplier will disagree, because they are weighting different inputs and refreshing them on different cycles. Treating a single number as an answer is the most common way these tools get misused.

Why procurement teams are buying now

The driver is regulatory, and it is specific rather than general.

Under the EU's NIS2 directive, entities in scope must address supply chain security, including the security aspects of their relationships with direct suppliers and service providers. Article 21(3) requires that assessment to take into account the vulnerabilities specific to each direct supplier and the overall quality of that supplier's products and cybersecurity practices, including its secure development procedures (Directive (EU) 2022/2555). That is a per-supplier evidence obligation, which is hard to meet from a spreadsheet.

In financial services, the Digital Operational Resilience Act requires firms to maintain a register of information covering contractual arrangements with ICT third-party service providers. The European Supervisory Authorities set 30 April 2025 as the deadline for competent authorities to submit those registers for the purpose of designating critical ICT third-party providers (EBA, EIOPA and ESMA, 2024).

The Corporate Sustainability Due Diligence Directive has slipped. Directive (EU) 2025/794 of 14 April 2025, the "stop the clock" measure, pushed the member state transposition deadline to 26 July 2027 and the start of application to 26 July 2028. That later date applies to the largest companies, meaning those above 3,000 employees on average and 900 million euro in net worldwide turnover (Directive (EU) 2025/794; Norton Rose Fulbright, 2025).

The direction is not uniformly toward more. Germany's cabinet adopted an amendment to the Supply Chain Due Diligence Act on 3 September 2025 that removes the annual reporting obligation, and BAFA stopped reviewing due diligence reports from 1 October 2025 (KPMG Law, 2025; BAFA). The substantive due diligence duties themselves remain in force. Reporting got lighter; the underlying obligation did not.

How the main approaches differ

Outside-in monitoring. The platform builds a supplier profile from externally observable data: credit and financial filings, sanctions and watch lists, adverse media, disclosed breaches, and scanning of internet-facing infrastructure. No supplier participation is needed, so coverage is broad and refresh can be continuous. The trade-off is depth. External signals tell you a supplier looks fragile, not why.

Assessment-based. Questionnaires, requested evidence, and in some markets shared assessment exchanges where one completed questionnaire is reused across many buyers. This produces documentation of the kind NIS2 and DORA expect. It is slow, and it stalls entirely when a supplier declines to respond.

Embedded in the source-to-pay suite. Risk data sits inside sourcing, onboarding and requisition workflow. The data is often thinner than a specialist tool's, but the enforcement point is real: a flag can hold an onboarding or block a purchase order rather than sit in a report.

Larger programmes usually run a combination, with the suite as the control point and specialists feeding it.

What to test during evaluation

Load your real vendor master during the trial, not a sample, and measure the match rate. Coverage on the top 200 suppliers is rarely the problem. Match rates fall off in the tail, which is also where unmonitored exposure accumulates.

Ask what moved a score and whether the platform will show the underlying document. A score you cannot explain to an auditor, or to the supplier disputing it, has limited value.

Check that criticality tiering is yours to define. NIST's cybersecurity supply chain guidance is explicit that scrutiny should be risk-based and driven by how critical a supplier is to the missions and systems it supports, with a criticality level assigned per tier-one supplier (NIST SP 800-161r1, 2022). A vendor-defined risk taxonomy will not match that on its own.

Then check the write path. If a red flag cannot stop an onboarding or route an approval, the platform is a monitoring subscription rather than a control.

On multi-tier visibility, ask how sub-tier relationships are derived. Inferred from shipping and trade data is a different claim from declared by the supplier, and the two carry very different reliability.

Where implementations fail

Scores get produced with no named owner, so nobody acts on them. Alert thresholds are left at defaults, category managers receive hundreds of notifications a month, and the feed gets muted. Questionnaire programmes go out to every supplier at once instead of the critical ones, and response rates collapse. Tail spend is cut from scope on cost grounds, and then a supplier in the tail becomes the incident.

The pattern underneath all four is buying to a compliance date rather than to an operating model. The tool arrives; the decision rights do not. Settling in advance who is allowed to block a purchase order, and on what evidence, does more for the outcome than the choice of vendor.

Sources

EUR-Lex. "Directive (EU) 2022/2555 (NIS2)." 2022. https://eur-lex.europa.eu/eli/dir/2022/2555/oj

EBA, EIOPA and ESMA. "The ESAs announce timeline to collect information for the designation of critical ICT third-party service providers under DORA." 2024. https://www.eba.europa.eu/publications-and-media/press-releases/esas-announce-timeline-collect-information-designation-critical-ict-third-party-service-providers

EUR-Lex. "Directive (EU) 2025/794 amending Directives (EU) 2022/2464 and (EU) 2024/1760." 2025. https://eur-lex.europa.eu/eli/dir/2025/794/oj

Norton Rose Fulbright. "Omnibus 'Stop the Clock' Directive comes into force." 2025. https://www.nortonrosefulbright.com/en/knowledge/publications/391bb931/brief-update-omnibus-stop-the-clock-directive-comes-into-force

KPMG Law. "Supply Chain Act: reporting obligation no longer applies, sanctions reduced." 2025. https://kpmg-law.de/en/supply-chain-act-reporting-obligation-no-longer-applies-sanctions-reduced/

BAFA. "Berichtspflicht (Lieferketten)." https://www.bafa.de/DE/Lieferketten/Berichtspflicht/berichtspflicht_node.html

NIST. "SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations." 2022. https://csrc.nist.gov/Projects/cyber-supply-chain-risk-management/key-resources-and-activities