Supplier Risk Scores Explained
What the number is actually telling you
A supplier risk score is a triage tool that gets treated as a verdict. Used properly it tells you where to look. Used as a decision, it replaces judgement with a number whose origins nobody can explain.
A supplier risk score is a single rating, usually out of 100, summarising what is currently known about a vendor across several weighted categories such as sanctions and exclusions, entity registration, financial or business stability, and past performance. It is a summary of evidence rather than a prediction, and its usefulness depends entirely on whether you can see which sources produced it and how they were weighted.
Four categories, weighted differently
The categories are fairly consistent across providers. The weighting and the sources behind them are where they diverge.
| Category | What it draws on | Why it is weighted as it is |
|---|---|---|
| Sanctions and exclusions | Exclusion, debarment and sanctions lists | Usually weighted heaviest, because a listing is a binary problem rather than a matter of degree |
| Registration and identity | Entity registration records and tax identifier validation | Establishes that the vendor is who they say they are, which everything else depends on |
| Past performance | Public award or contract history where available | Indicates whether the vendor has delivered before, though availability varies a great deal by sector |
| Business stability | Longevity, consistency and public filings | Slower moving than the others, which is why it typically carries less weight |
Two vendors, same score, different problems
A score is an average of unlike things
A vendor weak on registration and strong on screening can land on the same number as the reverse. The overall figure hides which, and those two situations need completely different responses.
The weighting encodes a judgement
Deciding that sanctions matter more than longevity is an opinion about risk. If you cannot see the weighting, you are adopting somebody else's opinion without knowing what it is.
A low score is usually a question
In practice a poor rating most often points at an unresolved finding awaiting confirmation rather than a genuinely bad vendor. Resolving it changes the number.
Movement matters more than level
A vendor that dropped is more interesting than a vendor that has always sat mid-range, and only a score with history tells you which you are looking at.
Including us
If a provider cannot answer these plainly, the score is difficult to rely on in front of anybody who challenges it.
| Question | What a good answer looks like |
|---|---|
| Which sources produced this? | Named sources, not a description of a proprietary model |
| How is each category weighted? | Stated numbers, visible on the record rather than in a sales conversation |
| Can I see the categories separately? | Yes, with each one openable to what fed it |
| When was it last refreshed? | A date, and an explanation of what triggers a refresh |
| What happens on a possible match? | It is shown to a person with the evidence, not concluded automatically |
| Can I challenge a finding? | A documented route, with the outcome recorded either way |
Triage, then look properly
| Do | Do not |
|---|---|
| Use it to decide where to spend review time | Use it as the approval decision |
| Open the weak category and read the sources | Treat the overall number as the finding |
| Watch movement and the reason attached to it | Compare scores between providers as if they mean the same thing |
| Record what you concluded and why | Assume a score that has not moved is a score that was re-checked |



