Supply Chain Risk Assessment: A Step-by-Step Framework
A supply chain risk assessment only drives decisions if it's built on a repeatable framework. This is the six-step method: map your network, identify and score risks, build a risk matrix, assign mitigation, and keep it current.

A supply chain risk assessment is how you turn a vague sense that things could go wrong into a ranked, evidence-based view of exactly where your network is exposed and what to do about it. Run once, it's a snapshot. Run as a repeatable framework, it becomes the engine of your whole risk programme. This guide walks through that framework step by step, so you can run an assessment that holds up to scrutiny and actually drives decisions.
The difference between an assessment that works and one that gathers dust is structure. A good framework is consistent enough to compare very different risks on the same terms, and light enough to repeat as conditions change. Here is the sequence.
How to assess supply chain risk, step by step
1. Scope and map your network
Start by deciding what the assessment covers, then map it. That means going beyond your direct suppliers to the sub-tier sources, routes, facilities and flows a disruption could travel through. You can't assess risk you haven't located, and the exposures that hurt most often sit below Tier 1, in the part of the network you can see least. A clear map is the foundation everything else builds on.
2. Identify the risks
With the network mapped, identify what could go wrong at each point. A thorough way to do this is to work through the four types of supply chain risk: supply, demand, operational and external. For each node, ask which of these apply and how. The goal at this stage is coverage, not scoring, a complete list of the threats your network actually carries.
3. Assess likelihood and impact
Now score each risk on two axes: how likely it is to occur, and how badly it would hurt if it did. Keep the scale consistent, a simple one-to-five on each axis works well, so a supplier failure and a regulatory change can be compared on the same terms. Scoring both dimensions is what stops you over-weighting dramatic but unlikely risks while ignoring the quiet, probable ones.
4. Plot the risk matrix and prioritise
Combine likelihood and impact and you have a supply chain risk matrix: a grid that ranks every risk by its overall exposure. It's a useful start, but a colour-coded grid still rests on subjective scores, and it can't tell you what a risk is actually worth. The step up is to quantify the value at risk, the financial exposure each risk carries if it materialises: model how a disruption would propagate through your network and estimate the cost genuinely at stake, so you prioritise by the dollars exposed rather than the cells you happened to shade red. A matrix turns a long list into a short set of decisions; value at risk makes sure they're the right ones.
5. Decide mitigation and assign ownership
For each priority risk, decide the response: reduce it, transfer it, accept it, or build a contingency for it. Then give it an owner and a date. A risk without an owner is a risk nobody is actually managing, and this step is where most assessments quietly fail. Be specific about what changes, whether that's qualifying a second source, holding more stock at a key node, or renegotiating a single-source contract.
6. Monitor and re-assess continuously
Finally, treat the assessment as a living document, not an annual event. Supplier financial health, geopolitical exposure and demand all move constantly, so a matrix built in January is out of date by March. Set triggers for re-scoring, a supplier downgrade, a geopolitical event, a new dependency, so the assessment keeps pace with reality rather than freezing a moment in time.
What separates a strong assessment from a checkbox
Most assessments fail in predictable ways. They stop at Tier 1 and miss the sub-tier exposures where disruption usually begins. They score inconsistently, so a risk owned by one team can't be compared with a risk owned by another. And they treat the exercise as a compliance task to be filed, rather than a decision tool to be used. Avoiding those three traps does more for your resilience than any amount of extra detail in the matrix.
The other mark of a strong assessment is that it can justify itself. In regulated, government and defence contexts, ranking risks isn't enough; you have to explain why. When you're asked why one risk was prioritised over another, or why a given mitigation was chosen, a bare score with no reasoning behind it won't hold. This is where causal analysis matters: modelling why a disruption would propagate, and which intervention actually changes the outcome, gives every entry in your matrix a rationale you can defend to a board, an auditor or a regulator.
That defensibility is also what makes an assessment worth repeating. When the reasoning is explicit, a re-assessment is an update rather than a rebuild, and the framework compounds in value over time.
A step-by-step assessment is the practical core of a broader discipline. For how it fits into a complete programme, see our guide to supply chain risk management.
Questions this piece raises
How do you do a supply chain risk assessment step by step?
Work through six steps. First, scope and map your network, including sub-tier suppliers, routes and facilities. Second, identify what could go wrong at each point, using the four types of risk (supply, demand, operational, external) for coverage. Third, score each risk on likelihood and impact using a consistent scale. Fourth, plot a risk matrix and prioritise the high-likelihood, high-impact risks. Fifth, decide a mitigation and assign an owner and date. Sixth, monitor and re-score continuously as conditions change.
What is a supply chain risk matrix?
A supply chain risk matrix is a simple grid that ranks risks by likelihood against impact. Each risk is scored on both axes, and its position on the grid shows its overall exposure. The risks in the high-likelihood, high-impact corner are your priorities; the low-low corner can be monitored and largely left alone. Its value is forcing prioritisation, turning a long list of risks into a short set of decisions.
What should a supply chain risk assessment include?
A complete supply chain risk assessment should include a map of your network beyond Tier 1, an identification of risks across the four types (supply, demand, operational and external), a consistent scoring of likelihood and impact, a prioritised risk matrix, a mitigation and owner for each priority risk, and a process for continuous monitoring. The thread through all of it is consistency: scoring everything on the same terms so risks can be compared and ranked.
See Causal AI applied to your supply chain.
A structured, 45-minute session with a senior solutions architect.
Request a Demo
Related insights

Sub-Tier Supply Chain Visibility: Seeing Beyond Tier 1
Most disruption starts in the suppliers you can't see. This is what sub-tier supply chain visibility means, why seeing beyond Tier 1 is so hard, and a practical way to map the Tier 2 and Tier 3 dependencies that actually threaten you.

The 4 Types of Supply Chain Risk (and How to Assess Each)
Not all supply chain risk behaves the same way. This guide breaks risk into its four core types, supply, demand, operational and external, and shows you how to assess each one so you can see where your network is genuinely exposed.


