What prioritising an assessment actually means
Prioritising a supplier assessment means matching how much scrutiny a supplier gets, and how often, to how much risk they actually carry.
That may sound obvious, but it's a different call from working out which suppliers are risky in the first place. A supplier can come out of a proper risk assessment correctly flagged as high risk, and still sit on exactly the same annual check as a supplier that barely registers. Nobody decided that on purpose. It's just what happens when the risk assessment gets treated as the finish line rather than the input to a second decision.
The highest risk suppliers get looked at more often, because it matters more that your current view of them is still accurate. A supplier that came out of its first review as low risk, with nothing pointing to it changing, can go a full year without another look, or longer. Not because it's been forgotten, but because there's genuinely nothing pulling it forward.
The mistake isn't reviewing low risk suppliers infrequently. It's applying that same infrequent rhythm to everyone, including the suppliers where a stale view is the whole problem.
That's the part worth sitting with before anything else - risk should set the clock but for a lot of programmes, a fixed calendar sets it instead.
Why one calendar for every supplier breaks down
A periodic checkpoint has real value. Having a person sit down and ask whether a supplier's risk level still looks the way it did last time is a genuinely useful piece of judgement, and it shouldn't go away.
Where it goes wrong is treating that checkpoint as something that happens on the same interval for everyone, regardless of what came out of the risk assessment.
A supplier that's already been through review and come out low risk, with nothing about the relationship suggesting that's about to change, can reasonably go a year without another look, or longer. A supplier sitting in the highest risk band needs a shorter interval than that, because it matters more that the view you hold of them is still current.
Reviews also don't have to be tied to a date at all. A contract change, a shift in what a supplier actually does for you, a new use of AI somewhere in their service, are all reasons to bring a review forward regardless of where that supplier sits in the schedule. None of those show up on a calendar, they show up when something changes - and the only way to catch them is to have a process that's actually watching for the change rather than waiting for the next fixed date to roll round.

The part of "review" that quietly gets expensive
Review gets treated as one job, but it's actually two, and only one of them needs a person's judgement.
The first part is keeping the picture of a supplier current, having something accurate to look at when the time comes. The second part is a person actually looking at that picture and deciding whether the risk level still holds.
Those get bundled together because in most programmes doing the second thing means doing the first thing from scratch, sending the questionnaire out again, waiting for it back, reading through the answers and deciding what's changed since last time.
That's what makes review expensive, and expense is what shrinks it. When refreshing the data and applying judgement to it are the same piece of work, the honest response under time pressure is to do less of it, on fewer suppliers, less often, and that's exactly how a well-designed risk tier ends up back on a flat annual cycle regardless of what it was supposed to get.
None of this means the data matters less. It means the two jobs are worth separating on purpose, so the person doing the judging isn't also the person doing the chasing.
.png)
Matching depth to risk, not just frequency
Prioritisation isn't only about how often a supplier gets looked at. It's also about the questions we need to ask.
A supplier's risk tier should decide the shape of the assessment, not just its position on the calendar. A high risk supplier and a low risk supplier reviewed on the same date shouldn't get the same depth of scrutiny just because the date happens to line up.
What decides that depth is the same three questions used to assess the risk in the first place, what does this supplier do for us, what data do they hold, what access do they have. Those questions don't just tell you whether a supplier is high risk overall. They point to which of the three areas actually needs the closer look for that particular supplier, which is a different decision to how often you come back and check.

Put this into practice
A consistent assessment schedule starts with a consistent way of identifying which suppliers matter most.
Use our Supplier Criticality Matrix to score suppliers based on business impact and likelihood before deciding how often they should be assessed.
Where the backlog gets in the way of scheduling
Splitting this into two separate problems is what makes it solvable. There's the backlog of suppliers you already have, and there's every new supplier coming in from this point on, and they need different treatment.
Trying to schedule both at once is where most attempts stall. If you've already got thousands of suppliers sitting on the books, sitting down and deciding a cadence for all of them in one go is overwhelming enough that it's hard to know where to even start.
The way through isn't clearing the backlog first, it's building a solid process for every new supplier coming in, one that assesses risk and sets the right cadence from day one, and letting that process do the work going forward.
Over time, suppliers move out of the backlog and into that properly scheduled group, not because the backlog got tackled directly, but because the new process is what's actually improving the picture. The backlog doesn't need solving in one sitting, it needs a route out of it that doesn't depend on solving it in one sitting.
What a working prioritisation process looks like end to end
Put together, this is a fairly short list, and each part builds on what's already been covered.
Start by knowing your full list of suppliers, because you can't prioritise a list you don't have in front of you. From there, have enough of a picture of the business to actually assess impact, which is what the earlier work on criticality and risk is there to support.
Look at both impact and likelihood across every supplier on that list, not just the ones that would hurt the most if something went wrong. Set a risk appetite, drawing the line wherever the organisation is comfortable drawing it, whether that's only the very highest risk suppliers or a wider group.
Then let that risk tier decide two things together, how much depth the assessment needs and how often it gets revisited, rather than treating either one as fixed.
Most programmes are already doing some of this. What tends to be missing is the last step, letting tier and appetite drive both depth and frequency at once, rather than defaulting back to one calendar because that's the part that was easiest to set up first.

A fixed schedule versus one that actually keeps up
Most of what's described here can be built with a spreadsheet and a genuine commitment to using it. Knowing your supplier list, assessing impact and likelihood, setting tiers, deciding depth and frequency by tier, all of that is process and judgement before it's tooling.
Where it tends to fall apart isn't the model. It's what happens between the scheduled points. A contract will often say a supplier has to tell you if they change who they use underneath them. That clause sits in a legal document somewhere, and there's rarely a working process that actually catches the change when it happens and routes it back to whoever owns the decision. The schedule looks right on paper, but problems show up in the months between reviews, not in the reviews themselves.
That's the real difference between a prioritisation model that's well designed and one that's actually keeping pace with the risk it's meant to track. It isn't a bigger version of the same annual exercise, reviewing more suppliers, more often, with more people. It's building around noticing change as it happens, rather than scheduling the next point at which someone might happen to notice it.
What security teams ask next
- How Do We Identify Critical Suppliers in Our Supply Chain?
- What Hidden Supplier Dependencies Could Increase Our Risk?
- What Makes a Supplier Critical?
- Are We Focusing Supplier Assurance on the Right Suppliers?
- Put this into practice: Use the Suppler Criticality Matrix



