Procurement & Vendors

Supplier risk review

Upload the vendor's information pack (proposal, policies, security questionnaire, certificates, accounts) and set your review criteria.

  • Procurement & Vendors
  • Traceable reasoning
  • Runs anywhere
Preview methodology

2–3 weeks ~25 minutes

For a typical multi-document review workflow

No coding required

Input
Supplier submissions, contracts or performance data
Output
A scored evaluation per risk with the reasoning shown
Runs in
Skillsize · ChatGPT · Claude · Copilot
Export
SKILL.md · MCP
Time saved
~2–3 weeks per run

— USE CASES

What people use Supplier risk review for

Defensible supplier selection

Score every risk on the same weighted criteria, with the rationale recorded.

Comparable submissions

Different formats are normalised into one structure so a like-for-like comparison is possible.

Ongoing vendor oversight

Re-run the same assessment periodically to track whether performance or risk has shifted.

What it works from

  • Supplier submissions, contracts or performance data
  • Your evaluation criteria and weightings

What you get back

  • A scored evaluation per risk with the reasoning shown
  • A ranked comparison ready for a decision paper

— HOW IT BEHAVES

How Supplier risk review produces its result

The mechanics behind this specific template — what it reads, what it calculates, and where a human stays in the loop.

Scored against your criteria

Each risk is assessed against criteria you control and weight, so the same standard applies to every risk in the risk universe in scope.

Risk registers, controls and policy documents pulled into one schema

Every risk is captured in the same field structure, so records drawn from different documents and sources stay comparable.

Whole sets of risk registers, controls and policy documents at once

All of your risk registers, controls and policy documents is processed as one set, so patterns across documents surface instead of being read one file at a time.

Live research on the risk universe in scope

Current external sources on the risk universe in scope are researched during the run rather than recalled from training data, and every source travels with the output.

Composed as work product

Findings on the risk universe in scope are written up as a document that reads like professional output, with each claim tied back to a risk.

Why this is expensive by hand

Evaluating the risk universe in scope fairly means applying identical criteria to submissions that arrive in wildly different formats. Defensible supplier selection is the typical trigger — score every risk on the same weighted criteria, with the rationale recorded. Done properly it is defensible; done at pace it becomes a judgement call nobody can retrace. And "properly" usually means 2–3 weeks of manual work.

How this Skill produces it

As a Skill, the work is already sequenced. You bring the evidence, and the run produces a scored evaluation per risk with the reasoning shown plus a ranked comparison ready for a decision paper. The judgement is built in — how items are broken up, what standard they are held to, and where the run stops for a human review. In effect, 2–3 weeks of senior time compresses into ~25 minutes — and the output is comparable across clients, quarters and colleagues instead of shaped by whoever ran it.

Who it's for

  • Procurement and category managers
  • Third-party risk and vendor management teams
  • Bid and proposal teams
  • Consultants running sourcing exercises

Run it in Skillsize — or export it anywhere

Supplier risk review exports as a structured SKILL.md file and is MCP-ready, so the same method runs in ChatGPT, Claude, Copilot or your own AI products. Adapt it to your methodology, and the intelligence stays yours — not locked to one vendor.

ChatGPTClaudeCopilotAI Products (MCP)

More Procurement & Vendors Skills

Browse the full library →