Supplier Due Diligence

Supplier Due Diligence Risk Tiering: How to Avoid One-Size-Fits-All Reviews

Build risk tiers that determine questionnaire depth, evidence requirements, approval thresholds and review frequency.

Updated 2026-08-226 min readReviewed by Emissa Compliance Research
On this page

Guide contents

Tiering should change the workflow

A risk score is useful only if it changes which requirements apply, how often the supplier is reviewed or who must approve an exception.

Use explainable drivers

Supplier category, geography, criticality, product exposure, spend and prior findings are easier to govern than opaque scores with no operational interpretation.

Combine inherent and control evidence

Separate the supplier’s underlying exposure from the evidence showing how risks are managed.

Re-tier on meaningful events

Material sourcing changes, new geographies, findings or regulatory exposure should trigger reassessment instead of waiting for an annual cycle.

Continue the workflow

Related Emissa resources

Editorial standard

Source-aware supplier compliance guidance

Emissa articles focus on operational data, evidence and workflow design. Regulatory applicability and legal decisions should be confirmed against current official sources and qualified advisors.

Turn the guidance into an operating workflow.

See how Emissa connects supplier evidence, buyer requirements, due diligence and regulatory work in one controlled operating layer.

Book a private demo