- Segment suppliers by risk, not by spend. A cheap component in a safety-critical assembly outranks an expensive commodity.
- Monitor with data you already collect: goods-in rejections, on-time delivery, and nonconformances traced to supplied material.
- Approval is a decision with evidence behind it, and it needs a review date.
A questionnaire sent to every supplier annually generates paperwork and no insight. Grading by risk means the few that matter get real attention and the rest get a light touch.
Segmenting by risk
- What does the part do? Safety, regulatory and functional criticality first.
- How easily would a defect be detected before it reached the customer?
- How replaceable is the supplier, and how long would requalification take?
- What is the history? Past performance is the strongest predictor.
- Spend matters, but it is the weakest of these factors.
Approving a supplier
- Define what evidence you need per risk band: certification, first article, sample approval, a site visit for the highest band.
- Record the decision, the evidence and the date, with a named approver.
- Set a review date. An approval with no expiry becomes permanent by default.
- Note any conditions, for instance approved for one part number only.
Monitoring with data you already have
Three measures cover most needs: goods-in rejection rate, on-time and in-full delivery, and the count of internal nonconformances traced to supplied material. All three come from records you keep anyway. Publishing them back to the supplier quarterly changes behaviour more than an audit does.
Escalation that means something
- Define the thresholds in advance: what performance triggers a formal request for corrective action, what triggers increased inspection, what triggers removal from the approved list.
- Request a structured response for significant issues rather than an email promise.
- Verify the corrective action with subsequent deliveries, then reduce inspection back. Increased inspection that is never removed becomes a permanent cost you absorb.
The audit question
On-site supplier audits are expensive and are worth it for the top risk band only. For everyone else, a short self-assessment plus your own performance data is more informative than a day spent reading a supplier's document control procedure.