Free Template · XLSX · 6 sheets · 605 formulas

    Supplier Risk Matrix: Excel template to prioritise third parties (2026)

    A working tool, not a blank form. Score seven risk dimensions per supplier: the matrix computes residual risk, classifies it into four levels with automatic colour coding, and tracks mitigation plans against their committed dates. Capacity for 100 suppliers.

    100% free · We send the link to your corporate email

    The workbook is in Spanish. Its formulas and validations behave identically in Excel and Google Sheets.

    What is a supplier risk matrix?

    A supplier risk matrix turns a list of third parties into a prioritised one: which supplier needs attention this week, which can wait until the next half-year review, and why. Without it, third-party risk management comes down to the buyer's intuition and to reacting once the problem has already happened.

    This template scores every supplier across seven dimensions — financial, operational, legal and compliance, cybersecurity, reputational, geographic and concentration — on a 1 to 5 scale, discounts the effectiveness of the controls you already have in place, and returns the residual risk: the risk actually left on the table.

    It is built for procurement managers, compliance officers and risk teams who have to defend decisions in a committee. Every risk level carries a suggested action, an owner and a committed date, and the dashboard shows at all times how many of those actions are overdue.

    The 6 sheets, one by one

    This is not a form to fill in by hand: 605 formulas wire the sheets together, so a supplier entered in the register shows up in the assessment and its risk level reaches the dashboard without anyone copying anything.

    Dashboard

    Five live indicators: suppliers assessed, how many sit at critical, high and medium risk, and — the one that stings in a committee — how many mitigation actions are already overdue and still open. Below, the legend of the four levels with their criteria and suggested action.

    Registro de Proveedores — supplier register

    Base inventory of up to 100 third parties: ID, supplier, country, category, internal owner, annual spend, dependency, status (dropdown: active, onboarding, inactive, blocked), last assessment date and notes. Ships with three sample suppliers so you can see the behaviour before loading your own.

    Evaluación de Riesgos — risk assessment

    The engine of the workbook: sixteen columns. ID and name are pulled from the register; you score the seven dimensions and likelihood from 1 to 5 and state your control effectiveness. The sheet computes the inherent average, the residual risk and the level, and colours the result.

    Planes de Mitigación — mitigation plans

    One row per action: supplier, risk addressed, committed control, owner, due date, evidence and status (pending, in progress, closed, blocked). Days remaining recalculate against today automatically, and the cell turns red once the action is overdue.

    Listas — reference lists

    The reference criteria, editable: what each level means and how often it should be reviewed — immediately, monthly, quarterly or half-yearly. This is the sheet that bends to your organisation's risk appetite instead of imposing someone else's.

    Instrucciones — instructions

    Five usage steps plus the warning every risk tool should carry in print: it is a guidance instrument and does not replace legal, financial or cybersecurity advice, nor specialist verification.

    How residual risk is calculated

    The logic is explicit and auditable: you can open it, argue about it in committee and change it if your methodology differs.

    Residual risk = average of the 7 dimensions × (1 − control effectiveness)
    • The seven dimensions are scored from 1 (low) to 5 (maximum). The cell only accepts whole numbers in that range: nobody types a 7 or a 0.5 by accident.
    • Control effectiveness is expressed as a percentage and is your documented judgement, not a fixed value baked into the template.
    • Likelihood is scored separately, also from 1 to 5, and can raise the level on its own: a near-certain event should not be diluted inside an average.

    The four levels and what to do with each

    LevelFormula criterionSuggested actionReview frequency
    CriticalResidual risk ≥ 3.5 or likelihood = 5Escalate and define an immediate controlImmediate
    HighResidual risk ≥ 2.5 or likelihood ≥ 4Assign an owner and an action dateMonthly
    MediumResidual risk ≥ 1.5Monitor on the defined cycleQuarterly
    LowResidual risk below 1.5Keep evidence and review periodicallyHalf-yearly

    What is inside

    605 formulas

    Inherent average, residual risk, level, days remaining on every action and the five dashboard indicators all calculate themselves. You score; the sheet concludes.

    Automatic colour coding

    Four conditional formatting rules colour the level column — critical, high, medium and low — and a fifth turns overdue mitigation actions red.

    Protected scale

    Three input validations: two dropdown lists for statuses and a whole-number 1 to 5 restriction on the scores. A matrix with mixed scales stops being comparable.

    Live deadlines

    Days remaining recalculate against the current date every time you open the file, and the dashboard counts how many overdue actions are still open.

    Third-party risk and compliance programmes

    Third-party due diligence is where procurement and compliance meet. Internal money-laundering and terrorist-financing risk management programmes — SAGRILAFT in Colombia and its regional equivalents — require counterparty assessment to follow a methodology and to be documented: who assessed, against which criteria, what was decided and when.

    This matrix produces that documentary trail and supports the programme your organisation already runs: it does not design it, approve it or replace it. Egixia does not certify or guarantee compliance with any regulation. Programme design, risk appetite, restricted-list screening and final approval remain with your compliance officer and your legal advisors.

    Frequently asked questions about the supplier risk matrix

    What is a supplier risk matrix and what is it for?

    It is a tool that scores each third party across several risk dimensions, discounts the effectiveness of existing controls and ranks the supplier base by attention priority. It tells you where to spend the team's time: which supplier needs an immediate control, which one only needs monitoring and which can be reviewed once every six months. This template does it for up to 100 suppliers, with 605 formulas already written.

    How is a supplier's residual risk calculated?

    Residual risk is the average of the seven inherent dimensions multiplied by (1 − control effectiveness). A supplier with high inherent risk but effective controls ends up with low residual risk; one with moderate risk and no controls ends up higher. The template calculates it automatically and classifies the result as critical, high, medium or low, raising the level when likelihood alone warrants it.

    Which risk dimensions should be assessed in a supplier?

    The seven in the template cover what usually fails in practice: financial (solvency and continuity), operational (capacity and delivery performance), legal and compliance, cybersecurity, reputational, geographic and concentration — the latter meaning how much your operation depends on that single supplier. You can add your own columns: the sheet is not locked.

    Is it useful for SAGRILAFT or an AML/CFT due diligence programme?

    It works as an input and as a record: it supplies the methodical counterparty assessment and the documentary trail — criteria, score, decision, owner and date — that these programmes require. It does not replace them. Egixia does not certify or guarantee regulatory compliance: programme design, restricted-list screening and final approval remain with your compliance officer and your legal advisors.

    Is it free, and what format does it arrive in?

    Yes, it is free. We ask for your name, company and corporate email so we can send you the download link — no spam chains. It arrives as an .xlsx file in Spanish, compatible with Excel and Google Sheets, with three sample suppliers loaded that you can delete in one go to start with your own base.

    Download the supplier risk matrix — free

    Leave your corporate email and we will send the link instantly. Six sheets, 605 formulas, capacity for 100 suppliers, automatic colour coding by level and mitigation plan tracking against committed dates.

    The download link is sent to your corporate email.

    The workbook is in Spanish. Its formulas and validations behave identically in Excel and Google Sheets.

    🙏 Found it useful? Help us reach more procurement professionals by following us on LinkedIn.

    Follow Egixia on LinkedIn

    What if your supplier risk updated itself?

    A spreadsheet is an excellent starting point and a poor system of record: someone has to remember to open it. Egixia's Risk & Compliance module keeps every supplier file alive inside the procurement flow. Book a 30-minute demo.

    Schedule strategic demo