Industrial risk registers degrade into a list of "supplier delay" lines with identical mitigations. Splitting risk by mechanism restores usefulness, because each mechanism has a different and testable control.
Five categories, five controls
1. Counterparty risk
The supplier is not who or what they claim. Control: documented verification of legal entity, ownership and trading history before award. Independent checks through a verification platform such as TradLoc.com convert this from opinion into an auditable record.
2. Delivery risk
Capacity, logistics or customs. Control: production-slot evidence, Incoterm clarity and a documented clearance path — with the customs documents pre-agreed, not improvised at the port.
3. Quality risk
Product meets the label but not the duty. Control: acceptance testing written into the contract and a rejected-lot procedure with commercial consequence.
4. Compliance risk
Sanctions, local content, HSE and permit exposure. Control: screening at qualification and re-screening at renewal, dated and stored.
5. Continuity risk
Single-source dependency on a critical consumable. Control: a qualified alternate for every category above a defined criticality, tested with a trial order rather than a paper approval.
Score what you can evidence
Score each category on evidence quality, not confidence. A supplier with no verified references scores badly even when the buyer likes them, and that is the point of the framework.
Close the loop with documents
Controls survive staff turnover only if they are written into the transaction documents — the PO conditions, the acceptance clause, the delivery note requirements. See who owes what, when for how those documents interact.