top of page

Complete Workpack · Version 1.0 · August 2026

 

Stop sending every supplier the same questionnaire. This pack gives you a two-tier assurance system you can issue this week: a short form for routine suppliers, a deep form for the ones who can actually hurt you, and the assessor kit that turns the return into a recorded decision.

 

The problem it solves

 

A single all-purpose questionnaire is usually too long for the stationery vendor and too shallow for the firm holding your controlled technical data. Ask too much and onboarding stalls. Ask too little and you inherit the supplier’s unpatched systems, unlicensed subcontractors, or sanctioned parent — without ever asking the question that would have found it.

 

This pack applies the ISO 31000 rule that effort should match consequence. Two minutes of triage decides the form. The rest of the pack is the process around that form: issue, verify, score, decide, file, reassess.

 

What’s in the download

 

Guide (eBook)

  • SRMBOK Guide to Risk-Based Supplier Assurance (42 pages, PDF)

 

Issue to suppliers — fillable PDF and editable Word

  • SRQ-T2 Tier 2 Basic Supplier Questionnaire
  • SRQ-T1 Tier 1 Enhanced Supplier Questionnaire

 

Internal use — fillable PDF and editable Word

  • SRQ-A1 Assessor Scoring Worksheet

 

Governance companions (Word + PDF)

  • POL-SC01 Procurement & Secure Supply Chain Policy
  • PROC-SQ01 Supplier Risk Assessment Procedure

 

Also included

  • README and license

 

Rebrand the templates, drop in your logo, set your onboarding mailbox, and issue.

The two tiers

 Tier 2 — BasicTier 1 — Enhanced
PurposeBaseline diligence for routine, low-consequence suppliersDeep assurance where failure or compromise would materially hurt you
Typical useConsumables, general services, commodity goodsControlled technology, data processors, sole-source manufacturers, site or system access
Supplier effort15–25 minutes60–120 minutes, usually across two or three people
ReassessmentEvery 24–36 months, or on material changeEvery 12 months, or on material change

 

One trigger is enough. A low-value supplier that holds your customer database is still Tier 1. The shared opening sections mean a supplier promoted from Tier 2 to Tier 1 can carry identity and business answers across without starting again.

 

What the guide actually gives you

 

The operating instructions that sit around the forms:

  • Tier-selection matrix — eight trigger criteria. Two minutes before you send anything.
  • Instructions for completion — reproduce with every issue so suppliers know what good looks like.
  • Evidence checklist — what to attach, by tier: registration, insurance, ISO 9001 / 27001, IRAP, DISP, SWMS, modern slavery, BCP test date.
  • Cover email and follow-up sequence — Day 0 through escalation at return date + 7.
  • Standards map — where ISO 31000, 28000, 27001, 22301, 9001, 14001, 20400 and 37001 show up in the questions.
  • Assessor guidance — completeness screen, independent verification table (ASIC, OFAC, DFAT, certification-body registers, DISP), red-flag list, and the scoring method.
  • Four outcomes — Approve · Approve with conditions · Defer · Do not approve. Weighted score bands so two assessors can defend the same call.
  • Adoption steps — find-and-replace placeholders, privacy note, licence terms.

 

The questionnaires also include the red internal-assessment block suppliers must leave blank, plus a supply-continuity check for single-source and critical vendors.

 

Who it is for

 

Procurement, security, trade compliance and supplier-assurance teams that need a defensible file — not a completed form sitting in a shared drive. Built for Australian operating conditions (DSGL, DTCA, Autonomous Sanctions, Modern Slavery Act, PSPF flow-down, ASD Essential Eight, FIRB/FOCI) and usable anywhere the same risks appear: ITAR/EAR, OFAC, UK and EU sanctions, CMMC, IRAP, DISP.

The structure is deliberately modular. Keep the identity, insurance, litigation, WHS and declaration sections; swap the domain-specific blocks if you need a financial, construction, privacy, ESG or product-safety variant. The scoring machinery stays the same.

 

License

 

Licensed to the purchasing organization for internal use, including issue to your own suppliers and subcontractors. You may rebrand, adapt and reproduce within your organization and related entities. You may not resell the pack or publish it as free content.

 

Ready when you are

 

Buy the pack. Replace the organization name and onboarding address. Run the two-minute trigger test on the next new supplier. Issue SRQ-T2 or SRQ-T1 with the cover note and evidence list. Score the return on SRQ-A1. File the decision against POL-SC01 and PROC-SQ01.

SRMBOK Guide to Risk-Based Supplier Assurance

97,00 US$ Precio
67,00 US$Precio de oferta
Impuesto incluido

    Libros y plantillas

    Si no puede encontrar una plantilla en particular o un tema de interés en nuestra plataforma, no dude en comunicarse con nosotros. Es muy probable que lo tengamos en nuestra extensa colección, listo para compartirlo con usted. Nos comprometemos a ayudarle a encontrar exactamente lo que necesita.

    Los más vendidos

    bottom of page