Token导航 LogoToken导航TokenDH.com
研究检索只读clawhub未标认证来源可访问clear审计通过

supplier-risk-scoring供应商风险评分

Agent Skill

supplier-risk-scoring 用于查找、检索和筛选相关信息,适合在 OpenClaw 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

8,690

周安装

355

GitHub Stars

公开资料未说明

下载量

2,783
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:supplier-risk-scoring(供应商风险评分)
来源仓库:https://github.com/flynndavid/supplier-risk-scoring
安装命令:
openclaw skills install supplier-risk-scoring
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install supplier-risk-scoring

简介

通过分层行动计划,针对财务、依赖性、合规性、绩效和地理风险生成 0-100 的供应商风险指数评分。

SKILL.md

Supplier Risk Scoring System — Supplier Risk Index (SRI)

Framework: Supplier Risk Index (SRI) Price: $19 Category: Productivity / Risk Management Tags: supplier risk, vendor risk, procurement, risk scoring, ops, compliance last_validated: 2026-03-03


What This Is

The Supplier Risk Index (SRI) is a structured scoring system that produces a 0-100 risk score for every vendor across five dimensions. It classifies vendors into Green, Yellow, or Red tiers and prescribes specific actions for each tier. Run it at onboarding, annually, and whenever a vendor's situation changes materially.

Problem it solves: Ops teams can't manage vendor risk without a consistent framework. The SRI eliminates gut-feel risk assessments and gives procurement teams an objective, defensible methodology for prioritizing vendor oversight and making sourcing decisions.

Output: A risk score (0-100), tier classification (Green/Yellow/Red), and a recommended action plan for every supplier in your portfolio.


The SRI Framework

Five Risk Dimensions:

┌─────────────────────────────────────────────────────────┐
│              SUPPLIER RISK INDEX (SRI)                  │
│                                                         │
│  D1: Financial Stability           (max 25 pts)         │
│  D2: Single-Source Dependency      (max 20 pts)         │
│  D3: Compliance History            (max 20 pts)         │
│  D4: Performance Track Record      (max 20 pts)         │
│  D5: Geographic / Regulatory Risk  (max 15 pts)         │
│                                                         │
│  Total SRI Score: 0-100                                 │
│  (Higher = LOWER risk — score is a "health" score)      │
└─────────────────────────────────────────────────────────┘

Note: The SRI is a health score, not a risk score — higher is better. A score of 90 means low risk; a score of 20 means high risk. This keeps it intuitive: you want vendors to score high.


DIMENSION 1: Financial Stability (25 points)

Why it matters: A financially unstable supplier can't fulfill contracts, maintain quality, or stay in business. Financial instability is the leading cause of unexpected supply chain disruption.

What to assess:

IndicatorHow to Evaluate
Business ageYears in operation
Revenue stabilityGrowing / Stable / Declining
Funding/ownershipBootstrapped stable, PE-backed, VC-backed, public
Credit risk signalsLate payments to their vendors, legal judgments
Concentration riskAre they heavily dependent on a single customer?

Scoring Rubric:

ConditionPoints
Company 5+ years old, stable/growing revenue, no financial red flags25
Company 3-5 years old, stable revenue, minor concerns18-22
Company 1-3 years old (startup), VC-funded or early-stage10-17
Company has known financial stress (late payments, restructuring, news of losses)3-9
Company has declared bankruptcy, receivership, or is insolvent0-2

Data Sources:

  • Dun & Bradstreet Paydex score (business credit)
  • Dunn & Bradstreet or Experian Business Credit Report
  • LinkedIn / public news search for financial distress signals
  • SEC filings (public companies)
  • Self-reported financials for small vendors ($25K+ spend: request last 2 years' financials)
  • References from their other major customers

Scoring Action: For vendors scoring below 15 on D1, escalate to Finance for review before awarding new contracts.


DIMENSION 2: Single-Source Dependency (20 points)

Why it matters: If you rely on one vendor for a critical product or service with no alternative, you're exposed. Any disruption — financial, operational, or relationship — creates immediate business risk.

What to assess:

FactorQuestion
ReplaceabilityHow quickly can you replace this vendor if they disappear?
AlternativesHow many qualified alternatives exist in the market?
Revenue concentrationWhat % of your spend goes to this vendor?
CriticalityWhat happens to operations if this vendor stops delivering?
Switching costTime and cost to transition to an alternative

Scoring Rubric:

ConditionPoints
Multiple qualified alternatives exist, vendor is easily replaceable in <30 days20
Some alternatives exist, 30-90 day replacement window, moderate switching cost13-19
Few alternatives, 90-180 day replacement window, significant switching cost6-12
No alternatives identified, critical dependency, >180 day replacement window0-5

Dependency Multiplier (apply if both conditions are true):

  • Vendor is the ONLY source for a critical input/service AND
  • Vendor accounts for >30% of your spend in that category

Reduce D2 score by 5 points (floor at 0)

Scoring Action:

  • Any vendor scoring 0-5 on D2 should have a documented contingency plan
  • Any vendor with the Dependency Multiplier applied should have a backup vendor identification project initiated

DIMENSION 3: Compliance History (20 points)

Why it matters: Compliance failures are leading indicators — they signal process weakness, poor management, or risk-taking culture. A vendor that's had one compliance issue is statistically more likely to have another.

What to assess:

AreaWhat to Check
Insurance complianceCOI gaps, lapses, late renewals
Regulatory complianceIndustry violations, fines, regulatory actions
Legal historyLawsuits, judgments, settlements
Data / security incidentsBreaches, audit failures, security violations
Contract compliancePrior vendor relationships, terminations for cause
LicensingValid licenses maintained in all required jurisdictions

Scoring Rubric:

ConditionPoints
Clean history — no known compliance issues in 3+ years20
Minor issues, fully resolved, 1-2 instances in 3 years14-19
Moderate issues (1-2 regulatory warnings, minor litigation) — resolved8-13
Significant issues (major litigation, regulatory action, insurance lapse) — resolved3-7
Active unresolved compliance issues, ongoing litigation, or recent serious violations0-2

Data Sources:

  • Your internal vendor record (COI tracking, past issues)
  • Court records search (PACER for federal, state court websites)
  • Better Business Bureau
  • State licensing board lookups
  • Google News search: "[Vendor Name] lawsuit OR violation OR fine OR breach"
  • Industry-specific databases (FDA for food/pharma, OSHA for contractors, etc.)

Scoring Action: Any vendor scoring 0-7 on D3 requires a Legal review before contract renewal.


DIMENSION 4: Performance Track Record (20 points)

Why it matters: Past performance is the most reliable predictor of future performance. Vendors with consistent quality, on-time delivery, and responsive issue resolution are lower risk than vendors with spotty records.

What to assess:

MetricHow to Measure
On-time delivery rate% of deliverables/invoices delivered on schedule
Quality defect rate# of quality issues reported in last 12 months
Issue resolution timeAverage days to resolve a reported problem
Communication responsivenessResponse time to queries and escalations
Contract adherenceAre they delivering exactly what was contracted?
Customer satisfactionInternal stakeholder rating of the vendor

Scoring Rubric (for existing vendors with performance history):

ConditionPoints
Consistently exceeds expectations, <2 issues/year, fast resolution20
Meets expectations, 2-5 minor issues/year, resolved promptly14-19
Mostly meets expectations, occasional issues, moderate resolution time8-13
Inconsistent, frequent issues, slow resolution, complaints from internal teams3-7
Significant ongoing performance problems, at-risk relationship0-2

For New Vendors (no internal history):

  • Default to 12 points (neutral)
  • Adjust up/down based on references: +3 for strong references, -3 for weak references
  • First 90 days: conduct a performance check-in (milestone review) and update score

Scoring Action: Any vendor scoring 0-7 on D4 should be on a Performance Improvement Plan (see Vendor Performance Audit skill).


DIMENSION 5: Geographic & Regulatory Risk (15 points)

Why it matters: Where a vendor operates and where they're incorporated can create risk — political instability, regulatory changes, natural disaster exposure, data sovereignty requirements, and trade compliance complexity.

What to assess:

FactorRisk Indicators
Country of operationPolitical stability, sanctions risk, trade restrictions
Data sovereigntyDoes data leave the country? GDPR, CCPA, HIPAA applicability?
Natural disaster exposureOperations in high-risk zones (hurricanes, earthquakes, flooding)
Regulatory environmentIs their industry heavily regulated in their jurisdiction?
Currency / FX riskAre payments in a volatile currency?
Export controlsAny ITAR, EAR, or export control applicability?

Geographic Risk Reference:

Vendor LocationRisk LevelStarting Points
US, Canada, UK, EU (stable)Low12-15
Australia, New Zealand, Japan, South KoreaLow12-15
Mexico, Brazil, IndiaModerate8-11
Eastern Europe, Middle East (stable countries)Moderate-High5-9
China (data handling concerns, regulatory risk)High3-6
Countries with active US sanctions or instabilityVery High0-2

Regulatory Complexity Modifier:

ConditionAdjustment
Vendor operates in a heavily regulated industry (healthcare, finance, defense)-2 pts
Vendor handles personal data across international borders-2 pts
Vendor has active export control considerations-3 pts
Vendor has robust regulatory compliance program documented+2 pts

Scoring Action: Any vendor scoring 0-5 on D5 should be reviewed by Legal or Compliance before contract execution.


SRI Score Calculation

Step 1: Score Each Dimension

DimensionMax PointsYour Score
D1: Financial Stability25___
D2: Single-Source Dependency20___
D3: Compliance History20___
D4: Performance Track Record20___
D5: Geographic / Regulatory Risk15___
TOTAL SRI SCORE100___

Step 2: Classify the Tier

SRI ScoreTierLabel
75-100🟢 GreenLow Risk
50-74🟡 YellowModerate Risk
Below 50🔴 RedHigh Risk

Recommended Actions by Tier

🟢 Green (75-100): Low Risk

  • Review frequency: Annual
  • Oversight level: Standard contract management
  • Actions:

- Include in standard quarterly performance reviews - Monitor for any D1/D2/D3 trigger events - Document score in vendor record - Eligible for preferred vendor status, extended contracts, increased spend

🟡 Yellow (50-74): Moderate Risk

  • Review frequency: Semi-annual (every 6 months)
  • Oversight level: Active monitoring
  • Actions:

- Identify the lowest-scoring dimension(s) and focus remediation there - Request a vendor meeting to discuss risk areas - For D2 issues: begin identifying backup vendors - For D3 issues: request compliance documentation - For D4 issues: initiate performance discussion - Set 90-day improvement targets for specific dimensions - Do not increase spend or award new contracts until score improves

🔴 Red (Below 50): High Risk

  • Review frequency: Monthly
  • Oversight level: Active risk management
  • Actions:

- Escalate to manager immediately - Notify internal stakeholders who depend on this vendor - Initiate contingency planning (backup vendor identification) - Place hold on new POs pending remediation plan - Send formal risk notification to vendor - Set 60-day remediation deadline - If score doesn't improve to Yellow within 90 days: recommend transition plan


Trigger Events (Re-Score Immediately)

Outside of scheduled reviews, re-score a vendor immediately when:

  • News of financial difficulty (layoffs, funding cuts, bankruptcy rumors)
  • Insurance lapse or COI non-compliance detected
  • Major customer of theirs announces they're switching vendors
  • Significant leadership change at vendor
  • Regulatory action or public litigation filed
  • Security breach or data incident
  • Merger, acquisition, or ownership change
  • Natural disaster affecting their operations
  • Your team reports a significant quality or delivery failure

Portfolio-Level Risk Analysis

After scoring all vendors, conduct a portfolio review:

Risk Distribution Target

TierTargetAction if Exceeded
🟢 Green>70% of portfolio
🟡 Yellow<25% of portfolioAddress highest-risk Yellows first
🔴 Red<5% of portfolioImmediate remediation or transition

Concentration Analysis

  • Identify your top 5 vendors by annual spend
  • If any top-5 vendor is Red tier → priority escalation
  • If >50% of spend is concentrated in vendors below 75 SRI → portfolio risk alert

Single-Source Audit

  • List every vendor where your D2 score is ≤5
  • These are your critical single-source dependencies
  • Each one should have a documented contingency plan within 90 days

SRI Registry Fields

Track these fields in your vendor registry:

FieldNotes
Vendor ID
Vendor Name
D1: Financial Stability Score0-25
D2: Single-Source Score0-20
D3: Compliance History Score0-20
D4: Performance Score0-20
D5: Geographic Risk Score0-15
Total SRI Score0-100
Risk TierGreen / Yellow / Red
Last ScoredDate
Next Review DateAnnual / Semi-annual / Monthly
Key Risk NotesFree text
Contingency PlanY/N + link
Action StatusNone / In Progress / Escalated

Expected Outputs

After implementing SRI:

  1. ✅ Risk score (0-100) for every vendor in your portfolio
  2. ✅ Tier classification (Green/Yellow/Red) with documented rationale
  3. ✅ Prioritized list of vendors requiring active risk management
  4. ✅ Identified single-source dependencies with contingency planning triggered
  5. ✅ Portfolio-level risk distribution with trend tracking
  6. ✅ Scheduled re-review cadence for every vendor

Decision quality improvement: Teams using structured risk scoring report 40-60% fewer vendor-related surprises because risk signals are identified before they become crises.


*Supplier Risk Index (SRI) — Part of the Vendor & Compliance Operations Pack by Remy Claw* *More at remyclaw.com | @Remy_Claw on X*

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

96.01%
按下载量换算2,672

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills