Supplier Risk Scoring: How We Catch a Slipping Supplier Before It Becomes a PPAP Rejection
Back to blog

Supplier Risk Scoring: How We Catch a Slipping Supplier Before It Becomes a PPAP Rejection

A supplier's corrective action response time can slide from five days to three weeks with nobody noticing, right up until a PPAP resubmission gets kicked back a third time. How QualityEngineer.ai scores supplier risk from four weighted signals, tiers the result Critical to Low, and triggers the second party audit before the paperwork catches up to the floor.

Daniel CrouseDaniel Crouse,August 19, 2026,10 min read

A supplier quality engineer maintains an approved supplier list the same way most teams do: a spreadsheet with forty rows, colored cells for on time delivery, and a column for the last audit date that somebody updates when they remember to. One supplier on that list has been slow to close corrective actions for two quarters running, five days stretching to three weeks, but nothing on the sheet turns red because nobody built a rule for response time drift. The first hard signal is a PPAP resubmission on that supplier's bracket getting rejected for the third time, and by then the launch date has already moved.

That is not a training problem. It is a math problem. A person tracking forty suppliers by memory and a spreadsheet cannot hold four moving signals per supplier in their head at once and notice the one that is drifting before it becomes a finding. This post covers how QualityEngineer.ai scores supplier risk from four weighted signals instead of a spreadsheet gut check, what those signals are, and what changes for the engineer who used to own that spreadsheet.

What the spreadsheet actually misses

The spreadsheet fails in a specific way, not a general one. Any single bad data point, a late shipment, a missed audit, a PPAP kickback, gets noticed because it is loud. What gets missed is drift: a metric that is still technically within range but moving the wrong direction across several data points in a row. Corrective action response time going from five days to twelve to twenty one is three separate, individually unremarkable updates to a spreadsheet cell. Nobody schedules a review because nothing crossed a threshold on any single day. The threshold gets crossed by the trend, and a static sheet has no way to see a trend unless someone is actively watching for it, which is exactly the job a busy SQE does not have time to do across forty suppliers.

How the platform scores it instead

Supplier Quality runs AI Risk Scoring across four weighted signals per supplier: quality, delivery, compliance, and cost. The composite recalculates when a supplier's evaluations, shipments, or SCAR outcomes are reassessed, so the score reflects the most recent reassessment, not the supplier as of the last quarterly review.

The output is a tier, not a raw number a reviewer has to interpret: Critical, High, Medium, or Low, each with an explanatory tooltip that names which of the four signals actually drove the assignment. A supplier lands in Critical because its compliance score has been trending down for three cycles, not because a black box said so. That distinction matters when the SQE has to explain to a supplier why their tier changed, or defend the assessment to an auditor asking how the organization determines supplier risk.

Evaluate is the companion side of this. Scorecards, layered process audits, and product evaluations all feed the same composite: you define the criteria, quality PPM, on time delivery, audit results, PPAP submission quality, and the system calculates the weighted score from whatever evaluations have actually landed. The workflow is five steps: select the evaluation type, let the AI pre-fill criteria from commodity type and evaluation history, score and attach evidence, review the AI's flagged risk patterns, export the report. None of those steps replace the engineer's judgment on the score itself. What they replace is the manual work of re-deriving the composite every time a new evaluation lands, and the blind spot of a metric drifting silently between review dates.

Why the tier changes what happens next, not just what it says

A tier that just sits on a dashboard is not worth building. The reason Critical is a distinct state is that it changes the audit cadence automatically: suppliers in the Critical tier get scheduled for quarterly second party audits instead of whatever cadence a spreadsheet owner remembered to apply. That maps directly to IATF 16949 Clause 8.4.2.4.1, which requires the organization to determine the type, frequency, and scope of second party audits based on a risk analysis, explicitly citing supplier performance indicators and the follow up of open issues as legitimate triggers. A risk tier built from live performance data and open findings is precisely the kind of input the clause describes, not a paperwork requirement layered on top of it.

Clause 8.4.2.4, Supplier Monitoring, is the parent requirement: the organization has to have a documented process and criteria to evaluate supplier performance and ensure conformity of externally provided product and services. Clause 8.4.2.1 sets the risk based expectation for the type and extent of control applied to each supplier in the first place. A tiering system that recalculates as new data is reassessed and drives a differentiated audit schedule is the mechanism that satisfies both, not a certificate that says the requirement was considered once a year.

When a supplier does trip into Critical, the loop has to close somewhere. Correct runs the SCAR itself, AI assisted 5-Why and fishbone analysis scoped to the supplier's actual nonconformance, the same 8D structure covered in our 8D vs CAPA guide. The corrective action's own closeout speed is exactly what an SQE weighs when reassessing the compliance dimension, so a supplier that responds fast and holds the fix earns its way back down a tier at the next reassessment, and one that reopens the same finding twice does not get to hide that pattern in a spreadsheet cell nobody rereads.

What the drift actually looks like on the platform

Walk the spreadsheet example back through the scoring model instead. The supplier's compliance score starts the quarter in the range that keeps the composite in Medium. Two SCARs close late in a row, not late enough to trip a hard threshold on their own, and the composite shifts into High when a new evaluation is applied to that supplier's record. The tooltip on that tier assignment names compliance specifically, not a generic "risk increased" message, so the SQE opening the supplier record already knows which of the four signals to dig into before making a call.

That is the structural difference from the spreadsheet. Nothing about the score requires the engineer to remember to check on a fixed calendar date. The composite recalculates the next time the supplier's record is reassessed, so a slow slide gets caught at that reassessment instead of waiting for the next scheduled review. Whether the resulting action is a phone call, an early second party audit, or a formal SCAR is still the engineer's decision. What the platform removes is the part where that decision depends on someone noticing a trend across three separate spreadsheet updates weeks apart.

What comes off the engineer's plate

  • Doing the weighted composite math by hand every time a new evaluation, shipment, or audit result should factor into the score
  • Remembering which suppliers are due for a second party audit and scheduling it by hand
  • Noticing a slow drift across multiple review cycles before it becomes a hard finding
  • Reconstructing why a supplier's risk changed when a customer or auditor asks
  • Tracking SCAR closeout separately from the risk score it should be feeding

None of that is a claim that judgment leaves the process. A tier tells an SQE where to look first across forty or four hundred suppliers. It does not decide whether a supplier gets disqualified, and it does not replace the second party audit itself, it just makes sure the audit gets scheduled before the drift becomes a PPAP rejection instead of after.

Where this fits for AS9100 and VDA 6.3 shops

The same scoring runs for aerospace and automotive suppliers alike; the four signals and the tier logic do not change by standard, only the audit checklist content and cadence expectations layered on top do. AS9100 organizations use the same Critical to Low tiering to prioritize which suppliers get a second party audit ahead of a NADCAP scope review or a customer flow down, and VDA 6.3 process audits attach to the same evaluation record a Gauge R&R or PPAP submission score would. If your supplier base spans both worlds, the composite score is the one place both audiences look, instead of two parallel spreadsheets that inevitably drift apart from each other as much as from reality.

Getting started

If your approved supplier list currently lives in a spreadsheet with colored cells for memory rather than a scoring rule, the fastest way to see the difference is to run one supplier's history through Supplier Quality and watch the tier assignment explain itself. A 30-day trial, no credit card required, is enough time to load your current supplier evaluations and see which ones would already be flagged.

FAQ

What four signals go into the supplier risk score? Quality, delivery, compliance, and cost, weighted into one composite that recalculates when new evaluations are applied.

What do the risk tiers mean? Critical, High, Medium, and Low. Each tier carries an explanatory tooltip naming which signal drove the assignment, so the score is traceable back to a specific input rather than a black box output.

Does a Critical tier automatically schedule an audit? Yes. Suppliers in the Critical tier are scheduled for quarterly second party audits, aligning with IATF 16949 Clause 8.4.2.4.1's requirement to determine audit frequency and scope from a risk analysis that includes supplier performance indicators.

Does this replace the second party audit itself? No. The score determines who gets prioritized and how often, the audit itself is still a scoped assessment against the supplier's QMS, run by a person.

How does a SCAR affect the score? A supplier's corrective action closeout speed and recurrence rate are exactly what an SQE weighs when reassessing the compliance dimension, so a fast, durable fix moves a supplier's tier down over time at the next reassessment, and a reopened finding does not.

Does this work for both AS9100 and IATF 16949 supply bases? Yes. The same four-signal scoring and tiering runs underneath either standard; what changes is the audit checklist content and cadence expectations a shop layers on top, not the scoring mechanism.

Related reading

Daniel Crouse
Daniel Crouse

Founder, QualityEngineer.ai

15+ years in supplier quality, PPAP, and manufacturing systems. Built QualityEngineer.ai because quality engineers deserve better tools than Excel.

View profile →
Built for quality engineers

Ready to automate your PPAP workflow?

QualityEngineer.ai handles the documentation-heavy parts of quality engineering: PPAP, supplier assessments, document analysis, CAPA, and more. Start with a free 30-day trial.