Supplier Risk Assessment
Quality & Inspection Standards
PRODUCTS CENTER
Get Custom Quote
PRODUCTS CENTER
Supplier Risk Assessment Under GJB9001C
Supplier risk assessment is a mandatory requirement under GJB9001C. Clause 8.4.1 explicitly states: "When selecting and evaluating external providers, the organization shall ensure effective identification and control of risks (see 8.1)." This requirement positions risk assessment as a non-negotiable element of supplier qualification and management — not an optional activity.
For PCB manufacturers, supplier risk assessment extends across the entire supply chain. External providers can introduce risks in multiple dimensions: technical (material performance, process capability), schedule (lead times, capacity constraints), economic (price volatility, financial stability), quality (defect rates, nonconformances), and security (counterfeit components, supply chain integrity). Failure to systematically identify and control these risks can lead to production delays, product nonconformances, program cost overruns, and audit findings.
Engineering Summary
- GJB9001C Clause 8.4.1 requires effective identification and control of risks when selecting and evaluating external providers.
- Clause 8.1 requires organizations to analyze and assess technical, schedule, and cost risks, develop risk management plans, and implement risk control measures.
- Supplier risks span multiple dimensions: technical, schedule, economic, quality, compliance, supply chain, and geopolitical risks.
- Risk assessment must be integrated into the supplier lifecycle — from initial evaluation through ongoing performance monitoring and re-evaluation.
- For PCB manufacturers, critical risk areas include material availability, counterfeit components, manufacturing capability, capacity constraints, and supply chain concentration.
- Risk mitigation strategies include supplier diversification, dual sourcing, last-time buys, enhanced verification, and contractual flow-down requirements.
1. What Auditors Check — A Quick Overview
| Audit Focus | What External Auditors Verify | Expected Evidence |
|---|---|---|
| Risk Identification | Are supplier-related risks systematically identified? | Risk registers, supplier evaluation records, risk identification checklists |
| Risk Analysis | Are risks analyzed for likelihood and impact? | Risk analysis matrices, severity assessments, scoring records |
| Risk Evaluation | Are risks evaluated and prioritized for action? | Risk evaluation records, prioritization criteria, risk rankings |
| Risk Treatment | Are risk mitigation measures defined and implemented? | Risk treatment plans, mitigation action records, verification of effectiveness |
| Risk Monitoring | Are risks monitored and reviewed periodically? | Risk review records, updated risk registers, re-evaluation records |
| Integration with 8.4 | Is risk assessment integrated with supplier evaluation and selection? | Risk assessment in supplier evaluations, AVL entries with risk ratings |
| Risk Management Plan | Is a risk management plan established per Clause 8.1? | Risk management plan, risk control measures, effectiveness evaluations |
KEY INSIGHT:
Supplier risk assessment is not a one-time activity. It must be integrated into the entire supplier lifecycle — from initial evaluation and selection through ongoing performance monitoring and re-evaluation. Auditors will verify that risk assessment is systematic, documented, and dynamically maintained.
2. Standard Requirements for Supplier Risk Assessment
2.1 GJB9001C Clause 8.4.1 — The Core Requirement
GJB9001C-2017 Clause 8.4.1 establishes the foundational requirement for supplier risk assessment:
"The organization shall invite customers to participate in the evaluation and selection of external providers of interest to them. When selecting and evaluating external providers, the organization shall ensure effective identification and control of risks (see 8.1)."
This requirement makes risk assessment mandatory in supplier selection and evaluation. The reference to Clause 8.1 means that organizations must apply the full risk management framework — including risk identification, analysis, evaluation, treatment, and monitoring — to their supplier management processes.
2.2 GJB9001C Clause 8.1 — The Risk Management Framework
Clause 8.1 establishes the overarching risk management requirements that apply to supplier risk assessment:
"The organization shall analyze and assess technical, schedule, and cost risks affecting product and service quality, develop risk management plans, and implement risk control measures."
For supplier risk assessment, this requires organizations to:
- Identify risks associated with external providers and their processes, products, and services
- Analyze the likelihood and potential impact of each risk
- Evaluate risks to determine which require treatment
- Develop and implement risk mitigation measures
- Monitor and review risks and the effectiveness of controls
2.3 Integration with Supplier Lifecycle
GJB9001C requires that risk assessment be integrated throughout the supplier lifecycle:
- Evaluation and Selection: Organizations shall "effectively identify risks and determine measures to address risks, and implement effective monitoring and control of risks" when evaluating and selecting suppliers
- Performance Monitoring: Organizations shall monitor supplier performance and "communicate with suppliers identified for improvement and conduct follow-up management to control and reduce risks"
- Re-evaluation: Organizations shall periodically re-evaluate suppliers based on performance data and update the Approved Supplier List accordingly, removing non-conforming suppliers
- Dynamic Management: Organizations shall implement dynamic supplier management and "promptly revise the Approved Supplier List" based on risk assessment results
2.4 Customer Involvement
Organizations must involve customers in supplier risk assessment:
"Organizations shall invite customers to participate in the evaluation and selection of external providers of interest to them."
This requirement ensures that customers have visibility into supplier risks that may affect their programs.
3. Supplier Risk Categories — What to Assess
Supplier risks span multiple dimensions. Organizations should assess risks across the following categories to ensure comprehensive coverage.
3.1 Risk Categories and Assessment Criteria
| Risk Category | Description | PCB Assessment Factors |
|---|---|---|
| Technical Risk | Supplier's ability to meet technical requirements and specifications | Material properties (Dk, Df, Tg), impedance control capability, layer count capability, process capability (Cpk), design for manufacturability |
| Schedule Risk | Supplier's ability to meet delivery commitments and lead times | Production capacity, lead time variability, on-time delivery history, raw material availability, backlog status |
| Economic/Financial Risk | Supplier's financial stability and cost competitiveness | Financial health (audited financials, credit rating), price stability, raw material cost exposure, payment history, investment in capability |
| Quality Risk | Supplier's quality management and product quality performance | GJB9001C certification status, defect rate (DPPM), nonconformance history, corrective action responsiveness, quality system maturity |
| Compliance Risk | Supplier's adherence to regulatory and contractual requirements | Export control compliance, ITAR/EAR compliance, RoHS/REACH compliance, counterfeit prevention (AS5553, AS6174), IPC-1791 certification |
| Supply Chain Risk | Supplier's sub-tier supply chain vulnerabilities | Sub-tier supplier control, single-source dependency, geographic concentration, raw material sourcing, logistics capabilities |
| Geopolitical Risk | Risks arising from geopolitical factors affecting supply | Country of origin, trade restrictions, tariffs, export controls, political stability, supply chain security concerns |
| Obsolescence Risk | Risk of component or material obsolescence | Component lifecycle stage, EOL notifications, availability of alternatives, last-time buy planning |
3.2 PCB-Specific Risk Factors
For PCB manufacturers, the following specific risk factors should be assessed:
- Material Availability: Laminates, prepregs, copper foils, and surface finish materials may have limited suppliers or long lead times
- Manufacturing Capability: High-layer-count capability, impedance control, buried/blind vias, backdrill, and other advanced technologies
- Counterfeit Risk: Electronic components are vulnerable to counterfeiting, especially obsolete or hard-to-find parts
- Supply Chain Concentration: Global PCB production is concentrated, creating dependency risks
- IPC Compliance: IPC-6012 Class 2/3 compliance, IPC-A-600 workmanship, and other IPC standards
- Military Specification Compliance: GJB 362B, GJB 908 (FAI), and program-specific requirements
4. Supplier Risk Assessment Process — The Seven Steps
The supplier risk assessment process applies the ISO 31000 risk management framework to supplier management, from initial identification through ongoing monitoring.
| Step | Activity | PCB Example |
|---|---|---|
| 1 | Establish Context — Define the scope of the risk assessment. Identify the supplier, the products/services they provide, and the program requirements. | Define scope: evaluate high-frequency laminate supplier for a radar program requiring GJB9001C compliance, 20-layer capability, and impedance control. |
| 2 | Identify Risks — Identify all potential risks associated with the supplier across all risk categories. Use checklists, historical data, and expert judgment. | Identify risks: single-source material, supplier financial instability, long lead times, counterfeit risk, sub-tier supplier control gaps. |
| 3 | Analyze Risks — Assess the likelihood and potential impact of each identified risk. Use qualitative or quantitative methods. | Analyze: single-source risk (high likelihood, high impact); financial instability (medium likelihood, high impact); lead time (medium likelihood, medium impact). |
| 4 | Evaluate Risks — Prioritize risks based on analysis results. Determine which risks require treatment and which are acceptable. | Evaluate: single-source and financial instability require immediate treatment; lead time requires monitoring. |
| 5 | Treat Risks — Develop and implement risk mitigation measures. Options include avoidance, reduction, transfer, or acceptance. | Treat: qualify alternative laminate supplier (avoidance); require financial guarantees (transfer); add lead time buffer (reduction). |
| 6 | Monitor and Review — Continuously monitor risks and the effectiveness of mitigation measures. Update risk assessments based on new information. | Monitor: track supplier financial health quarterly; monitor lead time performance; review alternative supplier qualification status. |
| 7 | Document and Communicate — Record risk assessment results, mitigation plans, and monitoring activities. Communicate risks to stakeholders, including customers. | Document risk register; include risk status in supplier performance reviews; communicate critical risks to customer. |
CRITICAL RULE:
Risk assessment must be documented and retained as documented information. Organizations must be able to demonstrate that risks were identified, analyzed, evaluated, treated, and monitored — and that the effectiveness of risk controls was evaluated per Clause 9.1.3.
5. PCB Supplier Risk Assessment Scenarios — Practical Examples
5.1 Laminate Supplier Risk Assessment
| Risk Category | Identified Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|---|
| Technical | Material Dk variation affecting impedance | Medium | High | Require material certification with lot-level Dk/Df data; conduct incoming impedance testing |
| Schedule | Long lead times (12+ weeks) for high-frequency materials | High | High | Place blanket orders; maintain safety stock; qualify second source |
| Economic | Supplier financial instability due to raw material cost increases | Medium | High | Review audited financials; require performance bond; diversify sourcing |
| Supply Chain | Single-source dependency for RO4350B material | High | Critical | Qualify alternative material; maintain 6-month safety stock; monitor supplier EOL notifications |
5.2 PCB Fabrication House Risk Assessment
| Risk Category | Identified Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|---|
| Quality | Inconsistent impedance control (historically ±10% vs requirement ±5%) | High | High | Require Cpk ≥ 1.33 for impedance; conduct FAI per GJB908; implement statistical process control monitoring |
| Schedule | Production capacity constraints during peak demand | Medium | High | Include capacity commitments in contract; maintain dual-source approval; provide long-term forecasts |
| Compliance | GJB9001C certification expires in 6 months | Low | Critical | Require re-certification 90 days before expiry; suspend orders if certification lapses |
| Geopolitical | Supply chain disruption risk due to trade restrictions | Medium | High | Diversify geographic sourcing; maintain inventory buffers; monitor regulatory changes |
5.3 Component Distributor Risk Assessment
| Risk Category | Identified Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|---|
| Supply Chain | Counterfeit component risk for obsolete parts | High | Critical | Require counterfeit prevention program per AS5553/AS6174; source only from authorized distributors; conduct incoming inspection |
| Economic | Price volatility for high-demand components | High | Medium | Include price adjustment clauses; secure long-term pricing agreements; consider last-time buys |
| Obsolescence | EOL notifications not communicated in time | Medium | High | Require 12-month EOL notice; maintain component lifecycle monitoring; establish PCN process |
6. Key Control Points in PCB Supplier Risk Assessment
6.1 Risk Assessment Integration
- Integrate risk assessment into supplier evaluation, selection, monitoring, and re-evaluation processes
- Ensure risk assessment is conducted before adding suppliers to the Approved Supplier List
- Include risk assessment results in supplier classification decisions
- Document risk assessment for every supplier, with updates based on performance changes
6.2 Risk Management Plan
- Develop risk management plans per Clause 8.1 requirements
- Include supplier-specific risks in the overall risk management plan
- Define risk treatment actions, responsibilities, and timelines
- Evaluate the effectiveness of risk control measures per Clause 9.1.3
6.3 Supplier Risk Monitoring
- Monitor supplier risks continuously through performance metrics (quality, delivery, cost, service)
- Update risk assessments based on new information (audit findings, nonconformances, financial changes)
- Communicate with suppliers identified for improvement and conduct follow-up management
- Remove non-performing suppliers from the Approved Supplier List
6.4 Counterfeit Risk Management
- Implement counterfeit prevention measures per AS5553 for electronic components and AS6174 for non-electronic products
- Source components only from authorized distributors
- Conduct incoming inspection and testing to verify authenticity
- Flow down counterfeit prevention requirements to sub-tier suppliers
6.5 Sub-tier Supplier Risk
- Require suppliers to control their direct and sub-tier suppliers
- Flow down risk assessment requirements to sub-tier suppliers
- Monitor sub-tier supplier risks through supplier reporting
- Include sub-tier control requirements in supplier contracts and quality agreements
6.6 Risk Documentation
- Maintain risk registers for all suppliers
- Document risk identification, analysis, evaluation, treatment, and monitoring activities
- Retain documented information of risk assessment activities per Clause 8.4.1
- Include risk status in supplier performance reviews and management reviews
7. Audit Preparation Checklist for PCB Manufacturers
| # | Check Item | Clause | Status | Notes |
|---|---|---|---|---|
| Risk Identification | ||||
| 1 | Supplier risks are systematically identified for all external providers | 8.4.1 | ☐ | |
| 2 | Risk identification covers technical, schedule, economic, quality, compliance, and supply chain risks | 8.1 | ☐ | |
| Risk Analysis and Evaluation | ||||
| 3 | Risks are analyzed for likelihood and impact | 8.1 | ☐ | |
| 4 | Risks are evaluated and prioritized for action | 8.1 | ☐ | |
| Risk Treatment | ||||
| 5 | Risk mitigation measures are defined and documented | 8.1 | ☐ | |
| 6 | Risk mitigation measures are implemented and verified | 8.1 | ☐ | |
| Risk Monitoring | ||||
| 7 | Risks are monitored and reviewed periodically | 8.1 | ☐ | |
| 8 | Risk registers are updated with current risk status | 8.1 | ☐ | |
| Risk Management Plan | ||||
| 9 | Risk management plan is established per Clause 8.1 | 8.1 | ☐ | |
| 10 | Risk control effectiveness is evaluated per Clause 9.1.3 | 9.1.3 | ☐ | |
| Integration with Supplier Management | ||||
| 11 | Risk assessment is integrated with supplier evaluation and selection | 8.4.1 | ☐ | |
| 12 | Risk assessment is included in performance monitoring and re-evaluation | 8.4.1 | ☐ | |
| Documentation | ||||
| 13 | Risk assessment records are retained as documented information | 8.4.1 | ☐ | |
| 14 | Risk information is communicated to relevant stakeholders | 8.4.3 | ☐ | |
8. Common Audit Findings and How to Avoid Them
| Finding | Why It Happens | How to Avoid |
|---|---|---|
| "No supplier risk assessment conducted" | Risk assessment not recognized as mandatory requirement | Implement documented supplier risk assessment process for all suppliers |
| "Risks identified but not analyzed or evaluated" | Risk identification not followed by analysis and prioritization | Apply risk analysis matrix; evaluate likelihood and impact; prioritize for action |
| "No risk mitigation measures implemented" | Risks identified but not treated | Define and implement risk mitigation actions; verify effectiveness |
| "Risk assessment not integrated with supplier management" | Risk assessment conducted separately from supplier evaluation | Integrate risk assessment into supplier evaluation, selection, monitoring, and re-evaluation |
| "No risk management plan" | Risk management not formalized per Clause 8.1 | Develop risk management plan; include supplier risks; implement and monitor |
| "Risks not monitored or reviewed" | One-time risk assessment without ongoing monitoring | Implement periodic risk review; update risk registers; monitor risk status |
| "No documented information of risk assessment" | Risk assessment conducted but not documented | Document all risk assessment activities; retain records as documented information |
9. Frequently Asked Questions
Is supplier risk assessment mandatory under GJB9001C?
Yes. Clause 8.4.1 explicitly requires organizations to "ensure effective identification and control of risks" when selecting and evaluating external providers.This is a mandatory requirement, not optional.
What risks must be assessed for suppliers?
Organizations must assess risks across multiple dimensions: technical, schedule, economic/financial, quality, compliance, supply chain, geopolitical, and obsolescence risks.
When should supplier risk assessment be conducted?
Risk assessment should be conducted at multiple points: during initial supplier evaluation and selection, during ongoing performance monitoring, during re-evaluation, and whenever significant changes occur.
How should risks be analyzed and evaluated?
Risks should be analyzed for likelihood and potential impact, then evaluated to determine priority. A risk matrix (likelihood × impact) can be used to classify risks as low, medium, high, or critical.
What is a risk management plan?
A risk management plan documents the risk identification, analysis, evaluation, treatment, monitoring, and review activities. Clause 8.1 requires organizations to "develop risk management plans and implement risk control measures."
How does supplier risk assessment relate to the Approved Supplier List?
Risk assessment results should inform supplier classification and AVL status. High-risk suppliers may require enhanced monitoring, while critical-risk suppliers may be removed from the AVL.
What is the role of customers in supplier risk assessment?
Organizations shall invite customers to participate in the evaluation and selection of external providers of interest to them.[reference:44] This includes sharing risk assessment information.
What documented information must be retained for supplier risk assessment?
Organizations must retain: risk identification records, risk analysis and evaluation records, risk treatment plans, risk monitoring records, and evidence of risk control effectiveness evaluation.
Related Standards & Topics
PCB Manufacturing for Military and Aerospace Programs
UltroNiu Electronics Group provides PCB and PCBA manufacturing services under GJB9001C-compliant supplier risk assessment and management. Contact our engineering team for program-specific supply chain risk management requirements.
Request Engineering ReviewReferences: GJB9001C-2017 Clauses 8.1, 8.4, 8.4.1, 9.1.3 (Central Military Commission Equipment Development Department). Supplier risk assessment requirements sourced from GJB9001C-2017 Clause 8.4.1. Risk management framework requirements sourced from GJB9001C-2017 Clause 8.1. Supplier risk management practices sourced from industry implementation of GJB9001C requirements. Counterfeit risk management guidance based on AS5553 and AS6174 standards. PCB-specific risk factors based on industry best practices for military and aerospace PCB manufacturing. Courtesy of UltroNiu Engineering Knowledge Center.
Get Custom Quote
PRODUCTS CENTER


