A missed delivery, a quality failure, a non-conformance: most organizations already have a defined supplier risk management process for this. An NCR gets logged, which can escalate into a CAR if it is not resolved, which can escalate further into a PIP if the pattern continues.
The three stages, briefly
- —NCR (Non-Conformance Report). A specific instance is documented: what happened, on which order, against which specification.
- —CAR (Corrective Action Request). If the NCR is not isolated, the supplier is formally asked to identify the root cause and fix it.
- —PIP (Performance Improvement Plan). If the pattern continues past the CAR, a structured plan with milestones and a defined consequence if it fails.
Where this breaks down in practice
The process itself is rarely the problem. Where it live is. NCRs get logged in one system, CARs get tracked over email, and by the time a sourcing decision comes up again, none of that history is visible to the buyer deciding whether to award more business to that supplier. A supplier can accumulate multiple NCRs without that pattern ever surfacing at the moment it would actually change a decision.
What fixes it
Not a better email folder. Effective supplier risk management means corrective action history lives on the same supplier record a buyer sees during sourcing and evaluation, so the pattern is visible exactly when it matters, not reconstructed after the fact when someone finally goes looking for it.
