Risk Center

A Framework for Supplier Risk: Internal vs External

By Laurits Aae Mouritsen, Founder · July 2026 · 735-word read

Key takeaways

  • Supplier risk is easier to manage when you sort it: external vs internal (is the risk in the supplier's environment or the supplier itself), and soft vs hard (qualitative signals vs hard data).
  • External risks — geopolitics, climate, conflict — act on the supplier from outside; you monitor the world around each supplier's locations.
  • Internal soft risks — reputation, ownership, cyber — are qualitative signals about the supplier that resist a single number.
  • Internal hard risks — financial and operational — are quantifiable, but only if you can find and trust the underlying data.

"Supplier risk" is a single phrase covering wildly different things — a coup, a bankruptcy, a data breach, a reputational scandal, a flood. Trying to manage them all with one method fails, because they do not behave alike. A useful framework, drawn from the research Intellens was built on — its founder's master's thesis at Copenhagen Business School — sorts supplier risk along two axes: whether the risk is external or internal to the supplier, and whether the signal is soft or hard. The two axes together turn a vague worry into a manageable map.

The point of the framework is not taxonomy for its own sake. Each quadrant needs a different kind of monitoring, a different data source, and a different response — and knowing which quadrant a risk lives in tells you how to watch for it.

External risk: the world around the supplier

External risks act on a supplier from the outside: geopolitical instability, armed conflict, climate and natural-catastrophe events, energy and infrastructure shocks, regulatory and sanctions changes. The supplier may be perfectly well-run and still be hit, because the risk originates in its environment, not its conduct.

The defining feature of external risk is that it is tied to place. A supplier's exposure depends on where its factories, ports, and logistics routes actually sit — which is why external-risk monitoring is inseparable from supplier location intelligence. You are, in effect, watching the world around each of your suppliers' real locations and asking whether anything there threatens supply.

Internal soft risk: the qualitative signals

Internal risks come from the supplier itself, and they split by how measurable they are. Soft risks are the qualitative ones: reputation, conduct, ownership and shareholder structure, and cybersecurity posture. A supplier accused of labour abuses, quietly acquired by a sanctioned party, or breached by ransomware is carrying internal soft risk — real and material, but resistant to a single tidy number.

Soft risk is where open-source intelligence earns its keep, because the signal lives in language and relationships rather than in a spreadsheet: adverse media, beneficial-ownership structures, sanctions and watchlists, and disclosure records. Monitoring soft risk means reading and resolving those signals continuously, not scoring a form once a year.

Internal hard risk: the quantifiable core

Hard risks are the quantifiable internal ones: financial health, solvency, and operational metrics — the datapoints that, in principle, reduce to numbers. A supplier drifting toward insolvency or missing operational thresholds is carrying internal hard risk.

The catch is that "quantifiable" does not mean "available." For many suppliers, especially private ones and those deep in the tiers, the hard data is incomplete or unverified, and self-reported figures cannot be taken at face value. Hard-risk monitoring is therefore as much about finding and corroborating the data — from filings, registries, and public signals — as it is about the arithmetic once you have it.

Why the framework matters in practice

Sorted this way, a supplier is not "risky" or "safe" — it has a profile across the quadrants, and each quadrant is monitored differently: external risk by watching the supplier's locations, soft risk by reading open-source signals, hard risk by finding and corroborating data. A serious platform has to cover all of them, because a supplier that is clean on hard financials can be carrying severe external or soft risk that a financials-only view would miss entirely.

This is the logic behind how Intellens is organised, and it traces directly back to the founder's research. To see the framework applied to your own supplier network, request a demo, or read related pieces in the Risk Center.

Frequently asked questions

What is the difference between external and internal supplier risk?

External risk originates in the supplier's environment — geopolitics, climate, conflict, sanctions — and acts on the supplier from outside. Internal risk originates in the supplier itself, such as its finances, conduct, ownership, or cybersecurity.

What are soft vs hard supplier risks?

Soft risks are qualitative and resist a single number — reputation, ownership, conduct, cyber. Hard risks are quantifiable — financial health, solvency, operational metrics — though the underlying data is often hard to obtain and verify.

Why use a framework instead of one risk score?

Because the categories behave differently and need different monitoring and data. A single blended score hides the fact that a supplier can be strong on hard financials while carrying severe external or reputational risk.

Where does this framework come from?

From the research Intellens was built on — its founder's master's thesis on OSINT in supply chain risk management at Copenhagen Business School (2024).

About the author

Laurits Aae Mouritsen is the founder of Intellens. His master's thesis at Copenhagen Business SchoolOpen Source Intelligence (OSINT) in Supply Chain Risk Management (Cand.merc.it., 2024) — built software to gather intelligence on hundreds of millions of companies and automatically analyse supplier risk across a supply network. Intellens is that research put into practice. More on the about page · LinkedIn.

Published 2026-07-08 · Back to the Risk Center