There are two distinct supplier risk assessment cycles, one is when you select a new supplier and the other is an ongoing risk evaluation which occurs during supplier ongoing performance evaluation. Look at the potential risks with the supplier which impact your customer ultimately: On Time delivery, quality levels, criticality of the product, volume etc. You can evaluate the supplier based on risk for each of these. You can then prioritize the supplier development to meeting the IATF requirements. Set a threshold for action, if a supplier is higher than a certain risk level, begin development with them. The first step should be ISO 9001 Compliance or certification. This can be done over time beginning with steps such as using portions of the MAQMSR (Minimum Quality Management System Requirements) published by the IATF.