Article 50 requires risk identification, risk assessment, measurable mitigation, monitoring, and reporting back to top management. Ask for the current risk register, active mitigation plan, supplier escalation criteria, and how failed mitigation triggers suspension or disengagement. Also ask for any notified body verification or supplier level verification reports the operator may rely on.
The goal is to see whether the supplier can support the operator own risk management plan, not merely state that it complies with OECD guidance.