Supply chain risk arises when objectives depend on external organizations, sub-suppliers, logistics, contracts, information, facilities, or scarce capabilities. Outsourcing activity does not outsource accountability for outcomes.
Understand the dependency
Identify what is supplied, why it is critical, acceptable interruption, alternatives, lead times, data or access provided, and consequences of failure. Map important sub-tier dependencies where practical.
Assess more than financial strength
- Operational capability and capacity
- Quality and performance history
- Concentration and geographic exposure
- Information handling at a high level
- Compliance and contractual obligations
- Continuity and recovery capability
- Subcontracting and fourth parties
- Exit and transition feasibility
Use proportionate due diligence
Apply deeper review to critical or high-risk relationships. Standard questionnaires can support consistency, but evidence, site visits, testing, references, and contract-specific review may be needed.
Monitor throughout the relationship
Track performance, incidents, attestations, ownership changes, concentration, unresolved issues, and scope changes. Reassess before renewal or major change.
Plan for failure
Define communication, inventory or capacity buffers, alternate suppliers, data return, access revocation, transition support, emergency authority, and recovery priorities. Test important arrangements rather than relying only on contract wording.
Map dependency beyond the direct supplier
A contract with a reliable first-tier supplier may still depend on a single manufacturer, transport route, cloud service, raw material, location, or specialized workforce. Mapping critical products and services, sub-tier dependencies, lead times, alternatives, and switching barriers can reveal concentration hidden by a long supplier list.
Use ongoing evidence
Pre-contract due diligence is only a starting point. Monitor service performance, quality, financial or operational warning signs, security and continuity commitments where relevant, ownership changes, geographic exposure, unresolved audit findings, and concentration. Information requirements should be proportionate and contractually supportable.
Third-party review prompts
- Which objective or service depends on this supplier?
- How long would substitution or recovery take?
- What information and audit rights are available?
- Are responsibilities clear during an incident?
- What dependencies remain after insurance or contractual transfer?