Home / Guides / Supply Chain and Third-Party Risk
Guide

Supply Chain and Third-Party Risk

A general framework for dependency, concentration, performance, continuity, and oversight risk.

By Adrian M. FenwickReviewed August 3, 2026

Supply chain risk arises when objectives depend on external organizations, sub-suppliers, logistics, contracts, information, facilities, or scarce capabilities. Outsourcing activity does not outsource accountability for outcomes.

Understand the dependency

Identify what is supplied, why it is critical, acceptable interruption, alternatives, lead times, data or access provided, and consequences of failure. Map important sub-tier dependencies where practical.

Assess more than financial strength

  • Operational capability and capacity
  • Quality and performance history
  • Concentration and geographic exposure
  • Information handling at a high level
  • Compliance and contractual obligations
  • Continuity and recovery capability
  • Subcontracting and fourth parties
  • Exit and transition feasibility

Use proportionate due diligence

Apply deeper review to critical or high-risk relationships. Standard questionnaires can support consistency, but evidence, site visits, testing, references, and contract-specific review may be needed.

Monitor throughout the relationship

Track performance, incidents, attestations, ownership changes, concentration, unresolved issues, and scope changes. Reassess before renewal or major change.

Plan for failure

Define communication, inventory or capacity buffers, alternate suppliers, data return, access revocation, transition support, emergency authority, and recovery priorities. Test important arrangements rather than relying only on contract wording.

Use with judgmentRisk methods support decisions; they do not remove uncertainty. Record assumptions, limits, and acceptance authority.

Map dependency beyond the direct supplier

A contract with a reliable first-tier supplier may still depend on a single manufacturer, transport route, cloud service, raw material, location, or specialized workforce. Mapping critical products and services, sub-tier dependencies, lead times, alternatives, and switching barriers can reveal concentration hidden by a long supplier list.

Use ongoing evidence

Pre-contract due diligence is only a starting point. Monitor service performance, quality, financial or operational warning signs, security and continuity commitments where relevant, ownership changes, geographic exposure, unresolved audit findings, and concentration. Information requirements should be proportionate and contractually supportable.

Third-party review prompts

  • Which objective or service depends on this supplier?
  • How long would substitution or recovery take?
  • What information and audit rights are available?
  • Are responsibilities clear during an incident?
  • What dependencies remain after insurance or contractual transfer?