Supply chain risk management

Supply chain risk programs usually fail at the first step rather than the last. Without a defensible method for deciding which suppliers are critical, everything downstream, from questionnaires to tiering, monitoring and continuity planning, gets applied evenly across hundreds of vendors and therefore properly to none of them.

The sequence here starts with critical supplier identification and tiering methodology, then moves to scoring and monitoring supplier performance, building a supply chain risk heat map, and framework implementation under NIST SP 800-161 for C-SCRM and ISO 28000. Contracting is covered through vendor agreement clauses and a risk based scoring framework for evaluating proposals, and there is a supply chain continuity plan for the point at which a supplier actually stops delivering. AI vendors get separate treatment, because the assessment questions differ.

For the vendor relationship itself see third-party risk, and for disruption response business continuity management and operational risk.

Receive the latest articles in your inbox