<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="https://riskpublishing.com/wp-content/plugins/pretty-rss-feeds/xslt/pretty-feed.xsl" type="text/xsl" media="screen" ?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Supply chain risk management &#8211; Risk Publishing</title>
	<atom:link href="https://riskpublishing.com/supply-chain-risk-management/feed/" rel="self" type="application/rss+xml" />
	<link>https://riskpublishing.com</link>
	<description>Connecting Risk Professionals</description>
	<lastBuildDate>Fri, 14 Aug 2026 13:23:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://riskpublishing.com/wp-content/uploads/2021/12/cropped-favicon2-32x32.png</url>
	<title>Supply chain risk management &#8211; Risk Publishing</title>
	<link>https://riskpublishing.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Critical Supplier Identification and Tiering Methodology</title>
		<link>https://riskpublishing.com/critical-supplier-identification-tiering/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 15:57:38 +0000</pubDate>
				<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Supply chain risk management]]></category>
		<category><![CDATA[Critical Supplier]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=37008</guid>

					<description><![CDATA[At 12:09 a.m. Eastern on July 19, 2024, a faulty CrowdStrike Falcon update began knocking 8.5 million Windows devices offline, and Delta Air Lines spent the next five days canceling roughly 7,000 flights. Chief executive Ed Bastian put the bill at $500 million, and Delta sued CrowdStrike that October. By procurement&#8217;s math, CrowdStrike was a ... <a title="Critical Supplier Identification and Tiering Methodology" class="read-more" href="https://riskpublishing.com/critical-supplier-identification-tiering/" aria-label="Read more about Critical Supplier Identification and Tiering Methodology">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Supply Chain Risk Heat Map: How to Build and Maintain One</title>
		<link>https://riskpublishing.com/supply-chain-risk-heat-map/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Mon, 06 Jul 2026 16:12:09 +0000</pubDate>
				<category><![CDATA[Supply chain risk management]]></category>
		<category><![CDATA[Supply Chain Risk Heat Map]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=36994</guid>

					<description><![CDATA[At 1:29 a.m. on March 26, 2024, the container ship Dali lost power and brought down Baltimore&#8217;s Francis Scott Key Bridge, closing the top US auto port for 11 weeks. Maryland lost roughly $15 million a day, and almost no supply chain risk heat map in the country had that bridge on it. The gap ... <a title="Supply Chain Risk Heat Map: How to Build and Maintain One" class="read-more" href="https://riskpublishing.com/supply-chain-risk-heat-map/" aria-label="Read more about Supply Chain Risk Heat Map: How to Build and Maintain One">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>NIST Supply Chain Risk Management: A C-SCRM Guide to SP 800-161</title>
		<link>https://riskpublishing.com/nist-supply-chain-risk-management-a-c-scrm-guid/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 14:44:58 +0000</pubDate>
				<category><![CDATA[Supply chain risk management]]></category>
		<category><![CDATA[NIST AI RMF vs EU AI Act]]></category>
		<category><![CDATA[NIST CSF Risk Assessment]]></category>
		<category><![CDATA[NIST Supply Chain Risk Management]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=36908</guid>

					<description><![CDATA[In December 2020, the security firm FireEye traced its own breach to an unlikely source: a routine software update from SolarWinds, a network-monitoring vendor trusted inside thousands of corporate and government networks. Attackers had hidden a backdoor, later named SUNBURST, in the Orion update itself. About 18,000 organizations installed the poisoned update, and roughly nine ... <a title="NIST Supply Chain Risk Management: A C-SCRM Guide to SP 800-161" class="read-more" href="https://riskpublishing.com/nist-supply-chain-risk-management-a-c-scrm-guid/" aria-label="Read more about NIST Supply Chain Risk Management: A C-SCRM Guide to SP 800-161">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Supplier Performance Risk Management: How to Score and Monitor Vendor Risk</title>
		<link>https://riskpublishing.com/supplier-performance-risk-management-how-to/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 10:43:00 +0000</pubDate>
				<category><![CDATA[Supply chain risk management]]></category>
		<category><![CDATA[Supplier Performance Risk Management]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=36876</guid>

					<description><![CDATA[On July 1, 2024, Boeing agreed to buy back Spirit AeroSystems for roughly $4.7 billion in equity, an $8.3 billion enterprise value with debt, six months after a door plug blew off a 737 MAX 9 on Alaska Airlines Flight 1282. Spirit built that fuselage. The reacquisition was supplier performance risk management in reverse: a ... <a title="Supplier Performance Risk Management: How to Score and Monitor Vendor Risk" class="read-more" href="https://riskpublishing.com/supplier-performance-risk-management-how-to/" aria-label="Read more about Supplier Performance Risk Management: How to Score and Monitor Vendor Risk">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Supply Chain Risk Management: ISO 28000 and NIST Practitioner Guide</title>
		<link>https://riskpublishing.com/supply-chain-risk-management-iso-28000/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Wed, 08 Apr 2026 13:20:15 +0000</pubDate>
				<category><![CDATA[Supply chain risk management]]></category>
		<category><![CDATA[ISO 28000 and NIST Practitioner Guide]]></category>
		<category><![CDATA[Supply Chain Risk Management]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=34120</guid>

					<description><![CDATA[When the CrowdStrike outage hit in July 2024, Fortune 500 companies absorbed more than $5 billion in direct losses within days. The incident did not originate inside any of those companies&#8217; supply chains in the traditional sense; it came through a single software update pushed by a trusted cybersecurity vendor. For risk managers who had ... <a title="Supply Chain Risk Management: ISO 28000 and NIST Practitioner Guide" class="read-more" href="https://riskpublishing.com/supply-chain-risk-management-iso-28000/" aria-label="Read more about Supply Chain Risk Management: ISO 28000 and NIST Practitioner Guide">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Best Internal Audit Management Software Compared: Top Platforms for 2026</title>
		<link>https://riskpublishing.com/best-internal-audit-management-software-compa/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Mon, 23 Mar 2026 14:33:33 +0000</pubDate>
				<category><![CDATA[Governance, Risk & Compliance]]></category>
		<category><![CDATA[Supply chain risk management]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=33344</guid>

					<description><![CDATA[Key Takeaways The internal audit management software market is projected to reach $6.0 billion by 2033 (Persistence Market Research), growing at 15.4% CAGR as regulatory complexity, AI adoption, and cloud migration drive investment in modern audit technology. AuditBoard leads the market with a 9.5/10 G2 rating for audit workflow, while Workiva dominates SOX and financial ... <a title="Best Internal Audit Management Software Compared: Top Platforms for 2026" class="read-more" href="https://riskpublishing.com/best-internal-audit-management-software-compa/" aria-label="Read more about Best Internal Audit Management Software Compared: Top Platforms for 2026">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Best Third-Party Risk Management Software: 12 Top TPRM Platforms Compared for 2026</title>
		<link>https://riskpublishing.com/best-third-party-risk-management-tprm-software/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Mon, 23 Mar 2026 12:53:43 +0000</pubDate>
				<category><![CDATA[Information security management system]]></category>
		<category><![CDATA[Supply chain risk management]]></category>
		<category><![CDATA[Best Third-Party Risk Management Software]]></category>
		<category><![CDATA[enterprise risk management]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[third party risk assessment]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=33320</guid>

					<description><![CDATA[In February 2024, the ransomware crew ALPHV/BlackCat breached Change Healthcare, a UnitedHealth Group subsidiary that clears roughly one in three U.S. medical claims. Pharmacies and hospitals nationwide stopped getting paid for weeks. UnitedHealth later estimated that 190 million people were affected and booked about $2.46 billion in direct response costs. It remains the most expensive ... <a title="Best Third-Party Risk Management Software: 12 Top TPRM Platforms Compared for 2026" class="read-more" href="https://riskpublishing.com/best-third-party-risk-management-tprm-software/" aria-label="Read more about Best Third-Party Risk Management Software: 12 Top TPRM Platforms Compared for 2026">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Best Vendor Risk Management Platforms Compared</title>
		<link>https://riskpublishing.com/best-vendor-risk-management-platforms-compared/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Thu, 19 Mar 2026 08:38:38 +0000</pubDate>
				<category><![CDATA[Information security management system]]></category>
		<category><![CDATA[Supply chain risk management]]></category>
		<category><![CDATA[Third-Party Risk Management]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=33235</guid>

					<description><![CDATA[Key Takeaways The vendor risk management software market reached $12.3 billion in 2025 and is projected to exceed $39 billion by 2033, driven by DORA, OCC interagency guidance, and rising third-party breach costs. Third-party breaches doubled from 15% to 30% of all incidents between 2020 and 2025 (Verizon DBIR), with average costs reaching $4.91 million ... <a title="Best Vendor Risk Management Platforms Compared" class="read-more" href="https://riskpublishing.com/best-vendor-risk-management-platforms-compared/" aria-label="Read more about Best Vendor Risk Management Platforms Compared">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>AI Vendor Risk Assessment: Evaluating Third-Party AI Tools</title>
		<link>https://riskpublishing.com/ai-vendor-risk-assessment-evaluating-third-part/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Thu, 05 Mar 2026 17:22:58 +0000</pubDate>
				<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Supply chain risk management]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=32679</guid>

					<description><![CDATA[Key Takeaways ✓ Third-party breaches doubled from 15% to 30% of all incidents in 2025 (Verizon DBIR), and supply chain compromise now costs an average of $4.91 million per breach (IBM), making a structured AI Vendor Risk Assessment non-negotiable. ✓ An AI vendor risk assessment extends traditional third-party risk management (TPRM) to cover model governance, ... <a title="AI Vendor Risk Assessment: Evaluating Third-Party AI Tools" class="read-more" href="https://riskpublishing.com/ai-vendor-risk-assessment-evaluating-third-part/" aria-label="Read more about AI Vendor Risk Assessment: Evaluating Third-Party AI Tools">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Supply Chain Business Continuity Plan: A Complete Guide with Templates</title>
		<link>https://riskpublishing.com/supply-chain-business-continuity-plan-a-comple/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Tue, 24 Feb 2026 18:30:01 +0000</pubDate>
				<category><![CDATA[Business Continuity Plan]]></category>
		<category><![CDATA[Supply chain risk management]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=32470</guid>

					<description><![CDATA[In 2025, 94 percent of companies reported that supply chain disruptions negatively affected their revenue. Only 6 percent had full visibility into their supply chains. And according to McKinsey&#8217;s Supply Chain Risk Pulse survey, 82 percent of respondents said new tariffs affected their supply chains, with 20 to 40 percent of their supply chain activity ... <a title="Supply Chain Business Continuity Plan: A Complete Guide with Templates" class="read-more" href="https://riskpublishing.com/supply-chain-business-continuity-plan-a-comple/" aria-label="Read more about Supply Chain Business Continuity Plan: A Complete Guide with Templates">Read more</a>]]></description>
		
		
		
			</item>
	</channel>
</rss>
