Talk to us

Supply chain and procurement risk management

Most organisations discover their supply chain risk the same way: a supplier fails, and only then does anyone establish that it was the sole source for something the operation cannot run without.

10-25%cost savingsacross managed categories
50-75%faster cyclesin sourcing and tendering
90%+supplier performanceimprovement on managed vendors
100%policy compliancedocumented and audit ready

The problem this solves

Risk registers are built around what is easy to name rather than what is likely to hurt. Currency and commodity price appear because they are measurable. Single points of failure deep in the supply base do not appear at all, because nobody has mapped past tier one.

Supplier financial health is checked at onboarding and never again, so a vendor can deteriorate for two years before anyone notices, usually at the point of failure.

Contingency plans exist as documents rather than as capability. Nobody has established whether the alternate supplier could actually take the volume, at what price, or how long qualification would take.

What we actually do

The steps, in the order we run them.

How the engagement runs1Map the supply base2Score exposure honestly3Stress test the assumptions4Mitigate by priority5Monitor continuously
  1. Map the supply base

    Tier one, and tier two wherever the exposure justifies it. The objective is to find concentration you did not know you had, including different suppliers who depend on the same upstream source.

  2. Score exposure honestly

    Each supplier is scored on operational criticality, substitutability, financial health, geographic and geopolitical concentration and compliance exposure. Criticality is judged by what stops if they stop, not by spend, because the cheapest supplier is often the one that halts production.

  3. Stress test the assumptions

    We test the contingency plan rather than reading it. Could the named alternate take the volume? At what price? How long to qualify? Plans that fail this test are plans in name only.

  4. Mitigate by priority

    Dual sourcing where it is justified, qualified alternates where it is not, contractual protections, buffer stock where the economics work, and exit provisions written before you need them.

  5. Monitor continuously

    Financial health monitoring, performance triggers and defined escalation thresholds, so deterioration surfaces while there is still time to act rather than at the point of failure.

What you get

The concentration that matters is rarely where clients expect it. The recurring finding is a low-value, sole-source supplier of something operationally critical, sitting well below the threshold that would have attracted procurement attention on spend alone.

Supplier exposure by criticality and substitutabilitySingle point of failureQualify an alternate beforeyou need one.Manage closelyCritical but replaceable. Keepthe alternate warm.Monitor onlyLow impact, easily replaced.Review annually.Watch the marketReplaceable and low impact,but track price and capacity.How easily the supplier can be replacedHow much stops if they stop
Criticality is what stops if they stop, not what you spend. Low-spend suppliers regularly sit top-left.

Questions we get asked

How far down the supply chain should we map?

As far as the exposure justifies and no further. Tier one for everything, tier two for categories where an upstream failure stops your operation. Mapping every tier of every category costs more than the risk it retires.

How do you score supplier risk?

On operational criticality, substitutability, financial health, geographic and geopolitical concentration, and compliance exposure. Criticality is weighted by what stops if the supplier stops, which is why low-spend suppliers regularly appear at the top of the register.

Is dual sourcing always the answer?

No. It costs volume leverage and adds management overhead, and for many categories a qualified alternate you could switch to in weeks is better value than a second supplier you keep active. The decision should be made per category, on the economics.

How often should the risk register be reviewed?

Quarterly for critical suppliers, annually for the rest, and immediately on a trigger event such as a missed delivery pattern, a credit rating change or a change of ownership. A register reviewed once a year is a compliance artefact rather than a management tool.

Where to start

Run the free procurement maturity diagnostic for a scored view of where the gaps are, or talk to a consultant about this specific problem. Both take less time than a meeting about having a meeting.

Talk to a consultant