Third‑Party Risk: Supply Chain’s Most Dangerous Blind Spot

BY MARY LOU JAY

EVALUATING THIRD‑PARTY VENDOR risks is standard procedure for supply chain organizations. But the risk assessment processes that have been used for years are no longer effective. Best practices for supply chain companies should now include continual monitoring of the financial stability, operational reliability and cybersecurity practices of all critical suppliers down the supply chain. Risk assessments should also incorporate geopolitical, weather‑related and regulatory requirements that may affect suppliers’ ability to deliver products and services.

“As supply chains become more complex and dynamic, most companies simply don’t have the visibility needed to understand how data, systems and risk move across thousands of external relationships in real time—much less their own internal systems,” said Adrienne Canter, senior director of governance, risk and compliance at OneTrust.

To avoid disruptions, supply chain companies are reexamining the ways that they prioritize third‑party risks and evaluating new technologies that can make them more effective in monitoring and addressing them.

MAPPING THE VENDOR ECOSYSTEM

In the past, supply chain companies have primarily focused on their primary and secondary vendors for in‑depth risk assessments.

To determine their priorities today, organizations need to understand how the goods or services that a vendor provides impact their business goals or organizational resiliency, according to Scott Bridgen, general manager for the risk and audit business unit at Diligent. They should ask themselves if a problem with a vendor is going to stop the company from doing what the board, shareholders or customers expect it to do. Would it impact the organization’s ability to operate? If the vendor of a customer relationship management (CRM) system goes offline, what happens to their organization’s ability to process sales or provide essential customer service?

It’s not only disruptions of first‑and second‑tier vendors that can cause this type of disruption, however. That’s why it’s essential to determine the risks with other vendors further down the supply chain.

Scott Lehmann, VP at Sphera, believes that warehouse or logistics operations should approach risk assessment in a new way, building risk programs around the physical equipment and components that run the facility rather than around vendor relationships.

“Most companies assess third‑party risk as a vendor scoring exercise: is this company financially sound, compliant, contractually reliable? That framing misses the physical reality of what actually keeps a warehouse running,” he said. “A warehouse facility can fully vet the conveyor OEM as a company and still have no visibility into the motor manufacturer behind it, the bearing supplier or the single plant that produces a proprietary drive component.”

“The overlooked danger is that physical equipment such as conveyors, forklifts, racking, dock levelers and Automated Storage and Retrieval Systems (AS/RS) are built from components sourced several tiers deep. A facility’s risk exposure runs through that physical bill of materials, not through the vendor contract sitting on file,” Lehmann said. To assess risks, companies should have visibility into the vendors that supply the batteries, motors, chains or hydraulic parts that make up that equipment.

He recommends that companies start by mapping physical equipment down to the component level. For a conveyor system, that means knowing the motor manufacturer, the drive component supplier and where those parts are actually made. For a forklift fleet, it means knowing the battery and hydraulic component sourcing behind the OEM nameplate. For trailers and tractors, it means understanding the tiered suppliers behind the trailer or truck manufacturer, aluminum, brakes, suspension and axles, not just the OEM itself.

Supply chain organizations should be monitoring that equipment and component base continuously, watching for plant closures, material shortages, geopolitical exposure or natural hazards affecting the physical supply chain behind the machines, Lehmann said. The next step is to build a response process specific to physical assets: if a critical part becomes unavailable, who identifies alternate sourcing, who assesses which equipment or lines are affected and how fast can that be executed.

UNDERSTANDING TODAY’S RISKS

The types of risks that can impact supply chain operations have been changing over the years.

Cybersecurity is a primary concern. AI has made it possible for cyber attackers to go on autopilot when it comes to developing and implementing new ways to attack their targets’ cyber infrastructures. But there are other tech issues as well.

“Most organizations focus on supplier availability and financial viability but underestimate the operational dependency risks associated with critical technology vendors,” said Guilherme Severino, executive director, EY Consulting. With a disruption to a third‑party technology vendor, companies might lose access to software updates, remote support, cloud services and documentation, source code and other operational knowledge needed to maintain systems independently. Those risks may be greater if their technology is supported by a small number of individuals, support teams or offshore delivery centers, or if the OEM controls the upgrade, maintenance or release processes.

“Many companies assume a vendor relationship will remain available indefinitely and do not adequately plan for sudden disruptions,” Severino said.

Risk managers must also factor in the increasing number of weather‑related disasters, including storms and fires, and the constantly changing geopolitical situations that can impact vendors’ ability to supply them. With the closure of the Straits of Hormuz, for example, many companies came to realize that their petrochemical supply chains run through the Persian Gulf, according to Lehmann. One material shipped through that waterway was naphtha; when Asian commodity plastics producers had their supply cut off, it impacted the availability of everything from resins and inks to medical gloves and IV bags.

Regulatory risks are also increasing, as governments throughout the world are holding the companies that buy from vendors responsible for ensuring that those vendors comply with environmental, labor, materials sourcing and other regulations. Although they may not affect a company’s ability to operate, reputational risks, such as vendors using child labor, can influence customers’ perceptions of a company and their willingness to do business with them.

Click here to read the full article.