---
# === IDENTITY ===
id: business/operations/supply-chain-risk-mapping/2026
canonical_question: "How do I map and score supply chain risk — single-source dependencies and mitigation strategies?"
aliases:
  - "supply chain risk assessment"
  - "supplier risk scoring"
  - "single source dependency analysis"
  - "supply chain resilience framework"
entity_type: concept
domain: business > operations > Supply Chain Risk Mapping
region: global
jurisdiction: global
temporal_scope: 2020-2026

# === VERIFICATION ===
last_verified: 2026-02-28
confidence: 0.89
version: 1.0
first_published: 2026-02-28

# === TEMPORAL VALIDITY ===
temporal_validity:
  status: evolving
  last_breaking_change: "2024-01-01"
  next_review: 2026-08-27
  change_sensitivity: high

# === CONSTRAINTS ===
constraints:
  - "Most companies have visibility only into tier-1 suppliers — sub-tier risk is invisible without active mapping"
  - "Risk scoring is subjective without standardized data — different assessors will score the same supplier differently"
  - "Mitigation strategies (dual sourcing, nearshoring) increase cost 15-40% — risk reduction is not free"
  - "Geopolitical risks (tariffs, sanctions) change faster than most risk frameworks can update"
  - "Risk maps are point-in-time snapshots that degrade — quarterly reviews are necessary to maintain accuracy"

skip_this_unit_if:
  - condition: "User needs procurement strategy or vendor selection, not risk assessment"
    use_instead: "business/operations/procurement-strategy/2026"
  - condition: "User needs inventory management to buffer against supply disruption"
    use_instead: "business/operations/inventory-management/2026"
  - condition: "User needs process improvement methodology, not supply chain analysis"
    use_instead: "business/operations/lean-six-sigma/2026"

inputs_needed:
  - key: "risk_scenario"
    question: "What supply chain risk scenario is the user addressing?"
    type: choice
    options: ["Identifying single-source dependencies", "Scoring and prioritizing supplier risks", "Building a mitigation strategy for critical suppliers", "Assessing geopolitical or tariff impact on supply chain"]

# === DISTRIBUTION ===
canonical_source: "https://knowledgelib.io/business/operations/supply-chain-risk-mapping/2026"
suggested_citation: "Source: knowledgelib.io — AI Knowledge Library (verified 2026-02-28)"

# === RELATED UNITS ===
related_kos:
  related_to:
    - id: "business/operations/procurement-strategy/2026"
      label: "Procurement Strategy"
    - id: "business/operations/inventory-management/2026"
      label: "Inventory Management"
  often_confused_with: []
  depends_on: []
  solves: []
  alternative_to: []

# === SOURCES ===
sources:
  - id: src1
    title: "Supply Chain Risk Pulse 2025: Tariffs Reshuffle Global Trade Priorities"
    author: McKinsey & Company
    url: https://www.mckinsey.com/capabilities/operations/our-insights/supply-chain-risk-survey
    type: industry_report
    published: 2025-06-01
    reliability: authoritative
  - id: src2
    title: "A Practical Approach to Supply-Chain Risk Management"
    author: McKinsey & Company
    url: https://www.mckinsey.com/capabilities/operations/our-insights/a-practical-approach-to-supply-chain-risk-management
    type: industry_report
    published: 2022-05-01
    reliability: authoritative
  - id: src3
    title: "McKinsey Global Supply Chain Leader Survey 2024"
    author: McKinsey & Company
    url: https://www.mckinsey.com/capabilities/operations/our-insights/supply-chain-risk-survey-2024
    type: primary_research
    published: 2024-09-01
    reliability: authoritative
  - id: src4
    title: "Key Supply Chain Risks for 2025 and Proactive Strategies"
    author: SupplyChains Magazine
    url: https://supplychains.com/key-supply-chain-risks-for-2025-and-proactive-strategies/
    type: technical_blog
    published: 2025-01-15
    reliability: moderate_high
  - id: src5
    title: "Risk, Resilience, and Rebalancing in Global Value Chains"
    author: McKinsey Global Institute
    url: https://www.mckinsey.com/~/media/mckinsey/business%20functions/operations/our%20insights/risk%20resilience%20and%20rebalancing%20in%20global%20value%20chains/risk-resilience-and-rebalancing-in-global-value-chains-full-report-vh.pdf
    type: primary_research
    published: 2020-08-01
    reliability: authoritative
---

# Supply Chain Risk Mapping

## Definition

Supply chain risk mapping is the systematic process of identifying, scoring, and visualizing vulnerabilities across a company's supplier network — from tier-1 direct suppliers through sub-tier dependencies. Each risk is scored on three dimensions: impact if materialized, likelihood of occurrence, and organizational preparedness. The goal is to identify single-source dependencies, geographic concentrations, and high-failure-probability nodes before disruption occurs, then build targeted mitigation strategies. [src2]

## Key Properties

- **Three-dimensional scoring**: Impact x Likelihood x Preparedness for each risk node [src2]
- **Tier visibility gap**: Majority of companies understand risk only to tier-1; sub-tier risks remain invisible [src3]
- **Single-source prevalence**: Companies average 3-5 critical single-source dependencies that represent existential risk [src5]
- **Mitigation adoption (2025)**: 45% increasing inventories, 39% pursuing dual sourcing, 33% developing nearshoring plans [src1]
- **Review cadence**: Quarterly reassessment required — risk maps degrade within 90 days due to geopolitical and market changes [src4]

## Constraints
<!-- Agents: read this section before recommending this concept/framework.
     These are hard boundaries on when and how it applies. -->

- Sub-tier visibility requires active effort — suppliers rarely disclose their own supplier networks voluntarily [src3]
- Risk scoring without standardized methodology produces inconsistent results across assessors [src2]
- Dual sourcing and nearshoring increase costs 15-40% — risk mitigation is a trade-off, not a free improvement [src1]
- Geopolitical risks (tariffs, sanctions, export controls) change faster than annual risk reviews can capture [src4]
- The percentage of companies pursuing dual-sourcing or regionalization has remained flat despite increasing disruptions [src3]

## Framework Selection Decision Tree

```
START — Company needs to manage supply chain vulnerabilities
├── What's the primary concern?
│   ├── Single-source dependency identification → Risk Mapping ← YOU ARE HERE
│   ├── Cost reduction in procurement → Procurement Strategy
│   ├── Inventory optimization to buffer disruption → Inventory Management
│   └── Process efficiency improvement → Lean Six Sigma
├── How many suppliers?
│   ├── < 20 → Manual risk register + scoring matrix
│   ├── 20-200 → Structured risk mapping with tier analysis
│   └── > 200 → Digital supply chain mapping platform required
└── Is the primary risk geopolitical?
    ├── YES → Focus on geographic concentration + tariff impact modeling
    └── NO → Focus on financial health, quality, and capacity risks
```

## Application Checklist

### Step 1: Map the supplier network (tier-1 and beyond)
- **Inputs needed**: Supplier list, BOM (bill of materials), spend data, geographic locations
- **Output**: Visual supplier network map showing tiers, locations, and spend concentration
- **Constraint**: Do not stop at tier-1 — request sub-tier supplier data from each tier-1 supplier. If they refuse, flag the node as "unknown risk" (which is worse than known risk) [src3]

### Step 2: Identify single-source dependencies
- **Inputs needed**: Supplier network map, component/material criticality assessment
- **Output**: List of all components/materials with only one qualified supplier
- **Constraint**: A component having two suppliers in the same geographic region is still a single-source dependency for regional disruption scenarios [src5]

### Step 3: Score each risk node
- **Inputs needed**: Impact scale (1-5), likelihood scale (1-5), preparedness scale (1-5) for each supplier/component
- **Output**: Risk register with composite scores and priority ranking
- **Constraint**: Use a consistent scoring rubric — calibrate with cross-functional team (procurement, engineering, finance) to reduce subjectivity [src2]

### Step 4: Design mitigation strategies
- **Inputs needed**: Prioritized risk register, budget for mitigation, timeline constraints
- **Output**: Mitigation plan per critical risk (dual sourcing, safety stock, nearshoring, contractual protections)
- **Constraint**: Mitigation must be cost-justified — calculate the expected value of disruption (probability x impact) vs. mitigation cost. Not all risks are worth mitigating [src1]

### Step 5: Establish monitoring and review cadence
- **Inputs needed**: Risk register, trigger events (financial distress signals, geopolitical changes, quality incidents)
- **Output**: Monitoring dashboard with automated alerts and quarterly review schedule
- **Constraint**: Risk maps that are not reviewed quarterly become actively misleading — stale data is worse than no data [src4]

## Anti-Patterns

### Wrong: Mapping only tier-1 suppliers and declaring the supply chain "assessed"
Most disruptions originate at tier-2 or below. The 2021 semiconductor shortage and 2020 PPE crisis both resulted from sub-tier concentration that was invisible to most companies. [src5]

### Correct: Push visibility to tier-2 minimum, tier-3 for critical components
Require tier-1 suppliers to disclose their key suppliers. For components where disruption would halt production, map to tier-3. [src3]

### Wrong: Scoring all risks with the same team
Procurement scores financial risk well but misses engineering risk. Engineering understands quality risk but underestimates geopolitical risk. Siloed scoring produces blind spots. [src2]

### Correct: Cross-functional scoring with calibration sessions
Assemble procurement, engineering, finance, and logistics to score risks jointly. Run calibration exercises on 3-5 known risks before scoring the full register. [src2]

### Wrong: Treating dual sourcing as complete mitigation
Having two suppliers for a component does not eliminate risk if both source from the same sub-tier supplier or region. Geographic diversification must extend beyond tier-1. [src1]

### Correct: Validate geographic and sub-tier diversification
Dual sourcing must include verification that second-source supply chains are truly independent at the sub-tier level. [src5]

## Common Misconceptions

- **Misconception**: Supply chain risk mapping is a one-time exercise that produces a static document.
  **Reality**: Risk maps degrade within 90 days. Geopolitical shifts, supplier financial changes, and demand fluctuations require quarterly reassessment with real-time monitoring for critical nodes. [src4]

- **Misconception**: More suppliers always means less risk.
  **Reality**: Supplier proliferation increases management complexity and can reduce quality control. The optimal strategy is a small number of deeply vetted, geographically diversified suppliers for critical components. [src2]

- **Misconception**: Cost is the primary driver of supply chain risk mitigation decisions.
  **Reality**: In 2024, only 34% of companies cited cost savings as the primary outsourcing driver — access to talent (42%) and strategic flexibility now outweigh pure cost considerations in supply chain decisions. [src1]

## Comparison with Similar Concepts

| Concept | Key Difference | When to Use |
|---|---|---|
| Supply Chain Risk Mapping | Identifies and scores vulnerabilities across supplier network | Proactive risk identification before disruption |
| Procurement Strategy | Optimizes sourcing decisions for cost, quality, and reliability | When selecting or renegotiating with suppliers |
| Business Continuity Planning | Broader organizational response to disruption events | When building recovery plans beyond supply chain |
| Vendor Risk Management | IT/software-focused supplier risk assessment | Technology vendor evaluation and compliance |

## When This Matters

Fetch this when a company asks about identifying supply chain vulnerabilities, scoring supplier risks, addressing single-source dependencies, building supply chain resilience, or responding to geopolitical disruption threats.

## Related Units

- [Procurement Strategy](/business/operations/procurement-strategy/2026)
- [Inventory Management](/business/operations/inventory-management/2026)
- [Lean Six Sigma](/business/operations/lean-six-sigma/2026)
