Skills on AI

Active theme: Light

Supply Chain Risk Assessment

Use when asked to identify and prioritize risks across a supply chain — supplier concentration, geographic or geopolitical exposure, single points of failure — as distinct from [[logistics-planning]], which is the concrete operational plan for moving goods rather than the exercise of finding what could go wrong along the way.

Supply chain risk assessment is the systematic practice of identifying and prioritizing risks across a supply chain: which suppliers, routes, or regions the business is overly dependent on, and what would happen if any one of them failed. It produces a prioritized set of risks with mitigation plans, not just a plan for moving goods under normal conditions.

Key components

  • Mapping the chain to find single points of failure — tracing where the business depends on one supplier, one route, or one region for something it can't easily replace, rather than assuming redundancy exists just because the org chart or supplier list looks long.
  • Likelihood and impact scoring — rating each identified risk on how likely it is to occur and how severe the consequence would be if it did, so risks can be compared against each other rather than treated as equally urgent.
  • Mitigation and contingency plans for the top risks — for the highest-priority risks, a concrete plan (a qualified backup supplier, an alternate route, safety stock sized for the disruption) rather than just a documented awareness that the risk exists.
  • A revisit cadence — a scheduled point to redo the assessment as the supply chain itself changes, not just after something has already gone wrong.

How this differs from logistics planning

Supply chain risk assessment asks what could go wrong across the whole chain and how prepared the business is for it. Logistics Planning takes the current chain as a given and plans the concrete movement of a specific shipment through it. Risk assessment findings — a single carrier dependency, a region prone to disruption — should feed into and change logistics plans and Inventory Management safety stock, but the two are distinct exercises with different outputs.

Common pitfalls

  • Assessment stops at first-tier suppliers — a business assesses the suppliers it buys from directly but never looks a tier or two further back, missing a critical raw-material dependency that several tiers back is itself a single point of failure for the whole chain.
  • A long risk list with no prioritization — cataloging every conceivable risk without scoring likelihood and impact produces a document that looks thorough but gives no guidance on which risks actually deserve a mitigation plan and budget.
  • Assessed once, after a past disruption — treating risk assessment as a one-time reaction to a disruption that already happened, rather than a recurring practice, means the next disruption comes from a direction nobody re-examined.
  • Risks identified but never mitigated — a risk register that lists concentration and exposure but stops short of an actual contingency plan leaves the organization no better prepared than before the assessment.
  • Geographic risk treated as static — political, regulatory, or climate conditions in a supplier's region change over time; an assessment that isn't refreshed can miss a region that's grown materially riskier since it was last reviewed.

Learn more

  • Logistics Planning for the concrete operational plan a risk assessment's findings should inform.
  • Inventory Management for sizing safety stock against the risks this assessment identifies.
  • Demand Forecasting for the demand-side projection this supply-side risk work needs to stay matched against.
  • Disaster Recovery Plan for the broader practice of preparing to continue operating through a major disruption, of which supply chain contingency is one part.

View supply-chain-risk-assessment/SKILL.md on GitHub