Skip to content
Search AI Powered

Latest Stories

Reflections

What's over the horizon?

Instead of reacting to supply chain risks as they come, organizations should have an integrated anticipatory process.

Supply chain leaders need to look over the horizon and anticipate. Sometimes what's over the horizon is a rainbow. Sometimes it's a tsunami. In either case, we need to be ready.

We call that process, supply chain risk management.


The U.S. Government Accountability Office (GAO) has a good way to structure the process. Late in 2016, the agency issued a publication with a holistic approach to risk management.1 This government-sponsored research laid out simple framework to address the broad issue of risk at the organizational level. Although GAO framed this as a six-step process for overall enterprise risk management, it can be cascaded seamlessly to supply chain risk management.

By looking into the risk management practices found in different government agencies, GAO identified six key practices that, when joined together, create an effective risk management process.

  1. Align the risk management process to the organization's overall goals and objectives. This step requires the full engagement and commitment of senior leaders because they play an active role in the goal-setting process. Their involvement also demonstrates to staff the importance of risk management.
  2. Identify risks. In order to assemble a comprehensive list of risks, it is important to develop a culture where all employees can effectively bring attention to risks and are able to connect these risks to the organization's higher-level goals and objectives.
  3. Assess risks. To help prioritize the risk, the organization needs to assess its probability and potential magnitude.
  4. Select appropriate risk response. When creating a response or mitigation program for a risk, organizations should make sure it fits into their overall management structure, culture, and processes. Risk cannot be managed in isolation.
  5. Monitor risks. Because risks are constantly changing, organizations should continuously monitor for and manage them. As a situation evolves, so will the organizational posture.
  6. Communicate and report on risks. Organizations should share information with internal and external stakeholders on the risks that they have identified and the steps that they are taking to address them.

While GAO presents these ideas as a step-by-step sequence, the recommendations really describe an integrated and anticipatory oversight process. Good supply chain risk management strategies forecast, rather than react. Once upon a time, risk management was about "rolling with the punches." Today, risk management means anticipating events before they happen and avoiding the issue rather than reacting to it.

Forecasting means moving beyond reacting to traditional disruptions. Traditional supply chain disruptors include problems like missing shipments, hurricanes, strikes, and equipment failure. But to be more fully in control, we need to think about larger issues that might create vulnerabilities. Let the imagination roam. Tariffs? China taking over the South China Sea? North Korea meddling in communications or the Internet? All of these could happen, with a profound ripple effect.

This means that we all need to develop the ability to look over the horizon. That capability needs to be cascaded through all the layers of the supply chain and be held by everyone.

Alternatively, we may want to reduce the complexity of the supply chain by eliminating layers or pulling sources of supply closer. The word that supply chain risk managers need to apply is simplicity.

The danger of "silo thinking"

Today, when considering operations, supply chain experts think end-to-end, not in silos. Supply chain risk management should not be any different. But that's sometimes not the case.

Let's consider the approach taken by the National Institute of Standards and Technology (NIST), formerly known as the Bureau of Standards. Around the same timeframe as the GAO report, NIST published a bulletin called, "Supply Chain Risk Management Practices for Federal Information Systems and Organizations."2 The abstract for the bulletin says, "Federal agencies are concerned about the risks associated with information and communications technology (ICT) products and services that may contain potentially malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the ICT supply chain."

While NIST's report asserts that it is about supply chain risk management, it isn't. Like the approach found in many government offices, the NIST policy treats supply chain risk as a cybersecurity issue. There is a cyber element in supply chain risk management, to be sure, but the topic of supply chain risk is broader than cybersecurity. Supply chain risk management extends beyond the cyber world and includes the physical.

Somewhere between the GAO high-level approach and NIST's narrow view lies the challenge for all of us: Understandthe layers of your supply chain, gather the data, analyze, characterize the processes, prioritize, and get to work.

Notes:

1. "Selected Agencies' Experiences Illustrate Good Practices in Managing Risk," GAO-17-63, a report to the Committee on Oversight and Government Reform, House of Representatives, https://www.gao.gov/products/GAO-17-63

2. "Supply Chain Risk Management Practices for Federal Information Systems and Organizations," NIST Special Publication 800-161, https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-161.pdf

Recent

More Stories

photos of grocery supply chain workers

ReposiTrak and Upshop link platforms to enable food traceability

ReposiTrak, a global food traceability network operator, will partner with Upshop, a provider of store operations technology for food retailers, to create an end-to-end grocery traceability solution that reaches from the supply chain to the retail store, the firms said today.

The partnership creates a data connection between suppliers and the retail store. It works by integrating Salt Lake City-based ReposiTrak’s network of thousands of suppliers and their traceability shipment data with Austin, Texas-based Upshop’s network of more than 450 retailers and their retail stores.

Keep ReadingShow less

Featured

minority woman with charts of business progress

Study: Inclusive procurement can fuel economic growth

Inclusive procurement practices can fuel economic growth and create jobs worldwide through increased partnerships with small and diverse suppliers, according to a study from the Illinois firm Supplier.io.

The firm’s “2024 Supplier Diversity Economic Impact Report” found that $168 billion spent directly with those suppliers generated a total economic impact of $303 billion. That analysis can help supplier diversity managers and chief procurement officers implement programs that grow diversity spend, improve supply chain competitiveness, and increase brand value, the firm said.

Keep ReadingShow less
Logistics industry growth slowed in December
Logistics Managers' Index

Logistics industry growth slowed in December

Logistics industry growth slowed in December due to a seasonal wind-down of inventory and following one of the busiest holiday shopping seasons on record, according to the latest Logistics Managers’ Index (LMI) report, released this week.

The monthly LMI was 57.3 in December, down more than a percentage point from November’s reading of 58.4. Despite the slowdown, economic activity across the industry continued to expand, as an LMI reading above 50 indicates growth and a reading below 50 indicates contraction.

Keep ReadingShow less
cargo ships at port

Strike threat lingers at ports as January 15 deadline nears

Retailers and manufacturers across the country are keeping a watchful eye on negotiations starting tomorrow to draft a new contract for dockworkers at East coast and Gulf coast ports, as the clock ticks down to a potential strike beginning at midnight on January 15.

Representatives from the International Longshoremen's Association (ILA) and the United States Maritime Alliance (USMX) last spoke in October, when they agreed to end a three-day strike by striking a tentative deal on a wage hike for workers, and delayed debate over the thornier issue of port operators’ desire to add increased automation to port operations.

Keep ReadingShow less
women shopping and checking out at store

Study: Over 15% of all retail returns in 2024 were fraudulent

As retailers enter 2025, they continue struggling to slow the flood of returns fraud, which represented 15.14%--or nearly one-sixth—of all product returns in 2024, according to a report from Appriss Retail and Deloitte.

That percentage is even greater than the 13.21% of total retail sales that were returned. Measured in dollars, returns (including both legitimate and fraudulent) last year reached $685 billion out of the $5.19 trillion in total retail sales.

Keep ReadingShow less