Supply Chain Risk Management (SCRM) is the systematic identification, assessment, treatment and monitoring of risks that can disrupt supply-chain performance. It is broader than reacting to emergencies: the objective is to understand exposure before disruption occurs and put proportionate controls in place.
Risk Management vs Supply Chain Resilience
The terms are related but not identical. Risk management focuses on identifying and reducing exposure to threats. Resilience is the ability to continue, adapt and recover when disruption still occurs. A company can have strong risk controls and still need resilience because not every event can be predicted or prevented.
Typical Supply Chain Risks
| Risk Area | Examples |
|---|---|
| Supplier | Bankruptcy, capacity shortage, quality failure, single-source dependency |
| Logistics | Port closure, carrier failure, border delay, route disruption |
| Demand | Forecast error, sudden demand spike, product-mix change |
| Inventory | Stockout, excess, obsolescence, inaccurate records |
| Geopolitical / Regulatory | Sanctions, tariffs, import restrictions, war, policy changes |
| Cyber / Technology | ERP outage, ransomware, supplier-system failure, data corruption |
| Operational | Plant breakdown, labour shortage, warehouse failure |
| Environmental | Flood, storm, heat, water scarcity and other physical hazards |
The SCRM Process
- Define scope and objectives. Identify the supply chain, product, geography or process being assessed.
- Identify risks. Use supplier mapping, process mapping, historical incidents, stakeholder input and external intelligence.
- Analyse risk. Estimate likelihood, impact, speed of onset, detectability and existing controls.
- Evaluate and prioritise. Decide which risks require treatment and which can be accepted.
- Treat risk. Avoid, reduce, transfer/share or accept the exposure.
- Monitor and review. Track indicators, incidents and changes in exposure.
- Communicate and escalate. Ensure owners and decision-makers know when action is required.
This follows the same basic logic as ISO 31000: establish context, identify, analyse, evaluate, treat, monitor and communicate risk.
Practical Risk Register Example
| Risk | Likelihood | Impact | Current Control | Action | Owner |
|---|---|---|---|---|---|
| Single-source component shortage | 4/5 | 5/5 | 30 days safety stock | Qualify second source | Procurement |
| Port congestion | 3/5 | 4/5 | Forwarder alerts | Pre-agree alternate port/routing | Logistics |
| ERP outage | 2/5 | 5/5 | Daily backup | Test manual continuity process | IT / Operations |
A simple risk score = likelihood × impact can help prioritisation, but it should not be used mechanically. A low-probability event with catastrophic impact may still require executive attention.
Risk Treatment Options
- Avoid: stop the activity or redesign the process.
- Reduce: dual-source, hold buffer stock, improve controls or shorten lead time.
- Transfer / share: insurance, contractual allocation or shared contingency arrangements.
- Accept: consciously retain the exposure when treatment cost exceeds the justified benefit.
Leading Indicators to Monitor
- Supplier OTIF deterioration
- Quality rejection trend
- Supplier financial or capacity alerts
- Lead-time increase
- Inventory below defined buffer
- Port congestion or route alerts
- Expedited freight frequency
- Cyber incidents and system availability
Example: Single-Source Supplier Risk
A critical component has a 16-week replacement lead time and only one approved supplier. The organisation currently holds four weeks of stock. The risk is not solved simply by recording it as “high.” A useful treatment plan might include:
- Qualify a second source.
- Increase temporary buffer stock while qualification is underway.
- Obtain visibility of the supplier’s capacity and sub-tier dependency.
- Agree emergency allocation and escalation rules.
- Track stock cover and supplier delivery as leading indicators.
Common Mistakes
- Creating a risk register that is never reviewed.
- Listing generic risks without owners or actions.
- Assuming “dual source” automatically means independent risk if both sources share the same sub-tier.
- Using only historical data and ignoring emerging risks.
- Confusing risk treatment with resilience planning.
Common Interview Question
Question: How would you manage supply-chain risk?
Strong answer: I would define the scope, map the critical suppliers and flows, identify risks, assess likelihood and impact, document current controls, assign treatment actions and owners, then monitor leading indicators. I would also prepare contingency options for high-impact risks that cannot be fully prevented.















Comments 2