
Case Study · Manufacturing
Supply-Chain Risk for a Manufacturing Group
- ~300Suppliers profiled by criticality
- 25Critical suppliers under continuous monitoring
- 14 weeksTo the first consolidated risk view
The challenge
A multi-plant manufacturing group depended on hundreds of suppliers for components, IT services and logistics, yet had no single view of the risk they introduced. Assessments, where they existed, were one-off questionnaires filed away.
After a few incidents involving external partners, management wanted to know which suppliers were genuinely critical, how exposed they were, and how to notice a deterioration in time.
My approach
I built a supplier inventory and ranked it by criticality, combining business impact with the level of access to the group’s data and systems. A small set of third parties emerged as deserving priority attention.
For the critical suppliers I paired document-based assessment with evidence from the outside — exposed surface, basic hygiene, signs of compromise — so that what they declared could be compared with what was observable.
Risk fed into a single view for management, with thresholds and a periodic review process. The most critical suppliers were placed under continuous monitoring, with alerts when their risk profile shifts.
The group moved from sporadic assessments to a repeatable third-party risk programme, with clear priorities and a shared basis for contractual decisions.
Related
You might also like
M&AIndustrial Equipment Manufacturer
Third-party risk, brought under control ahead of a cross-border acquisition.Manufacturing
Third-party riskPre-transaction posture assessment of an insurance group
A security posture and third-party risk assessment ahead of a corporate transaction, distilled into a board-level roadmap with clear priorities and timelines.Insurance / M&A
Supply chainThird-party and supply-chain risk in M&A
OT vendors, critical dependencies and permanent access: mapping and monitoring what you inherit.9 Nov 2025 · 4 min read