Risk 360

Managing Enterprise Risk Across Multi-Tier Supply Chains

Getting India Risk Ready

Introduction:

Your Supplier Has a Supplier Has a Supplier. Do You Know Who They Are?

Your biggest supply chain risk may be a company you have never heard of, sitting four tiers away from your business.

Ford did not think it was dependent on a neon gas producer in Ukraine.

Maruti was not buying chips from Taiwan.

A pharmaceutical company did not think it was dependent on a chemical manufacturer several tiers away in another country.

An automaker did not think a fire in a Japanese semiconductor plant could halt vehicle production worldwide.

Consumer durable manufacturers were not contracting with semiconductor foundries.

Yet all of these happened. Yet disruptions at those unseen suppliers affected production, deliveries, revenues, and customer commitments.

The lesson is simple:

The supplier you know is rarely the only supplier you depend on. The most significant supply chain risk often sits three, four, or five tiers beyond your visibility.

A ₹50 Component Can Stop a ₹15-Lakh Vehicle.

Most organisations manage their direct suppliers.

Few understand the suppliers behind those suppliers.

A modern vehicle is not built by one company. It is assembled by an ecosystem of thousands of suppliers, semiconductor manufacturers, logistics networks, cloud providers, software vendors, energy providers, and critical infrastructure partners spread across multiple countries.

The biggest supply chain risk may not sit with your Tier-1 supplier. It may sit with a Tier-4 semiconductor foundry, a Tier-5 specialty chemical producer, or a critical technology dependency you have never heard of.

The lesson for Boards, Chief Risk Officers (CROs), and Procurement Leaders is simple:

The next disruption may not come from your largest supplier. It may come from a company whose name you don’t even know exists in your supply chain.

Modern supply chain risk management is no longer about managing suppliers. It is about managing dependencies.

Context: Your Supplier Has a Supplier Has a Supplier. Do You Know Who They Are?

A ₹50 Component Can Stop a ₹15-Lakh Vehicle.

Most organisations manage Tier-1 suppliers. The biggest risks often sit in Tier-3, Tier-4, or Tier-5 suppliers.

Think about an SUV such as the XUV700. A customer sees:

  • One vehicle
  • One brand
  • One dealer
  • One invoice.

But what are they actually buying?

  • 20,000+ components
  • Hundreds of direct suppliers
  • Thousands of indirect suppliers
  • Global semiconductor ecosystems
  • Mining companies
  • Ports, railways, and trucking networks
  • Software vendors and cloud providers
  • Energy, water, and telecom infrastructure
  • Cybersecurity and technology dependencies

In reality, a modern vehicle is not manufactured by one company. It is assembled by an ecosystem.

The Supply Chain You Cannot See

Consider a simple dependency chain:

Mahindra / Original Equipment Manufacturer (OEM)
(On)

Instrument Cluster Supplier (Tier-1)
(On)

Electronics Manufacturer (Tier-2)
(On)

Semiconductor Component Supplier (Tier-3)
(On)

Chip Foundry in Taiwan (Tier-4)
(On)

Suppliers of specialty gases, chemicals, minerals, energy, and water (Tier-5)

Now imagine a semiconductor fabrication plant shuts down for 10 days. The impact travels quickly:

Chip Foundry Disrupted
(Triggers)

Electronic Components Delayed
(Triggers)

Instrument Cluster Production Impacted
(Triggers)

Vehicle Production Slows
(Results in)

Dealer Deliveries Delayed
(Results in)

Customer Orders Affected
(Results in)

Revenue Impacted
(Results in)

Investor Expectations Missed.

The disruption originated four tiers away. Yet the OEM feels the pain immediately. Such issues highlight why continuous risk assessment is essential.

We Have Seen This Before (across Industries):

Automotive: A global chip shortage disrupted production at manufacturers across India, Europe, and the United States, exposing logistics risk and supplier dependencies.

Consumer Durables: Shortages of microcontrollers delayed production of washing machines, refrigerators, and electronics.

Pharmaceuticals: Many companies discovered that multiple API suppliers ultimately depended on the same upstream manufacturing hubs.

FMCG: Diversified suppliers often relied on the same Tier-3 packaging, chemical, or ingredient providers.

Energy and Refining: A disruption involving a catalyst, specialty chemical, software provider, or critical infrastructure partner can ripple across entire operations.

Dependencies Leaders Often Miss

Supply chains are no longer just suppliers. They include:

  • GPS systems dependent on satellite infrastructure
  • Dealer platforms dependent on cloud providers
  • Payment systems dependent on banks and networks
  • Manufacturing systems dependent on software vendors
  • Industrial operations dependent on OT cybersecurity

A supplier risk review that ignores these dependencies is only seeing part of the picture.

The Questions Management, CROs, and Procurement Leaders Should Be Asking

Instead of only asking:

Is the supplier financially stable?
Are Service Level Agreements being met?
Are compliance requirements satisfied?

Also ask:

  • Where are our single points of failure?
  • Which critical suppliers have been mapped beyond Tier-1?
  • Which dependencies sit in geopolitically sensitive regions and are likely to be affected by geopolitical risk?
  • What happens if a Tier-3 supplier fails tomorrow?
  • How long would recovery take?
  • Do we have alternate sources?

How Deep Should We Go?

Not every supplier needs mapping. But for critical products, operations, and services:

Tier 1 – Direct suppliers
Tier 2 – Suppliers to your suppliers
Tier 3 – Component and material providers
Tier 4 – Semiconductor, technology, chemical and infrastructure providers
Tier 5 – Raw materials, minerals, energy and ecosystem dependencies

A practical target:

Map your Top 20–50 critical business dependencies to at least Tier-4 or Tier-5.

The objective is not to map everything.

The objective is to uncover hidden risks and concentration risks before they become business risks. Implementing enterprise risk management techniques is key to mitigating procurement risk and ensuring overall operational risk management and third-party risk management.

Final Thought

A supplier has a supplier.

That supplier has another supplier.

And somewhere in that chain may sit the component, technology, vendor risk, material, or service capable of stopping your business.

The next disruption may not come from your largest supplier.

It may come from a company whose name you have never heard.

Modern supply chain risk management is no longer about managing suppliers. It is about managing dependencies. 

The author of this article is Mr. Prashant Dhume, IRM India trainer. The author confirms that this article is original and has not been copied, reproduced, or derived from another author’s work, except for third-party references used for research purposes.

FAQs

1.What are the risks across multi-tier supply chains? 

Supply chains are no longer just suppliers. They include:

  • GPS systems dependent on satellite infrastructure
  • Dealer platforms dependent on cloud providers
  • Payment systems dependent on banks and networks
  • Manufacturing systems dependent on software vendors
  • Industrial operations dependent on OT cybersecurity

These create a multi-tier supply chain having components, technology, material, or services, each of which are dependencies and risk hotspots capable of stopping a business. 

2. Why is supplier dependency mapping important? 

The biggest supply chain risk may not sit with a Tier-1 supplier. It may sit with a Tier-4 semiconductor foundry, a Tier-5 specialty chemical producer, or a critical technology dependency one has never heard of.

Disruptions at those unseen suppliers are capable of affecting production, deliveries, revenues, and customer commitments.

Modern supply chain risk management is no longer about managing suppliers. It is about managing dependencies.

3. How can organisations identify hidden supply chain dependencies? 

Organisations can identify hidden supply chain dependencies by asking the following relevant questions – 

  • Where are our single points of failure?
  • Which critical suppliers have been mapped beyond Tier-1?
  • Which dependencies sit in geopolitically sensitive regions?
  • What happens if a Tier-3 supplier fails tomorrow?
  • How long would recovery take?
  • Do we have alternate sources?

For critical products, operations, and services:

  • Tier 1 – Direct suppliers
  • Tier 2 – Suppliers to your suppliers
  • Tier 3 – Component and material providers
  • Tier 4 – Semiconductor, technology, chemical and infrastructure providers
  • Tier 5 – Raw materials, minerals, energy and ecosystem dependencies

A practical target:

Map the Top 20–50 critical business dependencies to at least Tier-4 or Tier-5.

The objective is not to map everything. The objective is to uncover hidden concentration risks before they become business disruptions.

4. How to mitigate supplier concentration risk?

Supplier concentration risk can be mitigated through a combination of diversification, redundancy, contractual protection, and contingency planning:

  • Map concentration exposure: Identify critical suppliers, single-source components, geographic clusters, and suppliers with shared sub-tier dependencies.
  • Set concentration limits: Establish thresholds for maximum spend, volume, or critical-component dependency on one supplier or region.
  • Dual- or multi-source critical inputs: Qualify alternative suppliers before disruption occurs and allocate meaningful volumes to keep them operationally ready.
  • Diversify geographically: Avoid sourcing all critical materials from one country, region, port, or logistics corridor.
  • Build strategic inventory: Hold safety stock for high-impact, long-lead-time, or difficult-to-substitute materials.
  • Strengthen contracts: Include capacity commitments, priority-allocation clauses, continuity obligations, audit rights, and notification requirements.
  • Develop substitutes: Standardise specifications, redesign products where feasible, and pre-approve alternative materials or components.
  • Assess financial and operational health: Monitor suppliers’ liquidity, capacity, quality, cyber exposure, geopolitical risk, and business-continuity arrangements.
  • Understand sub-tier dependencies: Require visibility into key tier-two and tier-three suppliers to identify hidden concentration.
  • Test contingency plans: Conduct disruption simulations and define clear triggers for activating alternate suppliers, inventory buffers, or substitute materials.

5. What is third-party risk management? 

Third-party risk management is the discipline of identifying, assessing, monitoring and mitigating risks that arise from your organisation’s relationships with external vendors and business partners. “Third party” here means any outside organisation that processes your data, delivers services or supports your operations – from cloud providers and IT outsourcers to facilities managers, marketing agencies and consulting firms. 

A mature TPRM programme typically includes:

  • A complete inventory of all third parties and the services or products they provide.
  • Risk-based due diligence at onboarding, covering areas like information security, compliance, financial health, ESG practices and operational resilience.
  • Ongoing monitoring through questionnaires, certifications, audits, performance data and adverse-media checks. 
  • Contractual controls: SLAs, security clauses, right-to-audit, incident reporting and exit provisions.

In essence, TPRM asks: “For each external organisation we rely on directly, how much risk are we taking on – and is it acceptable?”

You may also like

Leave a reply

Your email address will not be published. Required fields are marked *

More in Risk 360