02 — Capability · BC-640.40
Supplier Risk
See which suppliers could hurt the business if they failed, were breached or behaved badly, watch those signals continuously and have a plan for the ones that matter most.
- Third-Party Risk Management
- Vendor Risk
In scope
- Risk tiering by criticality and spend
- Monitoring of financial and cyber and geographic and ethical risk
- Mitigation and exit plans for critical suppliers
Out of scope
- Enterprise risk framework and appetite (see BC-130)
- Security assessment of a supplier's technology (see BC-760)
Realized by · 0
- No product in the catalog yet.
Used in · 1
Build it · 0
- Nothing in the library points here yet.
Decomposes into · 3
- BC-640.40.10Supplier Risk TieringRank suppliers by how badly their failure would hurt and how hard they would be to replace, and scale oversight to the tier.
- BC-640.40.20Continuous Risk MonitoringWatch financial health, security posture, sanctions, news and geography for critical suppliers and act on changes rather than annual questionnaires.
- BC-640.40.30Supplier Contingency PlanningHold a tested alternative — second source, buffer stock or in-house option — for every supplier whose loss would stop the business.