Insight · Risk & resilience

Two suppliers, one factory

Dual sourcing is the standard answer to supplier risk, and it is frequently an illusion. Two suppliers that look independent on your approved vendor list can converge two tiers down on the same plant, the same region or the same raw material. The exposure that stops your line is almost never the one on your risk register.

Executive summary

Most supplier risk programmes are well run and looking in the wrong place. They monitor tier one thoroughly, because tier one is where the contracts are and where the data lives. But the events that halt production usually begin below that line: a specialist component plant, a single qualified coating facility, a region that happens to make most of the world's supply of one input. Because the exposure is not visible, it is not managed, and the first time anyone maps it properly is during the incident.

This paper is about finding that exposure before the event. It covers the forms concentration actually takes, how to build a sub-tier map when nobody will simply hand you one, why ranking by spend hides your worst risks, and what a proportionate response looks like once you know.

Concentration has more than one shape

Supplier concentration is usually understood as depending too much on one company. That is the least interesting version. In practice the convergence happens along several axes at once, and an organisation can be well diversified on one while completely exposed on another.

  • Entity. Two suppliers owned by the same parent, or one acquired by the other since the contracts were signed
  • Site. Different companies manufacturing in the same industrial park, sharing the same utilities, the same flood plain or the same labour pool
  • Geography. Diversified suppliers, all sourcing from one region exposed to the same weather, politics or export control
  • Component. Multiple assemblies containing the same specialist part, which itself has one qualified maker
  • Material. Different components sharing a raw input with a concentrated global supply
  • Route. Multiple sources whose goods pass through the same port, corridor, carrier or customs regime
  • Certification. One accredited test house, one approved treatment, one regulator sign-off that everything depends on

The last one catches people out repeatedly. Qualification is a bottleneck as real as a factory, and a great deal harder to duplicate at short notice.

You are not diversified because you have two suppliers. You are diversified when the two of them can fail independently. WAJD Group

Building the map when nobody hands you one

Sub-tier data is not sitting in a system waiting to be queried, and suppliers are often reluctant to disclose their own sources. The map is therefore built by triangulation. No single method is complete, but together they get to a picture good enough to act on, and each one improves as the others fill in.

  • Bill of materials analysis. Start from what your products are made of, not from who you pay. The parts list is the honest structure of your dependency
  • Contractual disclosure. Build sub-tier declaration into contract renewals and onboarding, with an obligation to notify changes rather than answer an annual questionnaire
  • Trade and shipping records. Public customs and bill of lading data reveals movement between parties that no questionnaire will
  • Certification and audit records. Approvals, test houses and accreditation bodies expose the qualification bottlenecks
  • Inference. Where a part has particular characteristics, the set of facilities capable of producing it is often small and can be narrowed analytically
  • Incident archaeology. Every past disruption tells you something true about the chain. Most organisations already hold this evidence and have never mined it

Doing this once produces a document. Doing it continuously produces a capability, and the difference is automation. This is precisely the network layer described in our paper on autotwins: a map that assembles itself from transactions and stays current without anyone maintaining it by hand.

Rank by revenue at risk, not by spend

Almost every supplier risk register is sorted by annual spend, which is a measure of commercial importance, not of operational fragility. The fastener that costs pennies and has one qualified source can stop more revenue than the largest contract on the ledger. Two numbers change the picture.

  • Revenue at risk. The value of finished output that cannot ship if this node fails, traced through the parts list rather than estimated
  • Time to recover. How long until output resumes through an alternate, honestly including qualification, tooling, certification and ramp, not just the first delivery date

Multiply exposure by duration and the list reorders dramatically. The suppliers at the top are rarely the ones procurement spends its time on, which is exactly why the exercise is worth doing.

What to do once you know

Not every exposure justifies action. The point of quantifying is to spend the mitigation budget where it changes an outcome, and to make a conscious decision to accept the rest.

  • Qualify an alternate before you need it. Qualification is the long pole, so it is the thing to buy early. A qualified but unused source is cheap insurance
  • Buffer where recovery is slow. Stock is expensive, so size it against time to recover, not against a blanket weeks of cover policy
  • Design the dependency out. Where a single specialist part drives the exposure, engineering a second approved specification is often cheaper than carrying the risk forever
  • Separate the shared paths. Split routes, ports and carriers where the convergence is logistical rather than industrial, which is usually the cheapest fix available
  • Contract for visibility. Make sub-tier notification a condition, so the map degrades slowly instead of silently
  • Accept and record. Some concentration is unavoidable. Write it down, price it, and make sure the board knows it was a decision rather than an oversight

Keeping it true

A concentration map is accurate on the day it is finished and decaying by the end of the week. Suppliers move production, subcontract, get acquired and change routes without telling anyone, because no term obliged them to. The map has to be wired to the transactions that reveal these changes, so a new shipping origin or an unfamiliar counterparty updates the picture rather than passing unnoticed. That continuous posture is the same argument we make about monitoring in continuous third-party risk, applied to structure rather than to supplier health.

Common pitfalls

  • Treating dual sourcing at tier one as evidence of resilience without checking where those suppliers buy
  • Sorting the risk register by spend and never seeing the cheap part that stops the line
  • Mapping once for a board paper, then letting it decay
  • Estimating time to recover from the alternate's quoted lead time, ignoring qualification and ramp
  • Asking suppliers for disclosure with no contractual basis, then believing the answers
  • Mapping everything to the same depth rather than going deep where revenue at risk justifies it

How WAJD Group helps

We build the sub-tier map from your own transactional data and the external sources that corroborate it, quantify exposure as revenue at risk and time to recover, and run it as a live capability rather than a report. It becomes the network layer of an autotwin, which is what lets you test a disruption before it happens. See it applied in our supplier risk assessment case study.

Confident about tier one, unsure about everything below it?

Tell us your top product line. We will show you what a sub-tier map of it would reveal.

Start a conversation