I have had a lot of conversations with colleagues, friends and family lately, trying to make sense of the crises unfolding around us. How will conflicts affect our day to day? How often should we expect extreme weather? Are we doing enough to protect ourselves from digital threats? It is clear we are all feeling a little overwhelmed. That we are grappling for a sense of control.
As disruption continues to shake up the supply chain, companies are doing all kinds of things to get a handle on the problems at play. A lot of organizations are turning to audits, reports and dashboards. Amidst the chaos, it is natural to retreat to what you know. Familiar risk and compliance routines provide reassurance. You want to feel like you are doing something to restore order. To understand what went wrong, so you can return to business as usual.
Still, as the first chapter in our MESH series revealed, there is only so much common risk management practices can do in this era of permanent disruption. Supply chains need to be dynamic in response to evolving challenges. Especially where these challenges meet and intensify. Static solutions might simulate control, but there is a good chance they are leaving you unprepared for future shocks.
Are you auditing too much?
Supplier audits have become the go-to tool for supply chain risk management. If you hit a rough quarter, an audit of your biggest suppliers will help you expose issues, uncover inefficiencies and show stakeholders you are taking action. In the face of uncertainty, it is easy to see why this is tempting.
But we are at risk of overkill. A typical supplier will be audited in areas like ESG, quality and security, each by different clients or agencies, with strikingly similar checklists. It is no surprise that audit fatigue is on the rise. When issues arise, your suppliers exhaust resources fixing paperwork, not the problems that will make a difference.
While passing audits feels like progress, the data tells us otherwise. Despite heavy auditing, three in five companies have ‘low maturity’ in supplier assurance and business continuity planning. This is because audits are static and treat issues in isolation. They might verify compliance at a moment in time, but they do not guarantee you can respond to unknown crises. It is like navigating a storm with yesterday's weather forecast. By focusing on known issues or past problems, you risk missing emerging challenges.
Audit results can be useful when integrated into strategy and decision making. But too often they are filed away. Without meaningful follow-up, finding an issue does not translate into fixing challenges long-term.
Is your data driving action?
In an effort to make your audit data useful, you might develop dashboards. Sophisticated heat maps and risk scoring algorithms can increase transparency and inform your KPIs. By providing a clear picture of where you sit against key metrics, they are a helpful tool for monitoring and sharing information with stakeholders. Like audits however, most dashboards suffer from volume over value.
Take the retailer who spends time tracking 20 risk indicators. All presented in an advanced dashboard showing improvement or stability across every metric. One KPI shows it has audited 95% of suppliers. Lead time variability is steady. Order fill rate sits at 97%. The retailer believes it is in a strong position. Able to tackle risk head on. But, when a sudden flood hits a tier 2 supplier, it causes a major supply shortage. The retailer is left floundering. None of the indicators predicted it. What went wrong?
Monitoring is not the same as managing. Among so many metrics, critical risk signals can get lost. You might feel confident because you have audited 95% of your suppliers. But the real question is what those audits changed. Is your data driving action? Even if a ‘red flag’ appears, when no one is responsible for solving it, the problem is likely to persist.
Data without accountability leads to complacency. Fancy dashboards might provide comforting optics. But unless they are paired with actionable insights and clear ownership, they will do little to boost your resilience.
Who takes ownership?
Audits and dashboards are often the product of siloed risk management practices. 39% of organizations report siloed decision-making between functions. Here lies part of the problem. Traditional corporate structures assign different areas of risk to different teams. Your sustainability team audits suppliers for environmental and social risks. Procurement reports on supply continuity. While security publishes a supplier security scorecard. Ownership might seem clear. But, if there is no thread tying data together, connecting it to central decision making, risks start to fall through the cracks.
Let's go back to the retailer whose tier two supplier was hit by a flood. Climate risk created an operational risk. Its manufacturer could not get the components it needed, causing a production shutdown. This, in turn, triggered a legal risk. The retailer found itself unable to fulfil customer contracts.
Siloed approaches to risk management limit visibility. They leave blind spots where risks do not fit into departmental boundaries. The retailer's sustainability team may have clocked the risk of flooding but not understood how its impact might cascade. The business is less prepared and more vulnerable as a result.
Without a unified view of risk, teams can assume someone else will handle the issues that fall outside their direct remit. This becomes a bigger problem when different groups have different definitions of high risk, inconsistent risk tolerance or conflicting priorities. In this case, sustainability leaves business continuity to operations and contractual liabilities to compliance. Yet, neither of those teams are tracking flood alerts or how weather events might affect their responsibilities. By the time the operational and legal consequences become clear, the window to prepare has already closed.
All too often, the teams that manage supply chains daily are only engaged after a crisis. When you leave procurement, operations and logistics out of planning, it becomes much harder to prevent supply chain fall out. What appears on a risk register, may not reflect the reality on the ground. You need practical knowledge from the front lines to understand how disruption will affect your factories, warehouses or shipping lanes.
Specialized teams are both necessary and valuable. But their greatest strength comes when they work together. Without a connected, cross-functional approach, your ability to control risk is incomplete.
What are your reports telling you?
Traditional risk management creates an illusion of control. Static data, limited accountability and siloed responsibilities all combine to create a gap between your reported risk and resilience in practice.
Annual reports assure stakeholders with high audit counts, certifications and dashboard reviews. But aggregate metrics are misleading and often disguise vulnerabilities, in particular where teams are failing to connect. Your annual sustainability report might boast a low supplier risk rating, alongside hundreds of completed audits. Yet a factory fire at one of your suppliers still cripples production for weeks. An investigation reveals you knew the risk of single sourcing, yet it was buried in paperwork with no action assigned. Your board might have received a glowing risk report. But operations - and your bottom line - bore the brunt of an unmitigated problem.
72% of executives consider supply chain resilience a board priority. Still, over 60% rate their maturity as “basic” or “ad hoc” in areas like logistics, continuity and supplier assurance. While only 38% have multi-tier supplier visibility. Foundational capabilities like this are the true markers of resilience. How quickly can you respond to a disruption? How well do you teams coordinate? Do you know what is happening at your tier 2 suppliers?
Many organizations, despite investing heavily in risk management processes, remain unprepared. Reports create a comforting narrative, but they only provide a snapshot. They show you what is already known and measured, often broken down across different functions, rather than painting a full picture. As new exposures emerge, the gap between reporting and resilience is becoming more apparent. You need a risk approach that will hold up in a real crisis.
How do you start to bridge this gap?
In this era of permanent disruption, we are all wrestling for control. Frequent audits, impressive dashboards and specialized teams might seem like the logical answer. These familiar tools can help you uncover issues, make sense of data and build a sense of security. But there is a big difference between having risk documentation and showing real resilience.
Audits should be continuous, risk-prioritized, and embedded within a broader resilience strategy to ensure they add value. Your data should provide actionable insights. And it should be clear who is responsible for taking those actions forward. You need to bring different teams together, actively involving core business functions such as procurement and logistics. Make ownership clear, but from a place of collaboration, not siloes. In doing this, you will build ongoing visibility, allowing you to report what is actually happening and laying the groundwork for true risk readiness.
This is not to say you should scrap everything you have been doing to date. But ask yourself, what really builds resilience? By focusing on capabilities, rather than scattered, box-ticking activities, you can transform your ability to navigate disruption. In the next chapter, we will look at how you can establish a maturity-based approach to resilience and replace perceived control with genuine preparedness.
Before we do, have a think about the following:
- How many audits have you done in the last 12 months? How many results were integrated into strategy?
- Are your audits driven by risk assessment, selected at random or based on supplier value?
- Do your dashboards show improvements in value at risk, or just improvements in compliance?
- Do your dashboard insights lead to clear actions?
- Are you managing risk in silos? Are teams aware of the risks others are monitoring?
- How many resilience wins have you reported in the last 12 months? Were they real or simply on paper?
- How do you measure resilience? Is it simply compliance or are you also considering disruption frequency, recovery time, a combination of these?
If these questions make you uncomfortable, it is probably time to explore a new approach to risk management. Check out chapter three of our MESH series to find out what this might look like.