Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Supply Chain Updates

How agencies can start catching up on supply chain risk management

usscmc by usscmc
February 11, 2021
How agencies can start catching up on supply chain risk management
Share on FacebookShare on Twitter

This content is provided by EY.

When the Government Accountability Office (GAO) investigated the supply chain risk management practices of the 23 civilian CFO Act agencies in late 2020, the results were concerning. It found that none of those agencies had fully implemented seven critical supply chain risk management (SCRM) practices outlined by the GAO and grounded in guidance from the National Institute of Science and Technology (NIST), and 14 agencies hadn’t begun implementing any of them at all.

“As a result of these weaknesses, these agencies are at a greater risk that malicious actors could exploit vulnerabilities in the [information and communications technology] supply chain causing disruption to mission operations, harm to individuals, or theft of intellectual property,” GAO said in the report. “For example, without establishing executive oversight of SCRM activities, agencies are limited in their ability to make risk decisions across the organization about how to most effectively secure their ICT product and service supply chains. Moreover, agencies lack the ability to understand and manage risk and reduce the likelihood that adverse events will occur without reasonable visibility and traceability into supply chains.”

And one thing that really drove home the importance of supply chain risk management, according to Alex Gurney, a principal at EY, is the pandemic. Shortages in toilet paper early on, followed quickly by hardware shortages as businesses scrambled to equip their new stay-at-home workforce, forced the public and private sector alike to examine where their goods and services came from.

“When we talk about supply chain risk management, the first thing you need to know is who are your suppliers?” said Gurney. “Where do they reside, where are their operations? Is it domestic, is it non-domestic, and who are the suppliers in their supply chain that they rely on to support your mission?”

In the public sector, supply chain risk management tends to go hand in hand with cybersecurity in most conversations. Kaspersky and Huawei were the early warnings, perfect examples of why supply chain risk management is important. SolarWinds became the cautionary tale of what happens when the weaknesses get exploited.

But cybersecurity isn’t the only domain in which the supply chain poses a threat. It’s about goods, services, finances, maintenance and repair. For example, if the Defense Department has a radar system that relies on a part that comes only from a single supplier, that’s a vulnerability. If the business supplying the part is mismanaged and goes under, the inability to obtain a $20 replacement part could cripple a multimillion-dollar defense system.

That’s why, Gurney said, it’s imperative that federal agencies finish implementing the guidance outlined by NIST.

“There are ways to accelerate a program like this and get it up and running quickly,” she said. “We’ve established a SCRM program for the Department of Energy, and there is a lot of market data out there that agencies can leverage. Also, agencies could benefit from each other’s efforts, because most agencies share a common set of contractors and suppliers.”

At DoE, EY helped establish a SCRM program that enables leadership to make risk-informed decisions and reduce the risk introduced by suppliers. The SCRM program identifies, assesses, helps to mitigate and monitors supplier risks: the greater the potential risk a supplier presents to DoE’s supply chain, the greater the diligence conducted to assess the supplier.  The program assesses suppliers across multiple risk lenses to include financial, cybersecurity, geo-political, corruption and foreign interest. Applying multiple lenses enables a more complete picture of the health of the supplier. For example, a particular supplier might not be financially viable or it may rely on multi-layered subcontractors to provide a product, each layer of which needs to be analyzed for potential risks.

“So, we do the analysis and establish a risk profile, from which management can make a risk-informed decision and evaluate options to reduce any risks identified,” Gurney said. “We built it to be scalable and customizable, so it can continue to expand quickly and adapt to constantly changing requirements and supply chain threats.”

This solution combines open source, subscription-based, and federal-based information about suppliers with control-based questionnaires and the suppliers’ potential impact on the agency to build supplier risk profiles. And while it does provide mitigation strategies to lessen supply chain vulnerabilities, Gurney also sees it being used proactively. For example, during the procurement lifecycle, agencies could utilize this process and factor this information into the awards process.

And because supplier data can be leveraged across the entire government, Gurney recommends that agencies develop a common service, such as that at the DoE, to develop a robust database of supplier risk information. Leveraging programs and processes already in place could also provide a jumpstart to agencies that have yet to begin implementing supply chain risk management guidance.

“Despite numerous conversations I have had with various clients about this issue, I don’t see a lot of agencies taking really accelerated action to address it. And then we see things like SolarWinds happen,” Gurney said. “Developing an initial supplier risk assessment is a very quick action and took our team only 2 weeks to establish at DoE, but I think there are a lot of steps that are involved in setting up an integrated program. And it really starts with executive sponsorship, just like anything else.”

 

To learn more, join EY for a knowledge sharing series focused on SCRM. Register here for the first session: Supply Chain Risk Management: Make risk-informed decisions before you buy. During this session, we will be discussing the value of assessing suppliers and how to implement an effective SCRM program to minimize risk across the supplier base.

usscmc

usscmc

No Result
View All Result

Recent Posts

  • How Hapag Lloyd captured a major market share in the Container Shipping Industry in USA
  • Why USA’s East Coast is the Favorite Destination for Manufacturing Companies
  • How Trade Relations Between the USA and UK Improved After Keir Starmer Became Prime Minister
  • Tips and Tricks for Procurement Managers to Handle Their Supplier Woes
  • The Crazy Supply Chain of Walmart Spanning Across the Globe

Recent Comments

  • Top 5 Supply Chain Certifications that are in high demand | Top 5 Certifications on Top 5 Globally Recognized Supply Chain Certifications
  • 3 Best Procurement Certifications that are most valuable | Procurement Newz on Top 5 Globally Recognized Supply Chain Certifications

Archives

  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019

Categories

  • Global News
  • Supply Chain Updates

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
  • Antispam
  • Contact Us
  • Disclaimer
  • Home
  • Privacy Policy
  • Terms of Use

© 2025 www.usscmc.com

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us

© 2025 www.usscmc.com