Home

The Risk Management Process: Identifying, Classifying, and Scoring Risks in the Supply Chain

|
|  Updated:  
2020-04-14 21:12:42
Supplier Diversity For Dummies
Explore Book
Buy On Amazon
Managing your supply chain always comes with risk. If you hope to mitigate those successfully, you’ll need to understand the risks you may be facing. Use this guide to identify, classify, and score risk in your supply chain.

Identifying risks in the supply chain

The first step in managing risks in a supply chain is identifying them. You probably have a good idea of some of the things that could go wrong with your supply chain. To really understand the scope of risks, however, you need to get input from other people who see, understand, and manage different parts of the supply chain.

Following are some of the groups you should include in your process to identify supply chain risks:

  • Transportation
  • Distribution/warehousing
  • Purchasing
  • Information technology
  • Accounting and finance
  • Legal
  • Sales and marketing
  • Key customers
  • Key suppliers
It might be easiest for you to reach out to each of these groups separately, but you could also invite all of them to join a supply chain risk management committee. However you choose to engage this team, use their input to make a list of the risks that could affect your supply chain.

You can create this list by brainstorming, and you may need to give people some ideas to prompt their thinking. Here are some risk categories that you can ask your supply chain team members to think about:

  1. Accidents
  2. Crime, terrorism, and war
  3. Financial problems
  4. Government regulations and politics
  5. Management problems
  6. Manufacturing problems
  7. Market trends
  8. Natural disasters and epidemics
  9. Supplier problems
  10. Surge in customer demand
  11. Technology trends
  12. Transportation and distribution problems
  13. Workforce and training issues
Getting people to think about these risks in concrete terms and write them down tends to be an eye-opening experience. The odds that any one of these risks will materialize may be low, but the odds that at least one of them will materialize is high. It’s a good bet that something will surprise you, but you have no way to know which thing it will be.

Classifying risks in the supply chain

Once you have identified your supply chain risks, you need to decide which risks are most important. You may be most concerned about the risk of a fire at your supplier’s distribution center, for example, or with the risk of disease outbreak that would shut down travel between countries.

One approach is to classify risks according to their scope. Classifying risks according to their scope is useful when you want to decide how — or whether — to mitigate them. Risks fall into three general scope categories:

  • Global: Risks that affect everybody in the world. Managing global risks is the responsibility of senior management, but your risk management planning can ensure that your leaders are aware of the global risks and their potential effects on your supply chain.
  • Systemic: Risks that affect more than one facility or company. These risks could disrupt the entire supply chain, not just its parts. Systemic risks are especially important in supply chain risk management because you are looking at how all of the companies in a supply chain contribute to delivering value to a customer. Many times, people don’t realize how severe a systemic risk can be because they think about it in terms of how it affects them locally rather than how it affects the rest of the supply chain. The responsibility for managing systemic risks is often shared between leaders in several different companies, so these companies need to collaborate in order to manage the risks effectively.
  • Local: Risks that affect the people in a particular company or facility. Local risks are the responsibility of facility and operations managers and are often addressed in a business continuity plan. Your supply chain risk management process can be useful in ensuring that each of these separate plans are complete and properly aligned.

Scoring risks to the supply chain

After you identify and classify the risks in your supply chain, the next step is scoring them. Risk scores can help you prioritize which risks you need to be most concerned about.

You score risks based on how likely they are to occur (the probability) and how severe their effects would be (the impact). Then you multiply these scores together to get an overall risk score. There are many different scoring systems for probability and impact ratings, but here’s an example to get you started.

On a scale of 1 to 10, assign a value to the likelihood that a risk will occur in your supply chain:

  • 10: Will occur; 100 percent probability
  • 5: May occur; 50 percent chance
  • 1: Very unlikely to occur; 10 percent chance, or less
Use a scale of 1 to 10 to assign a value to the impact of a risk on your supply chain:
  • 10: Would stop the supply chain or cost someone his or her job
  • 5: Would be a major problem taking days to fix but wouldn’t stop the supply chain from operating
  • 1: Would create a problem that the supply chain can handle in the normal course of business
Use a scale of 1 to 100 to categorize the risk score after you multiply the probability value by the impact value:
  • 100: This risk needs to be resolved immediately.
  • 50: This risk needs to be monitored closely and mitigated effectively.
  • 25: The company should have a mitigation plan in place for this risk.

A risk can never have a zero score for either probability or impact. If the score is zero in either category, it isn’t a risk.

The document that you use to track and score risks is called a risk register. The table below shows a typical risk register.
Supply Chain Risk Register
Risk Probability Impact Risk Score
Port strike 9 9 81
Supplier fire 3 9 27
Forklift breakdown 6 1 6
Comet strike 1 10 10
Canceled customer order 8 6 48
If you create your risk register in a spreadsheet program, such as Microsoft Excel, you can sort your risks according to the risk scores. You can also create reports and graphs so that you can communicate the status of your risks more clearly.

A common way to visualize risks is to use a risk plot or a heat map. The image below shows an example heat map for supply chain risks.

Supply chain risk heat map Supply chain risk heat map.

Risk scoring is handy but not perfect. Just because a risk gets a low score doesn’t mean that you should ignore it, especially if the potential impact is severe. Any risk that has the potential for someone to get hurt needs to be addressed, even if the probability (and the risk score) are low.

Risk scoring is like taking a snapshot of risks as they are today. You should keep your risk register up to date as circumstances change, watch for new risks to appear, and monitor changes in the scores of existing risks.

Want to learn more? Use this guide to learn how to make a risk-management plan.

About This Article

This article is from the book: 

About the book author:

Daniel Stanton is known as "Mr. Supply Chain." His books are used by students and professionals around the world, and his courses on LinkedIn Learning have been viewed more than 1 million times. He holds numerous industry certifications, including Certified Supply Chain Professional (CSCP) and SCPro.