...

A 3-step guide to Supplier Risk Mitigation: COVID-19 and beyond

Picture of Zycus

Zycus

Published On: 12/18/2020

Listen to this blog

Supplier Risk mitigation

Listen to this blog

Supplier risk mitigation has become very important, especially in these times. The two key themes to come out of 2020 from a procurement and supply chain standpoint have been risk mitigation and cyber threat. As the pandemicโ€™s effects started to grow, organizations found their business continuity plans (BCPs) being thrown out of the window.

Over dependency on one supplier or a small group of suppliers from one region dealt with organizations a heavy blow. They also saw their supply chains crumbling under the pandemicโ€™s weight.

With time, organizations did find ways to get their supply chains back up and running. However, with more digital technologies being used than ever before, a new and enhanced cyber-threat problem emerged. Suddenly organizations found themselves fighting off phishing attacks, fraud, duplicate invoices, and guarding themselves against data leaks to ensure that their businesses donโ€™t suffer anymore.

Given that the pandemic has disrupted our ways of working not just for 2020 but for the near future, these two challenges will be a constant for procurement and supply chain professionals. This is why we thought of putting together a few key points that you can incorporate into your strategy to conquer supplier risk and cyber threats in 2021 & beyond.

Limitations of Pre-COVID-19 Supplier Risk Mitigation Strategies

A majority of organizations across the globe were caught in a fix as soon as the pandemic hit as they had little to no visibility beyond their Tier-1 supplier. As the pandemic wore on, Tier-2 and Tier-3 suppliers were unable to feed the supply line either due to lockdowns or due to longer payment terms, which resulted in a cash flow crunch for them, eventually force them to halt production.

As Bruce Everett, CEO APAC, IACCM suggested in one of Zycusโ€™ webinar earlier this year, organizations and nations expected the pandemic to impact them or maybe a couple of their neighbors, but no one expected the whole world to come to a standstill.

This sums up what most organizations were thinking when the pandemic hit. For them, the immediate reaction was to assess if their key suppliers were under threat. Most organizations missed looking beyond their primary suppliers and evaluating the extent of the damage across the whole of the supply chain.

For organizations whose primary suppliers got impacted, a subsequent challenge was looking for a new supplier or a pool of suppliers who could fill in the gap. Unfortunately, most years of dependence on a select few suppliers and an impaired Supplier Information Management system made this search a tedious process.

Even though a majority of organizations found a make-shift way out of this fix, the question is, how do they find a long-term solution and account for any significant disruptions in the future? Hereโ€™s a quick look at a 3-step approach to better managing supplier risks.ย 

Download our whitepaper: Supplier Risk Management Framework: A Comprehensive Approach to Mitigating Supplier Risks

A 3-Step Approach to Better Supplier Risk Mitigation

supplier risk mitigation

1.ย Assess:

According to a Gartner survey,ย 89%ย of companies experienced a supplier risk event in the last 5 years, yet their awareness and plans to mitigate it lacked maturity.

What organizations need is a holistic 360ยฐ view of supplier risks, which factors in various types of risks viz. operational risks, Geo-political risks, financial risks, legal and global compliance risks, reputational and information security risks, etc., and isnโ€™t only limited to the primary supplier but takes into account the supplierโ€™s supply chain as well.

In addition to external risk coverage, organizations also need to monitor supplier performance through risk assessment scores continuously. Supplier risk and performance management KPI benchmarks and scorecardsย can come in handy in ensuring the right parameters are being set and monitored.

2. Manage:ย 

Once the correct KPIs are set, organizations can periodically review their suppliers performance evaluationโ€‹ย and segment them based on their risk scores. This way, they have a clear view of whoโ€™s the most impacted due to any of the possible risk factors stated above and who has a healthy supply chain.ย 

Suppliers whose risk and performance scores go below the minimum threshold can be asked to undertake SCAR (Supplier Corrective Action Request) programs.

3. Monitor:

The final piece of the puzzle is continuously keeping an eye for events and news across various parameters on a real-time basis. Automated alerts, risk trends, surveys, etc., can help organizations stay ahead of the curve. They can also be prepared for a black swan event like the pandemic.

While the above steps seem logical and easy in theory, organizations have struggled to put these into place due to a lack of technology improvisations over the past couple of years. Manually keeping a check on supplier performance management, looking for news and events across the globe, and deriving insights into possible impact on the supply chain on a real-time basis is not possible.ย 

This is why organizations need to adopt modern-day technologies such as Artificial Intelligence (A.I.), which can help. Gartnerโ€™s survey says that companies that use risk mitigation technologies are almost twice as effective as those that donโ€™t.ย 

Download our whitepaper: Ensuring Efficient Supplier Risk Management with Supply Chain Transparency

The Information Security Conundrum

According to INTERPOLโ€™s assessment of the impact of COVID-19 on cybercrime, thereโ€™s been a stark increase in the number of cyberattacks on major corporations, governments, and critical infrastructure ever since people started working from home.

supplier risk mitigation
Source: INTERPOL REPORT SHOWS ALARMING RATE OF CYBER ATTACKS DURING COVID-19

This is a cause of worry and caution for procurement teams, which may be looking to rapidly onboard new suppliers to fill in the gap created by their primary suppliers going bust. This may lead them to do a sub-par risk assessment of new suppliers. Also, this leaves the door open for fraudulent suppliers to enter their systems.

Thereโ€™s also been an exponential increase in the number of fake or duplicate invoices sent to the AP teams across commercial and Government organizations. Given the number of queries and emails that AP teams get during a day, manual oversight may result in fraudulent invoices getting passed as valid invoices and payments being made.ย 

With manual processes and systems in place, organizations will find it challenging to counter any such attacks, resulting in large-scale financial losses. Therefore, they need an automated tool such as the Zycus Merlin Invoice Reader BOT, which can go through invoices, extract line-level information, and highlight any fraud or duplicate data while ensuring no financial losses are incurred by the organization.ย 

An A.I. system also helps raise a red flag in case any of an organizationโ€™s supplier is impacted by a cyber attack or data theft. Organizations can immediately act upon such instances. Also, they can reach out to their suppliers to check if their data was stolen or compromised. Hence, they can then take corrective actions if required.

Conclusion

COVID-19 was an eye-opener for organizations who believed that their supplier risk and business continuity plans were fool-proof. Having limited or no visibility beyond the primary supplier and relying on manual systems to identify and iron out any potential risks proved detrimental. What made matters worse was the barrage of cyberattacks aimed at maximizing the fragile systems in place, especially with people working from home.

The need of the hour calls for organizations to have a holistic approach to supplier risk mitigation. This can be done by using advanced A.I. engines. Also, having a healthy and diverse pool of suppliers, which can be segmented according to their risk scores on a real-time basis, helps organizations make the right moves to circumvent any adverse situation and gain a competitive advantage over their peers. Governments can use such systems to ensure enhanced security and that none of their tax payerโ€™s money goes to waste.

Schedule a demo to learn more about how our AI-powered supplier risk management solutions can help you transform your supplier risk management practices and build a more resilient supply chain.

Related Read:

  1. Blog โ€“ How to Effectively Mitigate Supply Chain Risk in the Manufacturing Sector
  2. Blog โ€“ 4 Formulas for Supplier Risk Management
  3. Blog โ€“ Vendor Landscape: Supplier Risk And Performance Management
  4. Zycusโ€™ iSupplier, Supplier Information Management Software
  5. White paper โ€“ Ensuring Efficient Supplier Risk Management with Supply Chain Transparency
  6. TechWatch: Transform Supplier Risk Management with iRisk
  7. A Comprehensive Guide to Supplier Risk Management
  8. Solution: Supplier Management Software
  9. Solution: End-to-End Supplier Risk Management Software Powered by GenAI

CPONext: 30 Procurement Leaders to Watch Out For โ€“ SEA Edition

CPO Next - Horizon SEA 2025
Share:

Explore our latest Resources

Subscribe to Blogs!

Get the latest blogs, insights, tips and exclusive content delivered to you inbox, Join Now

Contact us today to know more about Zycus Deep Value Procurement AI

Name
Full name*
Company E-mail*
How can we help*