Skip to content

Supply-Chain Dependency Review

Procedure — instantiates Common-Mode Failure Analysis

Traces whether alternate suppliers, logistics routes, components, or raw materials share sub-tier vendors, regions, infrastructure, labor constraints, or regulatory chokepoints.

Two suppliers with different names and different contracts can still fail together the moment you follow their supply chains far enough down. A Supply-Chain Dependency Review is the procedure that walks each "alternate" source downstream through its tiers — its sub-suppliers, its raw-material origins, its ports, its regions — to find where the supposedly independent chains re-converge on a single physical or geopolitical dependency. Its defining focus is the shared physical and regional environment: the same foundry three tiers down, the same rare-material region, the same shipping strait, the same regulatory jurisdiction that can embargo both at once. It works in the world of shipped goods and geography, not logins and pipelines, and its product is a judgment on whether a named set of alternate sources is genuinely diverse or is two labels resting on one chokepoint.

Example

An automaker sources a critical microcontroller from two vendors — one in one country, one in another — and treats that as protection against a single supplier's outage. The Supply-Chain Dependency Review traces both chains down tier by tier. Vendor A and Vendor B design and package their chips separately, which is where a shallow check stops and declares independence. But three tiers down, both outsource wafer fabrication to the same contract foundry in a single region. And both that foundry and its neighbors depend on a specialty gas refined predominantly in one other region subject to its own export controls.

The review's finding is stark: "two suppliers" is one supplier below the packaging tier, and even that one foundry sits behind a regional raw-material chokepoint shared across the industry. It names the redundancy set (Vendor A, Vendor B) and scores it against a real diversity standard — different fabs, different regions, different material sources — which the pair fails. The remediation is not "add a third packager" but "qualify a source whose fabrication and material origin actually diverge." Procurement's language for this is the difference between multi-sourcing and multi-sole-sourcing: two vendors, one sole-source sub-tier, is not redundancy.[n1]

How it works

The review is a downstream traversal of the physical chain:

  • Name the alternate-source set. Fix the suppliers, routes, or materials being treated as substitutes for one function, so the review scopes a redundancy claim rather than a purchasing list.
  • Trace each chain down its tiers. For every source, follow sub-suppliers, component origins, and raw materials as far down as consequence justifies — the convergence usually hides below tier one.
  • Overlay for shared physical exposure. Compare the traced chains for a common sub-tier vendor, region, port, transport corridor, labor pool, or regulatory jurisdiction.
  • Score against a diversity standard. Judge whether the alternate sources meet an explicit requirement for geographic, material, and jurisdictional separation, and flag the tier at which independence collapses.

Tuning parameters

  • Tier depth — how many sub-tiers down the trace goes. Deeper finds the shared foundry and the shared mine; shallower is faster but stops above most real chokepoints.
  • Exposure axes — which shared-environment dimensions you check (region, port, material origin, labor, jurisdiction, climate). More axes catch subtler convergence; too many stall the review.
  • Separation standard — how much geographic and material diversity counts as enough. A strict standard rejects fragile pairs but may exceed what the market can supply.
  • Consequence gating — which functions warrant a deep multi-tier trace versus a tier-one check. Focusing depth on the highest-consequence parts keeps the review finishable.
  • Visibility method — supplier self-disclosure versus independent mapping. Self-disclosure is cheap and often incomplete; independent mapping is costlier and truer.

When it helps, and when it misleads

Its strength is defeating the "two suppliers" illusion at the tier where it actually breaks: only a downstream trace reveals the shared foundry, the single strait, or the one region that a first-tier comparison certifies as diverse. It reframes redundancy spending toward the separation that matters — different origins — rather than duplicate contracts over a shared base.

Its failure mode is depth exhaustion: real chains fan out into thousands of sub-tier suppliers, visibility fades below tier two, and the review either stops too shallow or drowns. A classic misuse is accepting supplier attestations of diversity without independent verification, so the mapped chain is the chain the vendors chose to disclose, not the real one, and the shared sub-tier stays hidden. The guarding discipline is to gate depth by consequence, verify the decisive tiers independently, and treat un-mappable depth as itself a flagged residual exposure rather than assumed independence.

How it implements the components

  • common_environment_check — its core test: whether alternate chains share a physical or regional environment (a foundry, a port, a material region, a jurisdiction).
  • diversity_or_isolation_requirement — it scores the alternate-source set against an explicit standard for geographic, material, and jurisdictional separation.
  • redundancy_set — it defines and sharpens the set of alternate sources whose independence is under review.

It works in the physical-goods lane and does not trace digital coupling: it does not build the identity-and-infrastructure shared_dependency_map or size the control-plane blast_radius_model of its nearest twin, Credential and Infrastructure Dependency Audit, which follows logins, networks, and pipelines rather than foundries, ports, and materials.

Editorial Notes

Form Classification

Form family: Assessment, Review & Assurance

Rationale: Supply Chain Dependency Review is defined in the frozen evidence as: Traces whether alternate suppliers, logistics routes, components, or raw materials share sub-tier vendors, regions, infrastructure, labor constraints, or regulatory chokepoints. Its operative deployed or enacted form is therefore Assessment, Review & Assurance.

Nearest alternative: Experiment, Test & Rehearsal — Experiment, Test & Rehearsal can support this mechanism, but the evidence centers the concrete operation described above rather than the alternative family's defining operation.

Review outcome: Adjudicated after independent review; high confidence.

Origin Attribution

Primary origin: Logistics & Supply Chain Management

Origin pattern: Single lineage

Present-day reach: Universal

Rationale: Tracing critical dependence on tiers and nodes is core supply-chain risk management.

Related originating lineages:

  • Operations Research — Operations research, optimization, and queueing analysis supplies a parallel or contributing lineage for the mechanism's defining operation: traces whether alternate suppliers, logistics routes, components, or raw materials share sub-tier vendors, regions, infrastructure, labor constraints, or regulatory chokepoints.
  • Systems Thinking & Cybernetics — Network dependency analysis reveals propagation paths.

Review resolution: The blind reviewers agree that logistics_supply_chain is the primary origin and differ only on alternate origin disagreement, domain reach disagreement, encyclopedia synthesis disagreement. I preserve every independently explained alternate from both records rather than imposing a numeric cap. I retain single_lineage because the combined evidence shows one traceable formative lineage. The broader reach of universal records portability separately from historical provenance; encyclopedia_synthesis=true preserves the affirmative synthesis judgment where either reviewer identified one.

Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.

Review outcome: Reconciled after independent review; high confidence.

Notes

[n1] In procurement, single-source means one supplier is chosen among several available, while sole-source means only one supplier exists at all. Two alternate vendors that both depend on a sole-source sub-tier component are single-sourced at the top and sole-sourced underneath — the exact false-redundancy structure this review is built to expose.