We began with a consider of the definition of third-party. Gellert related, “Historically, people talked about simply an entity outside of your organization as a third party. However, that definition is broadening, to mean really that entity with which your company works.” Obviously, this can be a supplier or vendor, it can be a service provider, a customer, a joint-venture (JV) partner and/or an intercompany affiliate. A broader view could include intercompany affiliates as third parties, even though many people would see them as just being another entity inside of a business. Gellert said, “the definition of third parties is expanding, which only makes life more complicated for anyone trying to do third party risk assessments and then the tiering just creates an exponential change.”
Specifically, “in supply chain, a tier one supplier is one of the suppliers your organization is directly purchasing from. Next a tier two is one that your company’s tier one is buying directly from. This means for risk managers assessing the various risks of their supply chain have to go deeper and deeper. One way to do so is through trying to understand the connection between tiers one, two, three, four and so on. The problem is there are many risks that companies do not manage because they cannot identify which companies are taking risks.” Gellert further noted, “one of the hottest topics in 2019 for a supply chain and risk managers is trying to get their arms around how to handle this particular question.”
I asked Gellert how would he suggest a supply chain professional began to think through some of these issues articulated but in the context of a global supply chain? He began by stating, “anyone who is involved in third party or supply chain risk management needs to try to map out and understand the suppliers whose exposure they need to assess for their organization. Obviously, this includes both direct and indirect suppliers but in terms of the tiering, the best way for anyone to understand the supply chain risk is to have really good communication with their tier one suppliers to be able to discuss the risks to both businesses.”
Moreover, “this means communicating with a tier one supplier about who their tier ones are that are providing product or service that are coming to that client. Only with that type of transparency and communication can businesses look through the tier one into the sub tiers to understand the risk your organization has and where there may be a risk concentration. Without effect communication and dialogue, created and fostered as part of the relationship, people are going to fly blind.” Finally, in this global economy with such internationalization and diversification of supply chains, organizations you “really do need to pull out all the stops to try to manage risk. Communication is one of the first places to start.”
Gellert concluded with some thoughts on transparency, which he believes is not only important but “should be applied everywhere.” He said you should begin with your tier ones but the ability “to look deeper into the supply chain is also really important.” Further, Gellert said, “a lot of supply chain risk professionals can go wrong if they use transparency as a bludgeon as opposed to as an opportunity. Then the company they are asking for information from only sees risks in disclosing information as opposed to seeing commercial value and we promote transparency as a means to commercial value.” But it is more about fostering the relationship so that you can adequately assess and then manage the risk. Gellert noted, “that’s the key part, that people have to embrace if they’re going to be able to look deeper into their supply chains.”
Please join us tomorrow when we consider some of the challenges Gellert is seeing in supply chain risk management for 2019 and going forward.
This podcast series is sponsored by Rapid Ratings International, Inc. For more information, check out their website at www.rapidratings.com.
Tag: Supply Chain
Gellert began by relating that the word “criticality” is used quite a bit in supply chain and broadly on third-party risk. He defined it, “as a means of defining for a company which suppliers are most important.” Yet he also noted it can be defined in different ways at different times. Historically, criticality was more about how much money was spent with suppliers. In practice, this meant the top spend suppliers would be the ones that were most critical. Conversely, suppliers where you were spending a small amount of money were seen as less important. However, Gellert cautioned that while such an approach is still an important part of defining risk management programs “’it’s not the end of the story.”
He explained, “Criticality now really stretches out into a whole bunch of other topics, such as which third-parties, irrespective of how much money you spend with them, have the ability to disrupt your business if they are not performing for one reason or another.” Put another way, “Do they have the ability to sidetrack your business? Does it cause you a disruption that not only has a revenue impact on your organization, but may have a reputational impact on you? What about companies that may have access to your internal IT infrastructure and therefore pose security risks? They may not be a big spend, but they may have the ability to cause a cyber problem for you.” This means that cyber risk is one of the newest and most important risks that companies are focused on. Obviously, this means if a company uses, tracks and maintains private information of its customers or others, any supplier that has access to that information has a another set of critical elements to it.
Subsequently, when organizations are trying to evaluate criticality of suppliers, they may segment them in different ways and create different cohorts of suppliers. For instance, you may want to start with those who can create the most business interruption, those that can create the most reputational risk and impact and those that can disrupt revenue and cost the most amount of money. Gellert related, “all of those are elements of credit, quality, and innovation are really just about the movement of product services. Data analytics and business process that allows companies to manage all of those suppliers and all of those risks in a more cohesive way.”
All of this means that supply chain risk is really about an enterprise-wide risk. It includes, “the sourcing, identifying what companies to work with, perhaps many possible ones and then narrowing it down to the one you want to work with and move forward with the due diligence. The next step is ongoing, continuous monitoring to ascertain that the suppliers that can grow with the business. It is important that with the ups and downs of business cycles it can withstand the shock, coupled with the flexibility an organization needs to make the investments; that the supply chain partner continues to be a good business partner. All of those are really important as companies align with the best possible partners.” Risk management is really valuable for the compliance professional to know it is a part of a long continuous process over the lifecycle of working with a company. Gellert stated, “It’s not just about doing something that’s a part of an onboarding process for really, there’s a lot more longevity and value that can be created when looking at suppliers and applying supply chain risk management best practices.”
One of the innovations which RapidRatings has brought is through its Financial Health Rating (FHR). The FHR allows an organization “to look deeply inside a company and compare it against years of public and private company data. And in order to generate an FHR, RapidRating obtains the financial statements from private companies and we use the filing data from public companies.” It is a review of more than simply a company’s financial statement but a more comprehensive look at overall financial health correlated to lots of other risks that are valuable for people to understand.
One of the key reasons for the innovation of this approach is that, in the past, companies have tended to use payments scores and payment data from companies to understand whether they are good risks or bad. However, this is a “pretty antiquated way now of understanding the health of a company. It is the first opportunity to be able to give people comprehensive coverage of really all of the suppliers that they work with or customers that they work with in a very quick, fast and very precise way.” The FHR helps to make the risk management process more efficient in a workflow process. It does so in a manner at scale for companies around the world, in a very analytically way. This adds tremendous value to the entire process.
Please join us tomorrow when we consider the issue of third-party expansion in supply chain risk management.
This podcast series is sponsored by Rapid Ratings International, Inc. For more information, check out their website at www.rapidratings.com.
Too many suppliers can certainly be inefficient. This means that many companies are trying to trim down the numbers of third-parties with which they are working. This could be through adjusting time or implementing lean types of philosophies around supply chain. This makes each third-party partner more important and criticality is something that can be measured in lots of different ways. Gellert said it raised such questions as: “How much money you spend on a company? How much access will your third parties have access to company information? How much access will they have to your IT systems? All of these things have led to the evolution of a much more complex supply chain that people have to manage and they contain more risks.”
I asked Gellert how managing the risk and supply chain is different than managing on the sales side? He began by noting that there is “definitely overlap when looking at third parties.” Yet the more sophisticated method is a “360 degree” approach which means to look all aspects of the relationship. In the anti-corruption world, the focus has typically been on the sales side. But it can also “mean suppliers all the way through to customers and intercompany affiliates and so forth.” Another approach from the compliance perspective has been upon knowing your customer (KYC). Gellert stated, “Customer risk is inherently more transactional than supply chain risk, in part because of who’s buying and who’s selling. When you are selling to someone, you are evaluating their ability to pay you. In this situation an organization needs to make sure that the company is one you want to do business with, that’s going to be able to pay you on time and in the terms that determined are economical for you”
However, “when you are looking at suppliers, you’re buying from them, whether it’s a supplier of a product or a vendor of a service. You may have a five-year product cycle, a 10-year product cycle. If the suppliers your company is embedding into that portion of your business are not strong for the long-term or are not resilient, then you have problems that you are baking into the ecosystem of companies with which you are working.” Gellert concluded, “I think probably the biggest difference in customer evaluation and supply chain evaluations, you need to be able to understand the risks of those companies over the long haul as well as the short-term risks. So, you can avoid the short-term problems that could arise from a weak supplier.” It also means that you are “baking in the most resilient and strong long-term partners to work with, as you possibly can, into your organization.”
One of the frustrations for compliance professionals is that they do not know how far down the third party or supply chain they should go to either evaluate or manage the risk. They may understand who to go to for a direct counter-party, their immediate counter party, their first party supplier or their first party sales agent, they may certainly understand managing that risk. I asked Gellert how about much farther down the chain a compliance practitioner should begin to look at that issue? He said it can be quite complicated but that is where a technological solution can help.
He began by stating, “it’s not just first tier, second tier, third tier supplier in your supply chain may affect you.” One of the reasons it is so difficult for the compliance professional is there are so many areas you must consider. Gellert said these can include, “fraud detection, anti-money laundering, anti-corruption considerations and making sure that no one appears in a sanctions list. All of these things get more difficult exponentially as you go deeper into a supply chain and the people on supply chain risks sides who have been looking at delivery risk and logistics and other operational aspects including finance and newer elements like cybersecurity It gets really hard when you’ve got to go to your supplier’s supplier.”
The bottom line is that there is not a really good answer for this except that collaboration between a company and its first-tier supplier is really essential to understand what the second and third tier supplier risks will be. Unfortunately, “many times organizations do not even know who their second tier supplier is for particular good or product or service because the tier one supplier has been delivering fine and there has been no need to find out how or where that tier one is getting the parts that they are bringing in.” Gellert conclude by noting, this “is changing but needs to change more. It really does start with collaboration and an understanding between the company and its tier one suppliers that understanding the risk deeper than that is going to be important and beneficial to everybody involved in that chain.”
Please join us tomorrow when we consider the issue of criticality in supply chain risk management.
This podcast series is sponsored by Rapid Ratings International, Inc. For more information, check out their website at www.rapidratings.com.