Supply Chain Risk Project Report
Supply Chain Risk Project Report
by The Supply Chain Council Risk Research Team Assembled and Edited by: Dr. Kevin McCormack Taylor Wilkerson Dave Marrow Melinda Davey Mitul Shah Deanna Yee
June, 2008 Abstract SCC members have reported that less than half of enterprises have established metrics and procedures for assessing and managing supply risks and organizations lack sufficient market intelligence, process, and information systems to effectively predict and mitigate supply chain risks. From this need arose the Risk Management Project Team approved by the SCC to enhance the SCOR model. The objective is to help organizations avoid/minimize costs, mitigate supply chain disruptions by managing risk proactively and thus, offering a competitive edge. This paper presents the outcome of a global multi-industry team that has worked passionately to achieve the same. The SCOR model is now integrated with processes that identify potential risk elements throughout the supply chain, define metrics to assess the potential impact of these risk elements and enable companies to control impact and mitigate service disruptions. Objectives of this paper This paper will describe the results of a project chartered by the Supply Chain Council that investigated and developed an approach for including supply risk management activities within the SCOR model. This paper will cover the background, approach, results and recommendations for including supply chain risk management within the SCOR model.
Table of Contents
TheSupplyChainCouncilRiskResearchTeam_________________________________________ 3 Background ____________________________________________________________________ 6 ProjectResults __________________________________________________________________ 9 DetailedRecommendations ______________________________________________________ 13
EnablerProcessModel ________________________________________________________________ 13 MetricsValueatRisk(VAR)___________________________________________________________ 15
VARDefinition _____________________________________________________________________________16 VARExample ______________________________________________________________________________18
BestPractices _______________________________________________________________________ 21
SupplyChainRiskManagement _______________________________________________________________21 SupplyChainRiskIdentification _______________________________________________________________22 SupplyChainRiskMonitoring _________________________________________________________________23 SupplyChainRiskAssessment ________________________________________________________________23 SourcingRiskMitigationStrategies ____________________________________________________________25 CrisisCommunicationsPlanning _______________________________________________________________25 RiskManagementProgramsCoordinationwithPartners ___________________________________________26 ConfiguretoReduceRisk:SupplyChainBusinessRules ____________________________________________26 ConfiguretoReduceRisk:SupplyChainInformation ______________________________________________27 ConfiguretoReduceRisk:SupplyChainNetwork _________________________________________________27
Due to the new relevance that the concept of risk has assumed, risk management concepts and approaches have been studied and formalized in the past and have been around for several years, but have generally been focused in the financial, project management or safety areas. Such concepts and approaches are generally not immediately suitable for use in the supply chain management arena, since they should be fitted to a completely different context than those they have been thought to. But, before the definition of risk managing model and methods, one of the key question it is worth to consider is: what is the benefit of Supply Chain Risk Management (SCRM)? According to a recent research report from Aberdeen (Figure 1), it leads to not only cost avoidance by reducing the probability and impact of disruptions it leads to performance improvements.
Figure 1. SCRM Benefits Once the importance of managing risk has been assessed, the further step is to define suitable models to analyze, assess, manage and communicate risk within a company as well as in a complex, geographically dispersed supply chain composed by several, legally independent entities. With these issues in mind, a team of Supply Chain Council (SCC) members have conducted a multi-year long project to incorporate the processes, practices and metrics of Supply Chain Risk Management (SCRM) into the Supply Chain Operations Reference Model (SCOR). The purpose of this paper is to provide an overview on the fundamental concepts of supply chain risk management, detailed the process used by the research team and present their findings. In addition, the risk management additions to the SCOR model are discussed and a practical application of SCRM using SCOR is presented.
Background
What is Supply Chain Risk Management (SCRM)? Risk is a concept that has applications in everything we do. It has several components, not the least of which is the lack of knowledge about the events that may impact us and our ability to manage them. In order to understand risk we first need to define and decompose it, specifically as it pertains to the supply chain. Under these statements, a common sense definition of risk acknowledged by the International Organization for Standardization (ISO, 2002) mainly deals with two of its essential components: losses (along with related amounts) and uncertainty of their occurrence. Another similar definition given by Culp (2001) states that risk can be defined as any source of randomness that may have an adverse impact on a person or a corporation. In the financial industry, operational risk is defined as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events (New Basel Capital Accord, 2006). Formally, risk in general can be defined as a collection of pairs of likelihood (L) and outcomes (or impact) (O): Risk = {(L1, O1), (L2, O2),, (Ln, On)} where Oi and Li denote outcome i and its related likelihood. The distribution pattern of the (likelihood; outcome) pairs is called a risk profile (Ayyub, 2003). Definitions of risk must also have a time dimension or a specific time horizon (day, month, year, etc.) and a specific perspective or view that defines the unit of analysis (boundaries, whats not included, etc.). How does this apply to the supply chain? Recently, several publications have advanced the conceptual clarity of the terms used in the domain of supply chain risk managementyet, there is still no commonly agreed nomenclature. According to Wagner and Bode (2006) it is possible to distinguish four interrelated terms: Supply chain risk: it is defined as the negative deviation from the expected value of a certain performance measure, resulting in negative consequences for the focal firm. Hence, risk is equated with the detriment of a supply chain disruption. The authors explicitly adopt the notion of risk as purely negative as the one that corresponds best to supply chain business reality. As a consequence, they do not consider either happy disasters nor the situation where managers intentionally gamble on risk. Supply chain disruption: a supply chain disruption is an unintended, untoward situation, which leads to supply chain risk. For the affected firms, it is an exceptional and anomalous situation in comparison to every-day business. Supply chain disruptions can materialize from various areas internal and external to a supply chain. Consequently, their nature can be highly divergent. Supply chain risk source: attempting to circumscribe supply chain disruptions (i.e. the demarcation of supply chain risks from other business risk), many scholars have proposed classifications in the form of typologies and/or taxonomies of risks. The derived classes of supply chain disruptions are often labeled supply chain risk sources. Supply chain vulnerability: while a supply chain disruption is the situation that leads to the occurrence of risk, it is not the sole determinant of the final result. It seems consequential that also the susceptibility of the supply chain to the harm of this situation is of significant 6
relevance. This leads to the concept of supply chain vulnerability. In other way, Christopher and Peck (2004) define supply chain vulnerability as an exposure to serious disturbance, while Barnes and Oloruntoba (2005) describe vulnerability as a susceptibility or predisposition to loss because of existing organizational or functional practices or conditions. In order to better understand and define risk in the supply chain the different perspectives need to be understood. Figure 2 shows the three perspectives in a supply chain and list some of the risk definitions related to them.
Global Environment
Companys Environment
Suppliers Environment
Customers Environment
Suppliers
(And outsource Manufacturing) Supplier Facing
Company
Customer Facing
Customers
Relationship Risk Supplier Performance Risk Human Resource Risk Supply chain disruption risk Supplier Environment Risk Market Dynamics Risk Disaster Risk Political / Country Risk Supplier Financial Risk Regulatory Risk
Internal Facing Operational Risk Technical Risk Financial Risk Legal / Regulatory Risk Environmental Risk HR / Health and Safety Risk Political/ Country Risk
Financial Risk Distribution Risk Relationship Risk Market Risk Brand / Reputation Risk Product Liability Risk Environmental Risk Political/ Country Risk
Figure 2. Supply Chain Risk Perspectives Supplier Facing looks at the network of suppliers, their markets and their relationship with the company. Customer Facing looks at the network of customers and intermediaries, their markets and their relationships with the company. Internal facing looks at the company, their network of assets, processes, products, systems and people as well as the companys markets. In all cases, a global perspective is essential. As a first attempt of definition, supply chain risk can be divided, according to its source, into demand-side (resulting from disruptions emerging from downstream supply chain operations (Jttner, 2005)), supply-side (residing in purchasing, supplier activities, and supplier relationships), and catastrophic risks (subsumes supply chain disruptions that, when they materialize, have a severe impact in terms of magnitude in the area of their occurrence)(Wagner and Bode, 2006). Treleven and Schweikhart (1988) have classified risks into five categories, connected with disruption, price, inventories and schedule, technology, and quality. Zsidisin (2003) focused on the definition of supply risk as the probability of an incident associated with inbound supply from individual supplier failures or the supply market occurring, in which its 7
outcomes result in the inability of the purchasing firm to meet customer demand or cause threats to customer life and safety, while Wu et al. (2006) states that inbound supply risk is defined as the potential occurrence of an incident associated with inbound supply from individual supplier failures or the supply market, resulting in the inability of the purchasing firm to meet customer demand and as involving the potential occurrence of events associated with inbound supply that can have significant detrimental effects on the purchasing firm. Finally, Nagurney et al. (2005) defines demand side risk as represented by the uncertainty surrounding the random demands at the retailers. In developing a definition, the team looked at general concepts being used in risk management. Business Continuity Management (BCM), defined by the Business Continuity Institute as an holistic management process that identifies potential impacts that threaten an organization and provides a framework for building resilience and the capability for an effective response that safeguards the interests of its key stakeholders, reputation, brand and value creating activities (BCI, 2005). Business Vulnerability, defined as an exposure to serious disturbances, arising from risks within the supply chain as well as risks external to the supply chain (Christopher, 2003). Vulnerability is a result of any weakness within a complex system that can seriously jeopardize its activities (Ayyub, 2003). Enterprise Risk Management (ERM) as a set of coordinated actions about protecting and enhancing share value to satisfy the primary business objective of shareholder wealth maximization (Chapman, 2006). Resilient enterprise meaning the ability of the company to recover quickly from a disruption (Sheffi, 2005). Several supply specific definitions were examined by the team. For example, Deloitte and Touche (2004) and Tang (2006) define supply chain risk (SCR) as the uncertainty of the occurrence of an event that could affect one (or more) partner or link within the supply chain and that could influence (generally in a negative sense) the achievement of companys business objectives. They define supply chain risk management (SCRM) as having the objective to control, monitor and evaluate supply chain risk, optimizing actions in order to prevent disruptions (that is, the occurrence of an event that causes a business interruption) or to quickly recover from them.
Project Results
With all of the background research in mind, the research team developed the following definition of SCRM: Supply chain risk management is the systematic identification, assessment, and quantification of potential supply chain disruptions with the objective to control exposure to risk or reduce its negative impact on supply chain performance. Potential disruptions can either occur within the supply chain (e.g. insufficient quality, unreliable suppliers, machine break-down, uncertain demand, etc.) or outside the supply chain (e.g. flooding, terrorism, labor strikes, natural disasters, large variability in demand, etc.). Management of risk includes the development of continuous strategies designed to control, mitigate, reduce, or eliminate risk. The next challenge for the team; where should supply risk management be within the SCOR model? In answering this question the team examined the three different approaches to risk management. Proactive: these approaches take place before the occurrence of an event, aiming at reducing (for negative outcomes) its likelihood. The emphasis here is on those methods related to failure prevention, near-misses detection and adoption of layered defense approaches. Proactive approaches are aimed at anticipating the causes of disruptions. Reactive: these approaches deal with the consequence of the occurrence of an event, aiming at reducing the resulting (negative) outcomes. In general, reactive, flexibility based and redundancy methods are known as disruption management in that they react after the disruptive event takes place, focusing on the resilience of the company or the ability to promptly recover from a disruption. Avoid, eliminate or transfer risk: avoid any action which has inherent risks or eliminate and mitigate the risk and its potential outcomes. In product design this could the design of a system that reduces or eliminates either the probability of occurrence of a particular risk event or its negative consequences if it occurs. In a supply chain, the risks can be mitigated by using more inventory or alternate suppliers. Risk can be transferred to an insurance company or another 3rd party that is more capable of handling it. In order to find the right approach for SCRM in the SCOR model the team looked at the different areas of the model, planning, execution and enablers. Figure 3 shows the definitions for Plan and the execution processes of Source, Make, Deliver, Return.
Figure 3. SCOR Process Definitions Drilling down further, the team ruled out execution as an area not directly involved in SCRM but can be influenced or directed by and SCRM process. This left the Enable area and Plan process as the two alternatives. As shown in Figure 4, the Plan process aligns expected resources to meet expected demand requirements. It balances aggregated demand and supply, considers consistent planning horizon, occurs at regular, periodic intervals and contributes to supply-chain response time. The Enable area contains processes that prepares, maintains, or manages information or relationships on which planning and execution processes rely. After several weeks of discussions on the pros and cons of each alternative, it was decided to incorporate SCRM in the Enable areas of the model. This was driven by the fact that the core activity of SCRM, the systematic identification, assessment, and quantification of potential supply chain disruptions, seemed to closely match the activities described as prepares, maintains, or manages information or relationships on which planning and execution processes rely.
10
Figure 4. SCOR Process Type How it would be incorporated was the next challenge of the team. Two alternatives were tested. 1. Centralized: A new enabler section was proposed that is the primary process for the process of developing and managing the Supply Chain Risk program and aligning it with the overall business risk management program. This proposal centralizes supply chain risk assessment and program management and guides risk mitigation enablers in each or the other (5) enabler groups (P,S,M,D,R). Benefits of this alternative are: a. better definition of the Plan process scope (i.e., differently form decentralized alternative that follows, the Plan enabler do not act as a coordinator or program manager for the other enablers; this is in charge of the new enabler section) b. possibility to consider an extended set of processes that not necessarily are included (or that could not be included) in the PSMDR enablers (i.e. the managing process of assets, considered in ERM5, can impact on more than one process, but at the same time is not a part of current PSMDR enablers) c. gives a better overview of the supply chain risk management process, considering the whole company (i.e. a set of PSMDR) from a higher level d. allows to better identify the role of coordination of the upper level of company (or supply chain) management e. centralizes supply chain risk assessment and program management and guides risk mitigation enablers in each or the other enabler groups (P,S,M,D,R) 2. Decentralized but Coordinated by Enable Plan: a new enabler is proposed to be added to each enabler group for the process of developing and managing the Supply Chain Risk program. The Plan enabler will act in a coordinating function by aligning the SCOR risk activities with the overall business risk management program. Each enabler group will have the responsibility for supply chain risk assessment and mitigation planning and actions for their process. The Plan risk enabler will act as program manager and guide risk mitigation strategies, plans and actions undertaken by each or the other (5) enabler groups (P,S,M,D,R). Benefits of this alternative: a. consistent with current SCOR architecture 11
b. more likely to be accepted by experienced SCOR users c. better definition of the enablers scope (since each enabler group will have the responsibility for supply chain risk assessment and mitigation planning and actions for their process) Alternative 2 (decentralized) was finally selected because it was more aligned to the current SCOR model philosophy and function of the Enablers section.
12
Detailed Recommendations
Enabler Process Model
The following section describes the detailed recommendation from the risk enabler team. Figure 5 shows the detailed Enabler Information Flow and Figure 6 shows the interactions and overall information flows for the risk enabler section. Risk is a combination of interactions with the external and internal environment. Therefore, the information flows are divided in two groups: External and Internal. The purpose of the risk enablers are to: 1. assess the external and internal environment, 2. understand the likelihood and impact of potential events, 3. understand the sensitivity of the supply chain to these events, 4. develop mitigation plans for the supply chain, 5. align these plans with the overall business risk management program, 6. communicate these plans and responsibilities and 7. monitor the internal and external environment in order to detect indicators of risk events. Figure 5 shows the details of the information types and flows of the typical risk enabler for a process area. The Plan risk enabler has an additional function of coordinating the other risk enablers as show in Figure 6. The Plan risk enabler takes in the overall business risk management program and translates this into the supply chain risk management program requirements. These requirements are then communicated to the other risk enablers. The Plan risk enabler also takes the program and plans for each process area, aggregates them into an overall supply chain risk management program and communicates this to the overall business risk management area.
13
External Information
External Monitoring
Overall SC Risk Management Program Rules, strategies, tools, etc. (EP9) Ex.9
External Communication
Filter results to suppliers, customers, agencies, etc. To suppliers, customers, publications, governmental agencies
Internal Information SC Risk Management Revised settings, business rules, Program for Process Area To ER1-8
Results, strategies, mitigation actions To Ex1-8 and EP.9
42
External Information
Internal Information
External Monitoring
Overall Business Risk Management Program Rules, strategies, tools, etc. (EP9)
Settings, business rules, event monitoring from Business Rules (EP1) Capabilities of the Processes (EP2) Data about Capabilities (EP3) Inventory Targets (EP4) Asset Capabilities and Capacities (EP5) Transportation Guidelines, Policies, and Agreements (EP6) Process Workflow Definition and Policies (EP7) Regulatory Requirements /Compliance (EP8) All Enabler Risk Reports and Plans (Ex.9)
EP.9
External Communication
Filter results to suppliers, customers, agencies, etc. To suppliers, customers, publications, governmental agencies on overall SC risk
Internal Information
43
14
Figure 6. Plan Risk Enabler Information Flow Figure 7 shows the overall information flows and interactions of the entire risk enabler sections.
EP
Internal Adjustments Rules Resources External Information External Monitoring External Adjustments ES.9 Manage Supply Chain Source Risk Plan / Results Internal Information Monitoring Internal Adjustments Risk Management Program for Process Area
ES
ES1- Manage Sourcing Business Rules ES.2- Assess Supplier Performance ES.3- Manage Source Data ES.4- Manage Product Inventory ES.5- Manage Source Capital Assets ES.6- Manage Incoming Product ES.7- Manage Supplier Network ES.8- Manage Import/Export Requirements ES.10- Manage Supplier Agreements
Figure 7. Overall Risk Enablers Information Flows and Interaction In this process, each risk enabler interacts (two way information flow) with the environment (internal and external), the Plan risk enabler and the other enablers within their specific process area. This continuous process is coordinated by EP, the Plan risk enabler.
15
Level 2
Supply Chain Value at Risk (VAR $) By PSMDR Supply Chain Event Risk (EVAR $) By PSMDR
Level 3
Value at Risk (VAR $) By PSMDR & individual performance metric Internal Enabler Process and Data Quality measures
Mitigated Risk by Category ($) By PSMDR & individual performance metric & event category
31
Figure 8. Risk Metric Hierarchy The hierarchy has three levels, as with all other metrics within the SCOR model. Level 2 and 3 are mostly internal to the risk enabler process and are used for analysis and diagnostics. Three specific metrics are rolled up to Level 2 and appear in the level 2 SCOR card. These are Value at Risk (VaR), Residual Risk and Mitigation costs. Mitigation costs are then rolled up and included in Total Supply Chain costs, which is a current level 1 metric within the SCOR model.
VAR Definition
Value-at-risk (VaR) is a category of risk metrics that describe probabilistically the market risk of a trading portfolio over a given period of time. Value-at-risk is widely used by banks, securities firms, commodity merchants, energy merchants, and other trading organizations. Such firms could track their portfolios' market risk by using historical volatility as a risk metric. Figure 9 highlights some key points about the VaR metric.
16
Value-At-Risk
1
Value-at-risk (VaR) is a category of risk metrics that describe probabilistically the market risk of a trading portfolio.
Value-at-risk is widely used by banks, securities firms, commodity merchants, energy merchants, and other trading organizations.
Such firms could track their portfolios' market risk by using historical volatility as a risk metric. They might do so by calculating the historical volatility of their portfolio's market value over a rolling 100 trading days.
The historical volatility would illustrate how risky the portfolio had been over the previous 100 days. Source: [Link]
22
Figure 9. Key Points on VaR VaR is about performance v. expectations (or target). With securities it measures the probability that the actual return will be below the desired (or expected) return. The VaR calculation uses historical data on the securities to calculate the number of times the securities performed below the target (probability) times the amount below the target. For example, if the target price was $100 and the security historical pricing was the following: 10% at $70 10% at $80 10% at $90 50% at $100 20% at $110
The VaR would be .10 (100-70)+.10(100-80)+.10(100-90) = $6 This is a very simple, non-statistical application of VaR. There are other, more sophisticated ways to apply this concept but this example is only meant to illustrate the concept. For a more detailed explanation, go to [Link] VAR can be also be used to evaluate and manage risk in the supply chain. The SCC defines Value at Risk as the sum of the probability of events times the monetary impact of the events for the specific process, supplier, product or customer. 17
VAR Example
The following example will explain how VaR can be applied to the supply chain using airlines and on time arrival metrics as an example of a supplier. Situation: You are flying to Detroit from Raleigh Durham. There are two airlines with direct flights and you want to know which one is more likely to arrive on time (on time delivery is a key metric). Figure 10 shows the average percent late for each airline.
Which supplier (AA or NW)) has the highest likelihood of being late?
Percent Late
6
Airline % Late Hawaiian Airlines Inc.: HA 6.95 Aloha Airlines Inc.: AQ 8.01 Southwest Airlines Co.: WN 18.26 Delta Air Lines Inc.: DL 19.66 AirTran Airways Corporation: FL 20.52 Frontier Airlines Inc.: F9 21.35 Pinnacle Airlines Inc.: 9E 22.45 Alaska Airlines Inc.: AS 25.53 Skywest Airlines Inc.: OO 25.85 All Rows (including those not displayed) 26.42 Continental Air Lines Inc.: CO 26.47 Expressjet Airlines Inc.: XE 27.84 United Air Lines Inc.: UA 28.15 by Airline Mesa Airlines Inc.: YV 28.20 Atlantic Southeast Airlines: EV 30.36 30.39 Std. Dev = 7.61 American Eagle Airlines Inc.: MQ Northwest Airlines Inc.: NW 30.87 Mean = 25.3 American Airlines Inc.: AA 31.00 JetBlue Airways: B6 33.35 N = 21.00 Comair Inc.: OH 33.45 37.5 US Airways Inc.: US 36.30
Count
1 0 7.5 10.0 12.5 15.0 17.5 20.0 22.5 25.0 27.5 30.0 32.5 35.0
NW AA
% LATE
Figure 10: Average Percent Late by Airline. From figure 10, it looks as if Northwest and American are about equal (31.00 v. 30.87 percent late). If you examine the distributions and the VaR for each airline, it tells a different story. Figure 11 and 12 shows the actual distributions of arrivals for each airline. The number above each bar represents the percent for the group of late events as a percent of the total events (by count only).
18
Distributions NW
0.15
13.7 13.2
11.0 10.7
0.10
8.0 7.5
6.0
4.8 4.0 3.4 2.8 1.9 0.8 0.0 0.1 0.3 2.1 1.7 1.4 1.1
0.05
0.8 0.7
0.6 0.5 0.4 0.3 0.3 0.2 0.2 0.2 0.2 0.2 0.1 0.1 0.1
-40
-30
-20
-10
10
20
30
40
50
60
70
80
90
100
110
120
Figure 11: Distribution of Northwest performance (minutes late by flight event) and VaR
Distributions AA
45.6
30.2
9.3 5.3 2.1 0.0 3.1 1.7 [Link] [Link].0 [Link].0 [Link].0 [Link].0 [Link].0 [Link].0 [Link].0 [Link].0 [Link].0 [Link].0 0.0
100
200
300
400
500
600
700
800
900
1000
1100
1200
Figure 12: Distribution of American performance (minutes late by flight event) and VaR As you can see, the average of percent late misleads. As shown in table 1, the VAR for Northwest is $14.24 (using each minute late as costing $1) and American is $25.93. The American distribution shows a high frequency of flights that are very late (over 100 minutes) while Northwest stays within 150 minutes and most late flights are under 100 minutes.
19
Probability
This example illustrates how VaR can be used in the supply chain to evaluate the different aspects of risk. Suppliers can be evaluated base upon the VaR of performance measures. Customers can also be measured based upon performance measures (profitability, volume growth, returns, and complaints) as well as products (warranty claims, etc.). VaR can also be applied to internal supply chain entities such as manufacturing, distribution or sales locations. Since VaR can be monitarized by accessing the cost of performance below target, VaR can be rolled up and examined by any demographic or data cut (by region, by customer, by supplier, etc.). Suppliers, Products, Customers, Locations, etc. can be evaluated based upon VaR and ranked according to the risk of poor performance. Caveats in using VaR : VaR calculates the probability of non-adherence to metrics value (expected value) based on historical data. Hence, it is a retrospective view of the event risk. The same may or may not be applicable in the future. VaR is a downside Risk Metrics. It calculates the loss for each level of confidence (probability). In a real life scenario, just like a sales forecast, predictive accuracy depends upon how well history predicts the future. Calculating VaR from historical data requires a potentially large database of events and metrics, and it could be computationally intensive.
20
Best Practices
Many companies have been starting to look at managing risk and several best practices have emerged. Practices in the financial services, project risk management, and insurance industries were studied. The details of these are described in the SCOR Best Practices section. Summaries are provided below. Ten practices have been identified under 4 categories shown in Figure 13. Each practices is described in more detail below.
RM Programs Coordination with Partners Supply Chain Risk Identification Supply chain Risk Monitoring Supply Chain Risk Assessment Sourcing Risk Mitigation Strategies Crisis Communication Planning Configure to Reduce Risk : Supply Chain Business Rules Supply Chain Information
Best Practices
Phase 3 Risk Mitigation: How can the risks be controlled and monitored? Mitigation measures (e.g. improved planning methods, alternative suppliers, response plans, redundant infrastructure, etc.) should be evaluated for the serious risks. After having checked the cost-efficiency of the alternative measures, the appropriate measures should be chosen and implemented. A risk can be mitigated by decreasing the likelihood that it will occur or by decreasing its impact if it does occur. Alternatives to mitigation include acceptance, transfer, and risk sharing.
property loss, ...); quality management; increases in production costs; link to source risks (interruptions and increases in costs); capacity (over and under); intellectual property; and personnel management. Deliver risk identification Visibility of customers improves the ability to identify Deliver risks. Return risk identification Data on returns needs to be tracked to identify risks. Excessive returns may reveal risks earlier in the process.
likelihood, or degree of belief, based on the opinions of experts. A time horizon is necessary to define the probability in a useful way (e.g., the likelihood that an event will occur in the next year or 50 years). Impact measures the consequences on the organization if the event occurs. It can be measured directly, for example in terms of dollars. It can also be measured on a scale, for example from zero to one with zero being very little negative consequence and one being a very bad consequence. Methods for measuring impact include what-if simulations, financial models, and opinions of teams of experts. Impact may also be measured in terms of other SCOR metrics besides financials. Summary risk score A summary risk score can be calculated for each risk by multiplying the Impact times the Probability to get an expected value of the risk. Then risks can be ranked by risk score. Also the risks can be shown on a map or graph. An example is shown below.
$120,000 $100,000
Impact
Likelihood
Figure 14. Risk Matrix Other methods for assessment include: Failure Mode Effects Analysis (FMEA) Fault Tree Analysis (FTA) Event Tree analysis (ETA) A risk assessment tool in the form of qualitative and quantitative spreadsheet or other software can be used by management teams to organize the assessment of risks to an organization. The tool can contain also contain information on relevant causes of those risks and their assessment, mitigation options and the impact of various mitigation plans. This helps establish standards for the measurement, reporting, and limiting of risk. Risk management is widely discussed, but practitioners have differing views of the categories, significance, and how to integrate mitigation plans into the overall project or operational plan. A frequent issue is that management focuses on the highest impact risks, overlooking more frequent occurrences. This practice should help standardize risk management vocabulary and practices within an organization. Some more sophisticated methods of risk assessment involve the use of simulations to derive approximations for the impact of risks. Varieties of different types of supply chain simulation software are available and may be used for this purpose. 24
25
26
This practice is useful in organizations where the cost of supply chain disruptions is high, either from a profit or brand image perspective. Using a risk mitigation configuration will reduce the potential for a disruption and reduce the recovery time after a disruption occurs.
27
Name
BUILD
Deliverable
Organizational Support Risk Management Program
Resolves
Who is the sponsor?
DISCOVER
II
ANALYZE
Scorecard Benchmark Competitive Requirements Customer service requirements Geo Map Thread Diagram Risk assessment Mitigation plans Level 3, Level 4 Processes Best Practices Analysis Opportunity Analysis Mitigation Definition Deployment Organization Monitoring and response programs
III
ASSESS
IV
MITIGATE
IMPLEMENT
Some of the challenges of implementing a supply chain risk management program are: Organizational Support: supply chain risk management needs cross-functional participation, agreement and cooperation in order to succeed. It cannot be done within a department without significantly limiting the impact on the business. This requires executive level commitment and active participation. Building this is a critical first step in the implementation process. Rules and strategies: Before risk management activities can start, a decision must be made as to the approach and the strategy. The main guidelines for managing risks and the rationale behind them must be developed, documented and communicated. Roles, Responsibility: Clear roles and responsibility are critical for any process or program. In the case of supply risk management, even more so. Cross-functional, company wide responsibility and authority are critical for success. In addition, supply risk management adds new responsibilities to existing jobs. These must be clearly communicated, current skill levels of incumbents assessed and corrections made (training or replacement) as required. Funding: Effective levels of funding are always a challenge in any company. The amount depends upon the scope of your program and how much detail is requirement. Top line annual risk assessment can be very inexpensive and might be a good place to start while the organization is training in new concepts of risk management. 28
Mitigation: The mitigation of risk considers options for treating risks that were not considered acceptable. This phase aims at identifying options to either reduce negative consequences, or to reduce the likelihood of adverse outcomes. In general terms, risk identification, analysis, assessment and mitigation means answering the following questions: (i) what can happen? (ii) how can it happen? (iii) why could it happen? (iv) what are the potential outcomes? (v) how we can overcome potential disruptions? Once these questions have been answered, this 3rd phase aims at identifying available actions in order to reduce risks negative outcomes. These actions will take place at the operational level. This phase clearly requires an intimate knowledge of the organization, the market in which it operates, the legal, social, political and cultural environment in which it exists, as well as the development of a sound understanding of its strategic and operational objectives. Coordinate and align the program: This phase places a strong emphasis on cooperation among departments within a single company and among different companies of a supply chain to effectively manage the full range of risks as a whole. A closer coordination of risk management activities performed throughout the supply chain is intended to conserve resources and increase effectiveness. The adoption of a common process framework within the supply chain can foster the share of information in order to improve existing initiatives and removal duplicated or ineffective activities. Moreover, sharing business continuity programs with supply-side and customer-side partners can help in identifying overlapping areas or uncovered issues. Risk Management coordination could be achieved by the establishment of a Risk Management Coordination Committee, whose purpose is to advise and coordinate the identification and inclusion of risk management treatments within the overall risk management process. Monitor and act: Finally, after all decisions have been made and roles and responsibility have been assigned, the results have to be continuously monitored in order to act (or react) when necessary. The monitoring process goes along the entire supply chain risk management process and interacts with each step bi-directionally, allowing for feedback and reconsideration of choices.
29
Conclusions
According to Hallikas et al. (2004), an effective collaborative process for risk management is possible only if there is a risk management mindset and culture. The SCOR model can play a substantial role in pursuing the overall objective of a real collaborative process within and between companies, aiming at maximizing the overall performances of the supply chain. Having a supply chain reference model that allows the definition of individual as well as collaborative risk management processes seems to be just a preliminary condition to pave the way for the design of a shared risk management process for the whole supply chain network. Obviously, this offers further theoretical and practical issues: how can a collaborative risk management process be implemented? Which companies are responsible for the definition, the implementation and the management of the process? Which are the partners? In our opinion, future studies have to provide some valuable answers to these issues, contributing in particular to the definition of a systematic model in order to understand the relationships between individual risk management processes and a collaborative risk management process, and the definition of a risk management reference model encompassing the entire supply chain network.
30
References
[1] [2] [3] [4] APICS, Protiviti Inc., 2004, Understanding supply chain risk areas, solutions, and plans. A five-parts series. ([Link] - September 2006) Attis D., Monahad S., and P. Laudicina, 2003, Supply Chains in a vulnerable, volatile world, A.T. Kearney Executive agenda Third Quarter 2003 Ayyub, B.M. , 2003, Risk Analysis in Engineering and Economics, Chapman & Hall/CRC, Florida ISBN 1-58488-395-2 Barton, T.H., Shekir, W.G. and P.L. Walker, 2002, Making enterprise Risk Management Pay Off, Fei Research Foundation. Financial Times Prentice Hall. Pearson Education Basel Committee on Banking Supervision, 2006, International Convergence of Capital and Capital Standards. ISBN print: 92-9131-720-9; ISBN web: 92-9197-720-9 ([Link] - September 2006) (The) Business Continuity Institute (BCI), 2005, Good Practice Guidelines 2005 A Framework for Business Continuity Management ([Link] - September 2006) Chapman, R.J., 2006, Simple Tools and Techniques for Enterprise Risk Management, John Wiley & Sons. England, ISBN 978-0-470-01466-0 Christopher, M., 2003, Creating Resilient Supply Chains: a Practical Guide, Cranfield University School of Management. ISBN 1-861941-02-1 ([Link] - September 2006) Clarke C.J. and S. Varma, 1999, Strategic Risk Management: the New Competitive Edge, Long Range Planning, Vol. 32, No. 4, 414-424 Cornalba, C. and P. Giudici, 2004, Statistical models for operational risk management, Physica A, N 388. 166-172 Culp, C.L., 2001, The risk management process. Business strategy and tactics, John Wiley & Sons, Inc. New York NY - ISBN 0-471-40554-X Deloitte and Touche, 2004, Supply Chain Risk Management, ([Link] agement_070704x(1).pdf) Daniell, M.H., 2000, World of risk, John Wiley&Sons (Asia) Pte Ltd - ISBN 0-47184085-8 Goodman, R.W., 2004, Is Your Supply Chain ready for Sarbanes-Oxley?, Global Logistics and Supply Chain Strategies, February 2004, 32-39 Hallikas, J., I. Karvonen, U. Pulkkinen, V.-M. Virolainen and M. Tuomine, 2004, Risk management processes in supplier networks, International Journal of Production Economics, 90, 47-58 Hendricks, [Link] V.R. Singhal, 2005, The Effect of Supply Chain Disruptions on Long-term Shareholder Value, Profitability, and Share Price Volatility ISO: International Organization for Standardization, 1999, ISO/IEC Guide 51 Safety aspects Guidelines for their inclusion in standards ISO: International Organization for Standardization, 2002, ISO/IEC Guide 73 Risk management Vocabulary Guidelines for use in standards Knight, R., & Pretty, D. (1996). The impact of catastrophes on shareholder value. In The Oxford Executive Research Briefings. Oxford, UK: Templeton College, University of Oxford. Kunamoto H. and E. J. Henley, 1996, Probabilistic risk assessment and management for engineers and scientists, IEEE Press, New York, NY. Latour, A. (2001). Trial by fire: A blaze in Albuquerque sets off major crisis for cellphone giants-Nokia handles supply shock with aplomb as Ericsson of Sweden gets burned-Was SISU the difference? Wall Street Journal, January 29, A1. 31
[5]
[6]
[7] [8]
[21]
[22] NSW Small Business, 2005, Risk management guide for small business, Department of State and Regional Development ([Link]) - ISBN 0-7313-32490 [23] Sheffi, Y., 2005, The Resilient Enterprise. Overcoming Vulnerability for Competitive Advantage, The MIT-Press, Boston - MA [24] Sitkin, S.B. and A.L. Pablo, 1992, Reconceptualizing the Determinants of Risk Behavior, The Academy of Management Review, 17, 9-38. [25] Tang, C., S., 2006, Perspective in supply chain risk management, International Journal of Production Economics, 103, 451-488 [26] Vose, D., 1996, Quantitative Risk Analysis A guide to Monte Carlo Simulation Modeling, John Wiley & Sons England - ISBN 0-471-95803-4, 96-99 [27] Woodman, P., 2006, Business Continuity Management (May 2006), ISBN: 0-85946445-8. ([Link] - September (2006)) [28] Zimmermann, H.-J., 2000, An application-oriented view of modelling uncertainty, European Journal of Operational Research, 122, 190-198 [29] Zsidisin, G.A. 2003, A grounded definition of supply risk, Journal of Purchasing & Supply Management 9, 217224 [30] M. Treleven, S.B. Schweikhart, 1988, A risk/benefit analysis of sourcing strategies: Single vs. multiple sourcing, Journal of Operations Management 7(4), 93-114. [31] Anna Nagurney, Jose Cruz, June Dong, Ding Zhang, 2005, Supply chain networks, electronic commerce, and supply side and demand side risk, European Journal of Operational Research 164, 120142 [32] Brindley, C. (ed.) (2004): Supply Chain Risk A Reader. Ashgate Publishing Limited. [33] Handfield, R., Blackhurst, J., Craighead, C.W. (2007): Supply Chain Risk Management: Minimizing Disruptions in Global Sourcing. CRC press. [34] Modarres, M. (2006): Risk Analysis in Engineering Techniques, Tools, and Trends. Taylor & Francis. [35] Ziegenbein, A. (2007): Supply Chain Risk Identification, Assessment and Mitigation. vdf Hochschulverlag Zrich (in German). [36] (2004) A Guide to Project Management Body of Knowledge. PMBOK guide Project Management Institute, Inc [37] (2002). Risk Management Guide for DoD Acquisition Defense Acquisition University US Department of Defense. [38] Hoeft, S., Davey M., Newsome, D., (May-June 2007) Proactively Managing Risk: The New Waste. Defense AT&L. [39] Best Practices in Risk Management: Private and Public Sectors Internationally Treasury Board of Canada Secretariat. Accessed on 10/25/2007 at [Link] [40] Comcovers Awards for Excellence in Risk Management 2004: National Capital Authority. Australian Government Comcover. Accessed on 10/25/2007 at: [Link]
32
Supply Chain Risk Management (SCRM) offers several key benefits, including cost avoidance by reducing the probability and impact of disruptions, leading to performance improvements. Implementing SCRM helps in managing risks within a complex, geographically dispersed supply chain composed of several legally independent entities . Additionally, SCRM enables a centralized risk assessment and program management, which guides risk mitigation across various enabler groups like Planning, Sourcing, Making, Delivering, and Returning (PSMDR).
Risk identification in supply chain management involves creating a comprehensive list of potential events that could negatively affect performance. This step is critical because it enables organizations to proactively manage risks by developing plans to address them before they manifest. Methods such as supply chain mapping, historical problem analysis, industry trend research, and expert brainstorming are essential in uncovering risks, thus making risk identification a cornerstone of effective supply chain risk management .
A collaborative risk management process in the SCOR model fosters greater effectiveness by promoting a unified approach to risk management across all supply chain partners. This process encourages information sharing and coordinated responses to risks, thus conserving resources and enhancing decision-making. However, challenges include establishing consensus among diverse companies on risk management practices and defining the roles and responsibilities within the collaborative framework. Future studies need to address these challenges by developing systematic models for effective implementation .
Supply Chain Value at Risk (VaR) measures the potential financial loss in the supply chain due to disruptive events. Mitigation costs refer to expenses incurred in implementing measures to reduce the likelihood or impact of these risks. Within the SCOR model, these metrics are essential for evaluating supply chain performance, as they help quantify the effects of risks and the benefits of mitigation efforts. A detailed understanding of VaR and mitigation costs can assist businesses in optimizing their risk management strategies and improving overall supply chain resilience .
Integrating assessments of both the internal and external environments allows for a comprehensive understanding of potential risks affecting the supply chain. It ensures that organizations consider external factors like supplier performance and market trends, along with internal capabilities and operational policies. Such dual assessments facilitate the development of risk mitigation plans that are well-aligned with the overall business risk management strategy, thereby enhancing the effectiveness of supply chain management .
The 'Plan risk enabler' in the SCOR model coordinates the other risk enablers by aligning the supply chain risk management activities with the overall business risk management program. It translates the overall business risk management requirements into specific needs for the supply chain and aggregates plans from each process area into an overarching supply chain risk management program .
A decentralized structure in supply chain risk management, consistent with the SCOR model philosophy, distributes responsibility for risk assessment, planning, and mitigation to individual enabler groups (PSMDR). This approach allows for a more precise definition of enabler roles and aligns with experienced SCOR users. Decentralization makes the model more likely to be widely accepted and implemented because it leverages existing structures and expertise within each enabler group .
A centralized approach to supply chain risk assessment streamlines program management by consolidating risk information and guiding mitigation strategies across multiple enabler groups. It enhances coordination, ensuring consistent risk assessment methodologies and facilitating more efficient allocation of resources for risk mitigation. By centralizing, companies can achieve a clearer overview of risks and implement comprehensive, organization-wide strategies that align with the overall business risk management program .
The three phases in supply chain risk management are: 1) Risk Identification, which involves listing potential disrupting events and analyzing existing countermeasures; 2) Risk Assessment, which evaluates the likelihood and impact of potential incidents; and 3) Risk Mitigation, which involves implementing measures to reduce risks through decreased likelihood or impact of negative events. These phases ensure a comprehensive approach to managing risks effectively, allowing organizations to preemptively address potential disruptions .
Risk mitigation involves actively implementing measures to decrease the likelihood or impact of risks in the supply chain. In contrast, risk acceptance means acknowledging the risk without taking further steps to address it, assuming potential losses. Risk transfer involves shifting the risk to another entity, such as through insurance or outsourcing, while risk sharing distributes the risk among multiple parties, such as through partnerships or joint ventures. Each approach offers different levels of control and responsibility concerning the potential risks .









