Advertisement /206696744/dsx/crmroute_top_over_banner · 970×90
CRM Route
Advertisement /206696744/dsx/crmroute_top_below_banner · 728×90

Building a Single-Source Risk Register

Most organisations can't name their sole-source dependencies until one of them fails. The register takes a week to build and it is the cheapest resilience you will buy.

Building a Single-Source Risk Register

Ask a procurement team which of their inputs come from exactly one source and the answer is usually a confident partial list. The full list is longer, and the gap between the two is where the next disruption will come from — not because the risk was accepted, but because it was never visible.

What to record per dependency

The register only earns its keep if each row supports a decision. 'Single source: yes' does not. These fields do:

• The item and the revenue or production it enables — the consequence, in numbers.

• Why it is single-sourced: tooling, qualification, IP, regulation, or nobody got round to it.

• Time and cost to qualify an alternative, honestly estimated.

• Current inventory cover in weeks, and the lead time to replenish.

• The known second tier — where your supplier gets it from.

• A named owner and a review date.

Distinguish the four reasons

The reason determines the remedy, and only one of the four is cheap to fix.

• Nobody got round to it — dual-source it. This is the easy win and it is more common than people expect.

Advertisement /206696744/dsx/crmroute_scroll_in_articles · 300×250

• Tooling or capital investment — quantify the cost of a second set and decide deliberately.

• Qualification or regulatory approval — start the second qualification now, because the lead time is the risk.

• Genuine sole source, IP-protected — you cannot dual-source, so the answer is inventory, contractual protection, or redesign.

Two approved suppliers who both depend on one upstream plant is a single source wearing a disguise.

Push one tier further than feels necessary

Tier-one diversity is often an illusion. Ask each critical supplier where their critical inputs come from, and for the top handful ask again. Suppliers are more willing to answer this than people assume, particularly if you frame it as joint continuity planning rather than an audit.

Rank by consequence, not by spend

Sort the register by the revenue or output at risk, not by purchase value. The rows at the top are frequently low-spend items — a connector, a certification, a specialist calibration — and they are the ones that justify carrying strategic inventory or funding a qualification programme.

Review it on a calendar, and after every near miss

A register written once during a crisis and never revisited is an artefact of that crisis. Quarterly review, plus an immediate update whenever a supply scare occurs, keeps it current. The near misses are the most valuable input you will get — they identify real dependencies at no cost, which is the only free information in risk management.

Discussion (2)

You
AJ
Astrid J. Aug 9, 2026

The hidden second tier is the real finding. We had two approved suppliers for a component and felt fine, until we learned both bought the same sub-assembly from one plant in one region.

HV
Hector V. Aug 13, 2026

Recording the requalification time rather than just 'single source: yes' changed how we prioritised. A part with a nine-month requalification is a completely different risk from one we can re-source in a fortnight.

Ready for more?

Subscribe