RSC Topic: Supply Chain Risk & Resilience

SPoF exposure, volatility response, and continuity modeling.

  • Supply Chain Risk Management (SCRM)

    Supply Chain Risk Management (SCRM) is a structured set of processes and controls used to identify, assess, monitor, and mitigate risks across the end-to-end supply chain. In industrial and regulated manufacturing, it focuses on any disruption, constraint, or nonconformance that could affect material availability, quality, cost, delivery performance, compliance, or data security.

    Key elements of SCRM

    Although implementations vary, SCRM in manufacturing environments commonly includes:

    • Risk identification: Mapping suppliers, logistics routes, critical parts, and digital dependencies (such as ERP, MES, PLM integrations) to surface where failures or constraints might occur.
    • Risk assessment: Evaluating likelihood and impact of risks such as single-source suppliers, long lead times, export-controlled components, cyber incidents affecting OT/IT, or quality escape risks.
    • Risk mitigation and controls: Defining actions like dual sourcing, safety stocks, alternate routings, tighter incoming inspection, supplier development, or hardened data-sharing workflows.
    • Monitoring and detection: Using metrics (on-time delivery, defect rates, shortages), supplier scorecards, and multi-tier visibility tools to detect early signs of disruption.
    • Response and continuity planning: Documented playbooks for expediting, re-planning, rerouting work orders, or temporarily modifying specifications under controlled deviation processes.

    Typical risk categories in regulated manufacturing

    For manufacturers operating under aerospace, defense, or other regulated frameworks, SCRM commonly covers:

    • Supply and capacity risks: Shortages, capacity limits at key suppliers, long lead times for critical parts, and bottlenecks in outsourced processing.
    • Quality and compliance risks: Supplier nonconformances, missing certifications, traceability gaps, and risks to meeting requirements like AS9100, AS9102, or customer-specific quality clauses.
    • Logistics and geopolitical risks: Transportation delays, customs issues, tariffs, export controls, and country-of-origin constraints.
    • Cybersecurity and data-handling risks: Compromise of shared technical data, vendor access to OT/IT systems, and alignment with controls such as NIST 800-171, CMMC, DFARS, or ITAR-related workflows.
    • Operational integration risks: Failures in data exchange between ERP, MES, PLM, and supplier portals that affect purchase orders, work orders, and as-built records.

    How SCRM shows up operationally

    Operationally, Supply Chain Risk Management often appears as:

    • Supplier qualification and onboarding processes that evaluate risk factors.
    • Use of supplier scorecards, critical part tracking, and shortage dashboards in ERP or planning tools.
    • Cross-functional reviews that connect purchasing, planning/MRP, quality, engineering, and production.
    • Documented risk registers, exception workflows, and escalation paths tied to work orders and materials.
    • Controls on how drawings, models, and specifications are shared with external partners.

    Common confusion

    • SCRM vs general supply chain management (SCM): SCM covers planning and execution of material and information flows. SCRM focuses specifically on identifying and controlling risks within those flows.
    • SCRM vs business continuity planning: Business continuity is organization-wide and looks at sustaining critical operations. SCRM is supply-chain-focused and often feeds into wider continuity and resilience planning.
    • SCRM vs cybersecurity risk management: Cybersecurity programs address digital and network risks broadly. SCRM includes cyber and data-handling risks where they affect suppliers, logistics, and shared technical data, but is not limited to cybersecurity topics.
  • counterfeit parts

    Counterfeit parts are components, materials, or products that are unauthorized imitations and are intentionally misrepresented as genuine, conforming, or coming from an approved source. In industrial and manufacturing environments, this typically refers to mechanical parts, electronic components, raw materials, or assemblies that falsely claim a particular origin, specification, or certification.

    Counterfeit parts may involve:

    • Use of false or altered manufacturer names, logos, or part numbers
    • Falsified certificates of conformity, test reports, or material certificates
    • Reuse or re-marking of scrap, rejected, or previously used parts as new
    • Substitution of lower grade or different materials than those specified

    They are distinct from nonconforming parts that fail a requirement due to error or variation but are not intentionally misrepresented. Intentional deception and misrepresentation are central to the definition of counterfeit parts.

    Operational meaning in regulated manufacturing

    In regulated industries such as aerospace, defense, medical devices, and pharmaceuticals, counterfeit parts are treated as a significant product integrity and safety risk. Requirements commonly apply to:

    • Supplier selection and oversight: qualifying and monitoring suppliers, distributors, and brokers to reduce the risk of counterfeit material entering the supply chain.
    • Traceability: maintaining records that link received parts to approved sources, lots, and certificates.
    • Receiving and inspection processes: visual inspection, documentation checks, and, when appropriate, testing to detect suspicious or non-genuine items.
    • Segregation and control: isolating suspected or confirmed counterfeit parts, preventing use, and documenting their disposition.
    • Event reporting and investigation: documenting suspected counterfeit incidents, conducting root cause analysis, and taking corrective and preventive actions.

    Quality management systems, including those aligned with standards used in aerospace and other highly regulated sectors, often call for documented processes to prevent the use of counterfeit parts and to manage them if detected.

    Common confusion

    • Counterfeit parts vs. nonconforming parts: Nonconforming parts fail to meet requirements but are not necessarily deceptive or misrepresented. Counterfeit parts involve intentional misrepresentation of origin, status, or characteristics.
    • Counterfeit parts vs. obsolete or alternate parts: Obsolete or alternate parts may be legitimate and approved if properly evaluated and documented. They become counterfeit only when they are intentionally misrepresented as something they are not.

    Context in aerospace and other regulated sectors

    In aerospace and other highly regulated supply chains, controls on counterfeit parts are often integrated with configuration management, traceability, supplier management, and product safety processes. This can include specific requirements for procurement from authorized sources, enhanced verification for high-risk items, and documented escalation or reporting when counterfeit parts are suspected.

  • What is the SR control family in NIST 800-53?

    In NIST Special Publication 800-53 (Revision 5), the SR control family is the set of controls titled Supply Chain Risk Management.

    The SR family focuses on managing cybersecurity and integrity risks that arise from external providers of systems, components, software, services, and data. This includes hardware and software suppliers, systems integrators, cloud and managed service providers, and maintenance vendors.

    What the SR family covers

    At a high level, the SR controls require organizations to:

    • Establish a supply chain risk management strategy and governance.
    • Define supply chain risk requirements and flow them into contracts and purchasing specifications.
    • Assess suppliers and integrators for security and integrity risks over the asset lifecycle.
    • Control provenance, tampering risk, and counterfeit or untrusted components.
    • Monitor and respond to emerging vulnerabilities and compromises in the supply chain.
    • Integrate supply chain risk considerations into system acquisition, development, deployment, and maintenance.

    Relevance in industrial and regulated environments

    In manufacturing and other regulated operations, SR controls interact directly with:

    • Engineering and OT procurement: How you specify, source, and qualify equipment, firmware, and software, typically through formal specifications, FAT/SAT, and validation protocols.
    • Quality and supplier management: How supplier risk assessments, audits, and nonconformance handling are performed and documented, often within QMS and ERP.
    • Change control and validation: How updates from vendors (patches, component substitutions, firmware changes) are evaluated, tested, and released into production with proper traceability.
    • System coexistence: How new suppliers or cloud/remote services are integrated into existing MES, SCADA, and ERP environments without breaking validated interfaces or disrupting production.

    Implementing SR controls effectively in brownfield plants usually means augmenting existing procurement, supplier quality, and engineering change processes, not replacing them wholesale. Full replacement of established systems or suppliers is often impractical due to downtime constraints, requalification and validation burden, and the cost and risk of reworking integrations and documentation.

    Practical constraints and tradeoffs

    The impact and feasibility of SR controls depend on:

    • Current supplier agreements: Many older contracts do not contain detailed cybersecurity or software bill of materials clauses, and renegotiation may be slow or contested.
    • Data and tooling maturity: Without a clear asset inventory and supplier map, applying SR controls consistently across all OT and IT assets is difficult.
    • Regulatory and qualification requirements: In aerospace, pharma, and similar sectors, changing a supplier or component can trigger costly requalification and documentation updates, which limits how aggressively SR controls can be enforced in the short term.
    • Integration complexity: Many legacy OT systems cannot be easily instrumented or monitored at the level implied by some SR enhancement practices, so compensating controls may be required.

    Because of these constraints, organizations typically prioritize SR control implementation on higher-risk systems, critical suppliers, and new procurements, while gradually backfilling legacy environments as contracts and change windows allow.

  • Can AOG risk mapping be applied to both OEM and MRO operations?

    Short answer

    Yes, AOG risk mapping can be applied to both OEM and MRO operations, but it does not look the same in each environment and it does not eliminate AOG events. In OEM contexts it is mainly a design, initial provisioning, and global supply-chain tool, while in MRO it is more tightly coupled to shop scheduling, parts availability, and turnaround-time commitments. The underlying concepts transfer, but the data structures, time horizons, and decision points differ enough that a single, generic template usually fails in practice. Both uses also depend heavily on data quality, integration with existing systems, and disciplined change control. In regulated environments, AOG risk mapping is decision support, not a guarantee of service levels, compliance, or audit outcomes.

    How AOG risk mapping fits OEM operations

    For OEMs, AOG risk mapping is typically anchored in design, reliability, and spares provisioning rather than day‑to‑day maintenance events. The focus is on which part families and configurations are most likely to create AOG exposure once the fleet is in service, based on criticality, lead times, repair capacity, and obsolescence risk. This usually requires integrating engineering data, reliability predictions, approved supplier lists, and global stocking strategies across multiple ERPs and PLM systems. The useful output is not just a “high‑risk part list,” but design and provisioning decisions: alternate part options, dual‑sourcing, recommended initial provisioning, and repair network strategy. Because OEM product lifecycles are long, the mapping must be maintained under change control; new revisions, service bulletins, and supplier changes all alter the AOG risk profile and must be traceable.

    How AOG risk mapping fits MRO operations

    In MRO environments, AOG risk mapping is operationally closer to the point of impact: which components and workscopes most often lead to AOG situations or extended ground times. The emphasis is on turnaround time, shop capacity, parts availability, and the variability of findings during disassembly and inspection. MROs typically combine historical work package data, unplanned findings, vendor repair lead times, and local inventory performance to identify steps where AOG exposure spikes. This mapping often needs to reflect customer‑specific contracts, different aircraft configurations, and regulatory approvals for repair alternatives or DER solutions. The actionable outcome is usually targeted: pre‑positioning specific parts, adding alternate repair vendors, adjusting work instructions, or re‑sequencing work to protect AOG‑sensitive path steps. As with OEMs, the mapping is only as credible as the underlying data and the rigor of how new findings and changes are incorporated.

    Key differences between OEM and MRO AOG risk mapping

    While the method can be shared, the risk drivers and time horizons differ enough that one model rarely serves both OEM and MRO without tailoring. OEMs typically work with longer lead times, global demand uncertainty, and configuration diversity, so models are more strategic and aggregated. MROs work on much shorter horizons, constrained by shop schedules, specific tail numbers, and committed delivery dates, so they need more granular, real‑time‑capable views. OEMs usually have better control over design and approved suppliers, while MROs have to work within customer‑specified configurations and certificates, limiting some mitigation options. These differences mean that data sources, integration points, and governance structures are not interchangeable, even if both parties call it “AOG risk mapping.” Trying to force a single, shared template or tool across OEM and MRO operations often leads to oversimplification that nobody trusts.

    Data, integration, and brownfield constraints

    In both OEM and MRO settings, AOG risk mapping depends heavily on pulling consistent data out of legacy systems that were not designed for this purpose. Typical sources include ERP, MRP, MES, maintenance records, reliability databases, and supplier performance logs, many of which exist in separate instances or on-premise systems with limited APIs. In aerospace‑grade environments, replacing these systems just to improve AOG analytics is rarely realistic due to validation burden, downtime risk, and integration complexity with certified equipment and processes. Instead, most organizations layer AOG risk analytics on top, using data warehouses, reporting layers, or point‑to‑point integrations, accepting that some data will remain incomplete or delayed. These integration compromises must be made explicit in the risk maps themselves (e.g., flags for low‑confidence data) so that operators and planners understand the limits of what they are seeing. Without this transparency, decision‑makers will either overtrust the maps or ignore them entirely.

    Tradeoffs, limitations, and validation needs

    AOG risk mapping improves visibility and prioritization; it does not prevent all AOG events or guarantee on‑time performance. Models can be biased by historical data that reflect past contracts, fleets, or suppliers, and may not adapt quickly when the business mix or supply base changes. Any algorithmic or scoring logic used for AOG risk must go through appropriate validation, configuration control, and documentation, especially if it influences planning, stocking, or work sequencing in regulated environments. Over‑focusing on high‑scored AOG risks can pull attention and inventory away from lower‑scored areas that still have significant operational or safety impact, so mitigation strategies need periodic review. OEM and MRO organizations should treat AOG risk mapping as a living, documented tool within the broader quality and operations management system, with clear ownership, review cycles, and traceable change history.

    Connecting OEM and MRO views without forcing a single model

    In many programs, OEMs and MROs both attempt AOG risk mapping but from different angles and with different data, leading to conflicting conclusions. A more realistic approach is to keep separate OEM and MRO models, then define a limited set of shared indicators or part families where alignment really matters. For example, both parties can agree on a critical component list, shared lead time assumptions, and a standard way of flagging AOG‑relevant events, even if their internal models differ. This respects brownfield realities—different systems, contracts, and regulatory approvals—while still allowing meaningful dialogue about AOG risk across the value chain. Attempting to impose a unified, end‑to‑end system across both OEM and MRO environments often stalls on integration and validation costs; a federated but aligned approach tends to be more achievable. Over time, this coordination can be expanded, but only as systems, data pipelines, and governance mature enough to support it reliably.

  • Which components should be prioritized when mapping AOG risk?

    Start from aircraft-level criticality, not part price

    When mapping AOG risk, the primary filter should be aircraft-level impact: does the absence of this component prevent dispatch or safe operation under applicable regulations and operator MELs? Price and annual spend are secondary; a low-cost sensor or minor actuator can be far more AOG-critical than an expensive cabin furnishing if the former has no approved deferral or workaround. A structured link from the maintenance program and MEL to the parts list will usually surface a much smaller subset of truly grounding components. This requires disciplined configuration control to know which parts are actually installed by tail and which configurations drive dispatch limitations. Without accurate configuration and MEL mapping, AOG risk maps quickly become misleading and overbroad.

    Prioritize long-lead and qualification-heavy hardware

    Components with long manufacturing or repair lead times deserve early focus because they drive extended ground time when things go wrong. In aerospace-grade environments, structural parts, unique machined details, and heavily certified hardware often sit at the top of this list. Items that require significant qualification, revalidation, or first-article work with each supplier change are especially risky, since you cannot easily pivot to alternates when supply breaks. Lead times are also affected by special processes, capacity bottlenecks, and export or regulatory constraints, which may not be visible in standard ERP data. Mapping AOG risk should therefore incorporate realistic lead time and requalification windows, not only nominal vendor lead times.

    Highlight safety-critical and no-workaround LRUs

    Line-replaceable units that are safety-critical or tightly tied to flight-critical functions should be prioritized because they often lack permissible deferrals. Examples include flight controls, avionics, braking components, and other systems where MEL relief is limited or non-existent. Even when spares exist, low on-hand quantities combined with long repair cycle times can make these LRUs de facto AOG drivers in certain fleets or stations. The risk map should capture both the severity (does it ground the aircraft?) and the time-to-recover (how quickly can a serviceable unit be positioned?). Fleet maturity and reliability data will influence how aggressively you prioritize specific LRUs, but assumptions must be explicit and periodically reviewed.

    Focus on single-source and fragile-supply parts

    Single-source components and parts from suppliers with fragile quality or capacity performance should move up the AOG priority list, regardless of historical usage. In regulated environments, shifting to a new source may trigger substantial qualification, documentation, and PPAP or equivalent activities, meaning that theoretical multi-sourcing is not an immediate mitigation. Parts relying on obsolete materials, legacy processes, or special licenses also contribute to fragile supply chains and elevate AOG exposure. When mapping risk, you should combine supplier dependency, qualification burden, and geographic or geopolitical risks into a simple but explicit supply fragility score. This helps separate genuine AOG risk from normal commercial risk.

    Include unique-repair and limited-serial-number items

    Components with unique repairs, mod states, or limited serial-number interchangeability create hidden AOG risk because not every spare can support every tail. Over years of operation, incremental design changes, bulletins, and repairs can fragment interchangeability in ways that standard part-number-based planning does not capture. When a tail-specific or configuration-specific part fails, even a seemingly healthy network spare inventory may not help, leading to avoidable ground time. Mapping AOG risk effectively means linking parts to configuration and mod status, not just to a generic fleet. Where that traceability is weak, the risk map should explicitly call out this data gap rather than implying a level of control that does not exist.

    Do not ignore consumables and expendables that can still ground you

    Certain consumables, sealants, fasteners, and other ostensibly low-value items can be AOG-critical if they are required to close maintenance tasks that affect airworthiness. In many plants and MRO operations, these items fall outside tight planning and can be managed casually through local stores, which works until a specific spec or batch becomes unavailable. Items with narrow specification windows, limited shelf life, or mandatory batch traceability can be particularly problematic. AOG risk mapping should therefore include a minimal set of consumables and expendables whose absence has previously driven delays or that maintenance engineering labels as “task-stoppers.” Over-prioritizing everything in this category, however, dilutes focus and should be avoided.

    Use fleet reliability data and actual AOG history to refine priorities

    After the initial prioritization by criticality and supply constraints, you should refine the list using fleet reliability and AOG event history. Some theoretically high-risk components rarely fail in service, while other mid-criticality parts drive frequent line disruptions due to reliability issues, nuisance faults, or diagnostic ambiguity. Combining MTBUR/MTBF data, delay codes, and AOG logs helps identify where the real ground-time risk is emerging in your specific operation. This requires data quality and consistent failure coding, which are often weak points in brownfield environments, and those weaknesses should be acknowledged when presenting the risk map. The result is a prioritized set of components that reflects both design intent and operational reality.

    Recognize brownfield and system-integration constraints

    In most organizations, the data needed to perform this prioritization lives across legacy MRO, ERP, engineering, reliability, and document management systems that do not integrate cleanly. Full replacement of these systems just to improve AOG risk mapping is rarely viable due to validation cost, operational downtime risk, and the long lifecycle of existing assets and certifications. Instead, most teams succeed with incremental approaches: targeted data extracts, reconciled part and configuration lists, and manual review by engineering and maintenance experts. Any AOG risk map built in such an environment should explicitly document its data sources, known gaps, and manual assumptions so leaders do not mistake it for a fully authoritative view. Over time, those same mappings can inform where to invest in better integration or master data cleanup.

    Connecting this to practical AOG mitigation

    The components you prioritize in the AOG risk map should directly inform stocking policies, repair loop management, and contingency plans, but none of these interventions are automatic. Regulatory constraints, capital limits, and warehouse capacity mean you cannot simply buy your way out of AOG risk for every high-priority item. For some components, the best mitigation may be alternative repair schemes, pooled inventory with partners, or pre-negotiated access to third-party stock, all of which introduce their own governance and traceability burdens. For others, design or reliability improvements may be more cost-effective than deeper stocking, but carry certification and validation overhead that must be weighed realistically. Treat the AOG risk map as a decision-support tool that highlights tradeoffs, not as a guarantee that specific actions will prevent future groundings.

  • AOG Risk

    Core meaning

    AOG risk commonly refers to the likelihood and potential impact of an **aircraft-on-ground (AOG)** event, where an aircraft is unable to depart as scheduled due to a technical issue, missing parts, documentation problems, or other operational constraints.

    In aviation-intensive manufacturing and maintenance environments, AOG risk is used to describe how vulnerabilities in production, repair, logistics, or information systems can cause or prolong an AOG situation.

    What AOG risk includes

    AOG risk typically covers:

    – **Technical failures**:
    – Unplanned equipment or component failures discovered before departure
    – Quality defects that prevent release to service
    – **Supply chain and logistics issues**:
    – Non-availability of certified spare parts
    – Delayed material deliveries or customs clearance
    – Incorrect or incomplete part configurations
    – **Process and information problems**:
    – Missing or incorrect maintenance records or quality documentation
    – IT/OT system outages affecting release, traceability, or configuration control
    – Inefficient escalation or approval workflows that delay return-to-service
    – **Resource constraints**:
    – Lack of qualified maintenance personnel when and where needed
    – Limited access to required tools, test equipment, or facilities

    AOG risk is usually assessed in terms of:

    – **Probability**: how often AOG events are expected to arise from a given cause
    – **Impact**: cost of delay, disruption to schedules, contractual penalties, and reputational consequences

    Use in operational and manufacturing workflows

    In industrial and regulated environments (for example, aerospace manufacturing, MRO, and component suppliers), AOG risk is used to:

    – **Prioritize production and maintenance tasks**: critical parts or work orders with direct AOG exposure receive higher priority in planning and scheduling.
    – **Design processes and controls**: workflows, checks, and approvals are structured to reduce the chance that a defect, missing data, or configuration error will ground an aircraft.
    – **Configure systems**: MES, ERP, quality, and maintenance systems may flag items or orders as AOG-related or AOG-critical, influencing routing, lead time assumptions, and escalation.
    – **Support decision-making**: operations and supply chain teams may evaluate trade-offs (e.g., expediting, reallocating inventory, or creating dedicated buffers) by referencing AOG risk.

    Boundaries and exclusions

    – **Includes**:
    – Risks directly connected to the creation, extension, or recurrence of aircraft-on-ground events.
    – Upstream risks (in manufacturing, logistics, or information management) that can manifest as downstream AOG events.
    – **Excludes**:
    – General operational risk unrelated to aircraft groundings (e.g., generic plant safety risk, financial market risk).
    – Non-aviation production downtime risks, unless they can be clearly traced to potential AOG outcomes.

    Common confusion and misuse

    – **Not the same as general downtime risk**: many industries speak of “downtime risk” for production lines; AOG risk is specific to aircraft being unable to operate.
    – **Not just a maintenance term**: while AOG events are often managed by maintenance organizations, the underlying AOG risk is also shaped by manufacturing quality, supply chain reliability, configuration management, and IT/OT availability.
    – **Distinct from safety risk**: AOG risk focuses on operational continuity and availability, not directly on flight safety assessments, even though both may use similar risk-analysis techniques.

    Site context: relevance to industrial and regulated systems

    In regulated industrial operations that support aviation, AOG risk is closely linked to:

    – **Quality systems**: Nonconformances, rework, and missing traceability can prevent release to service, triggering or prolonging AOG.
    – **MES/ERP integration**: Misalignment of part data, routings, or certifications across systems can delay availability of airworthy components.
    – **OT and IT reliability**: System outages or data integrity problems in maintenance, logistics, and documentation systems can stop aircraft from being cleared for flight.

    Organizations often model AOG risk in their broader risk and safety management frameworks to ensure that critical paths related to aircraft availability are identified, monitored, and controlled.