RSC Topic: Supply Chain Risk & Resilience

SPoF exposure, volatility response, and continuity modeling.

  • Third-Party Risk Management (TPRM)

    Third-Party Risk Management (TPRM) is a structured approach for identifying, assessing, controlling, and monitoring risks that arise from an organization’s relationships with external entities such as suppliers, contract manufacturers, logistics providers, IT service vendors, and other partners.

    In industrial and regulated manufacturing environments, TPRM commonly covers risks related to:

    • Supply continuity and performance, including capacity, delivery reliability, and quality of supplied materials or services
    • Quality and compliance, including adherence to customer, regulatory, and standard-specific requirements (for example aerospace, defense, or medical regulations)
    • Information security and cybersecurity, especially where third parties access production networks, MES/ERP systems, or handle controlled technical data
    • Data privacy and confidentiality, including handling of proprietary designs, process data, and as-built records
    • Financial and operational stability, such as risk of insolvency, sudden capacity loss, or major process changes at the supplier
    • Ethical and environmental considerations, such as labor practices or sustainability requirements when they affect contracts or certifications

    Operational meaning in manufacturing

    Operationally, Third-Party Risk Management translates into defined processes and controls across the lifecycle of a supplier or service provider, typically including:

    • Onboarding and qualification with due diligence checks, technical capability assessments, security questionnaires, and trial orders or audits
    • Contracting and requirements flow-down, where quality, cybersecurity, export control, and traceability clauses are defined and documented
    • Ongoing monitoring using metrics such as on-time delivery, defect and NCR rates, CAPA closure, security incident reporting, and audit findings
    • Risk assessment and tiering to classify suppliers based on criticality, regulatory exposure, access to controlled data, and single-source status
    • Corrective action and escalation when performance, compliance, or security issues are identified
    • Offboarding and transition management to handle data return/destruction, access revocation, and continuity planning if a relationship ends

    TPRM activities often interact with MES, ERP, QMS, and supplier portals to capture evidence such as certificates, audit reports, CAPA records, and security attestations, and to align with internal risk registers or enterprise risk management (ERM) frameworks.

    Scope and boundaries

    Third-Party Risk Management typically includes:

    • Direct material suppliers and contract manufacturers
    • Special process providers and outsourced operations (for example heat treat, coating, testing, calibration)
    • IT and OT service providers, including cloud or hosting partners, managed service providers, and MES/ERP vendors
    • Logistics partners and distributors where they impact product integrity or regulated handoffs

    It generally does not include internal departments, wholly internal plants, or risks that are entirely under an organization’s direct operational control, which are handled through internal risk and quality management processes.

    Relationship to cybersecurity and regulatory frameworks

    In regulated sectors such as aerospace and defense, TPRM is closely linked to cybersecurity and export control requirements. Organizations may use TPRM processes to evaluate how third parties align with frameworks and requirements such as NIST 800-171, CMMC, DFARS clauses, export control rules, or customer-specific data handling standards. This often includes security questionnaires, technical data access controls, and contract language defining responsibilities for incident reporting and remediation.

    Common confusion

    • TPRM vs. supplier quality management (SQM): SQM focuses mainly on product and process quality, whereas TPRM covers a broader risk set including cybersecurity, continuity, financial, and compliance risks. In manufacturing, SQM is often a component of a wider TPRM program.
    • TPRM vs. vendor management: Vendor management typically focuses on commercial relationships, pricing, and service levels. TPRM focuses specifically on risk identification, assessment, and control across those relationships.

    Manufacturing-relevant examples

    • Requiring a special process supplier to complete a cybersecurity questionnaire and sign data handling terms before they receive controlled CAD files or work instructions.
    • Classifying a single-source aerospace fastener supplier as high risk and scheduling more frequent performance reviews, quality audits, and business continuity checks.
    • Tracking third-party access to an on-premises MES system and periodically reassessing those vendors for compliance with current security and regulatory expectations.
  • Critical Supplier

    A critical supplier is a third-party provider whose products or services are considered essential to product quality, safety, regulatory compliance, or business continuity. In industrial and regulated manufacturing environments, these suppliers are identified through formal risk assessment and are subject to enhanced qualification, monitoring, and control.

    What a critical supplier typically includes

    Organizations commonly classify a supplier as critical when one or more of the following apply:

    • The supplier provides parts, materials, or components that directly affect final product performance, safety, or regulatory characteristics (for example, flight-critical aerospace components, sterile medical-device materials, or pressure-containing parts).
    • The supplier delivers special processes that cannot be fully verified by subsequent inspection or testing (for example, heat treatment, plating, welding, nondestructive testing, or sterilization services).
    • The supplier has unique capabilities, approvals, or intellectual property, and there are limited or no qualified alternate sources.
    • The supplier provides systems or services that are essential to manufacturing or quality operations (for example, calibration labs, certain software providers, or logistics services that are single points of failure).
    • The supplier’s performance has a direct impact on regulatory, customer, or contractual requirements (for example, approved special-process houses in aerospace or validated material suppliers in life sciences).

    What a critical supplier is not

    • It is not simply a preferred or high-volume supplier. High spend alone does not make a supplier critical.
    • It is not every supplier that provides indirect goods or services, such as general consumables or office supplies, unless those services create a clear operational or compliance risk.
    • It is not a fixed regulatory category across all industries; each organization defines and documents its own criteria based on risk.

    Operational use in manufacturing systems

    In practice, the designation of a supplier as critical influences how the supplier is managed across ERP, MES, QMS, and procurement workflows:

    • Supplier qualification and approval: Critical suppliers typically undergo more rigorous initial evaluation, which may include on-site audits, deeper technical reviews, and tighter quality agreements.
    • Ongoing monitoring: Quality and supply chain teams often apply enhanced metrics such as detailed supplier scorecards, on-time delivery and defect tracking, and more frequent performance reviews.
    • Change control and notifications: Changes at a critical supplier, such as process modifications, facility moves, or key equipment changes, are usually subject to formal notification and internal impact assessment.
    • Incoming inspection and traceability: Materials or parts from critical suppliers often receive higher sampling levels, additional verification steps, and tighter lot-level traceability in MES or ERP.
    • Risk and continuity planning: Critical supplier lists are frequently used in supply chain risk assessments, business continuity plans, and dual-sourcing strategies.

    Relationship to quality and compliance

    In regulated sectors such as aerospace, defense, and medical devices, critical suppliers are often referenced in procedures related to supplier control, nonconformance management, and internal or external audits. Organizations may be expected to:

    • Define criteria for classifying suppliers as critical or non-critical.
    • Maintain documented lists of critical suppliers and their scope of supply.
    • Demonstrate appropriate oversight, including audits, records of corrective actions, and documented performance reviews.

    Manufacturing and quality systems may tag or flag critical suppliers so that related purchase orders, work orders, and incoming inspections follow defined workflows.

    Common confusion

    • Critical supplier vs. sole-source supplier: A sole-source supplier is the only available or approved source for a given item or service. Many sole-source suppliers will be critical, but a critical supplier is defined by risk and impact, not just by exclusivity.
    • Critical supplier vs. key supplier or strategic supplier: Key or strategic suppliers are important from a commercial or strategic standpoint (for example, volume or long-term partnerships). Critical suppliers are specifically important for product quality, compliance, and operational risk. The two groups may overlap but are not identical.
    • Critical supplier vs. critical part: A critical part is an item with particular quality, performance, or safety significance. A supplier may be classified as critical because they provide one or more critical parts, but the terms address different objects in the supply chain.
  • supply chain risk management

    Supply chain risk management (SCRM) is the systematic process of identifying, assessing, monitoring, and treating risks that arise from an organization’s suppliers, contractors, logistics partners, and broader supply network. In industrial and regulated manufacturing environments, it focuses on how external parties and materials can affect product quality, safety, security, compliance, and continuity of operations.

    Scope and key elements

    SCRM commonly covers:

    • Supplier-related risks: financial stability, capacity, quality performance, regulatory history, and dependence on single or sole sources.
    • Material and component risks: counterfeit parts, substitutions, obsolescence, and variability in critical characteristics.
    • Process and service risks: outsourced manufacturing, special processes, calibration, maintenance, and logistics services that affect product conformity or availability.
    • Information and data risks: handling of technical data, intellectual property, production instructions, and order information by external parties.
    • Cyber and OT/IT supply chain risks: vulnerabilities introduced through hardware, software, firmware, and connected equipment supplied or maintained by third parties.
    • Geopolitical and environmental risks: country-of-origin constraints, sanctions, transportation routes, and exposure to natural disasters.

    It typically includes risk identification, qualitative or quantitative assessment, documented controls, and ongoing review, often integrated with enterprise risk management, quality management, and information security programs.

    Operational meaning in manufacturing

    In manufacturing operations, supply chain risk management appears in activities such as:

    • Supplier qualification, audits, and approval workflows managed through quality or ERP/MES systems.
    • Contract requirements on traceability, change notification, cybersecurity practices, and data handling.
    • Incoming inspection plans and sampling levels tied to supplier risk ratings.
    • Dual sourcing, safety stock, and alternate material approvals for high-risk or single-source items.
    • Controls on software, firmware, and networked equipment from vendors, aligned with cybersecurity standards (for example, policies modeled on NIST or similar frameworks).
    • Monitoring of supplier performance metrics (delivery, quality, incidents) and periodic risk re-evaluation.

    Relation to cybersecurity and NIST 800-53 SR

    In the context of NIST 800-53, the SR (Supply Chain Risk Management) control family focuses on risks introduced by information and communications technology (ICT) and operational technology (OT) products and services. This includes:

    • Assessing and selecting vendors of software, hardware, and cloud or managed services.
    • Defining security, transparency, and integrity requirements for externally provided ICT/OT components.
    • Maintaining traceability of components, configurations, and updates received through the supply chain.
    • Monitoring for tampering, unauthorized changes, or unexpected behavior in supplied systems.

    This cybersecurity-oriented view is typically integrated into broader SCRM practices so that physical, quality, and digital risks from the supply chain are managed in a coordinated way.

    Common confusion

    • Supply chain management vs. supply chain risk management: Supply chain management (SCM) focuses on planning, sourcing, production, and logistics to meet demand. SCRM specifically targets uncertainty and potential adverse events across that chain, and may recommend accepting, reducing, transferring, or avoiding specific risks.
    • Vendor risk management vs. supply chain risk management: Vendor risk management often centers on individual suppliers or service providers. SCRM looks at end-to-end flows of materials, data, and services, including sub-tier suppliers and systemic risks such as concentration in one region or technology.
  • What data from suppliers is most critical to assessing backlog execution risk?

    For assessing backlog execution risk, the most useful supplier data is specific, forward looking, and directly mappable to your own purchase orders, parts, and work orders. In regulated and long-lifecycle environments, you typically need more than a high-level on-time delivery metric.

    1. Order- and line-level delivery commitments

    This is usually the single most important input for backlog risk.

    • Confirmed commit dates per PO line / schedule line (not just requested dates).
    • Partial shipment plans (split deliveries, quantities per date).
    • Firm vs tentative commitments with clear status codes.
    • Lead-time changes by part family or commodity.

    Value depends on: reliable linkage between supplier line IDs and your PO/part structure, frequency of updates, and whether suppliers systematically update commits when issues occur.

    2. Capacity, prioritization, and constraints

    To understand whether your backlog can be executed on time, you need some view into supplier capacity and bottlenecks, at least for critical parts.

    • Rough-cut capacity by work center, line, or product family for the coming 3 to 12 months.
    • Slotting / priority rules the supplier uses (e.g., program priority, customer tier).
    • Current load vs capacity for your parts or programs if they are willing to share.
    • Known constraint flags (single machine, unique process, specialized operator, qualification-limited tools).

    This data is often qualitative or semi-structured. It is most useful when at least your top-tier and sole-source suppliers expose it through a portal or structured file that aligns with your part families and programs.

    3. Material availability and upstream dependencies

    For long-lead or regulated items, a large portion of backlog risk is hidden in your supplier’s own supply chain.

    • Material availability status for key raw materials and components (on-hand, on-order, short).
    • Planned receipts and commit dates from their key sub-suppliers for your parts.
    • Allocation status when materials are shared across multiple customers or programs.
    • Qualification-dependent materials (e.g., only one approved mill or coating provider) with risk flags.

    Because full multi-tier transparency is rare, many plants start by requiring this data only for a small set of critical or sole-source parts and then standardize the format over time.

    4. Quality performance and open issues

    Quality data is critical because NCR, rework, and MRB cycles can quietly consume your schedule margin.

    • Supplier quality metrics at part number / family level (defect rate, DPPM, right-first-time).
    • Open NCR / deviation / concession status for deliveries that tie to your current backlog.
    • Rework / replacement lead times for defective lots.
    • Inspection and FAI status (e.g., AS9102 FAI approved, pending, failed) where applicable.

    In brownfield environments, this often requires bridging data across your QMS/NCR system, supplier portals, and ERP/MRP so that a backlog line clearly shows if it depends on high-risk or repeatedly nonconforming suppliers.

    5. Schedule stability and delivery performance history

    Historical behavior is not a guarantee, but it is a strong indicator of schedule risk.

    • Line-level OTD performance (not just aggregate percentages) by part and program.
    • Average and worst-case slip in days for similar parts or routings.
    • Frequency of commit date changes per PO line.
    • Split-ship behavior (partial early, remainder late) and impact on your build plan.

    In regulated aerospace and defense, this can highlight suppliers whose chronic small slips accumulate into missed milestones, even if their scored OTD looks acceptable.

    6. Change notifications and disruption signals

    Execution risk often spikes when suppliers change processes, facilities, or key resources.

    • Planned process changes (new routing, tooling, special process provider) with effective dates.
    • Facility moves or consolidations and associated ramp-down / ramp-up plans.
    • Key personnel changes that affect special processes, programming, or inspection signoffs.
    • Regulatory or approval status changes (loss of a certification, new approval pending, etc.).

    These notifications rarely arrive in a structured way. Mature organizations implement formal change-control workflows with suppliers so that such changes tie to specific parts, POs, and qualification plans.

    7. Logistics and shipping visibility

    Once parts leave the supplier, execution risk shifts to logistics and customs.

    • Advanced shipping notices (ASN) with serial/lot, quantities, and packing details.
    • Carrier, tracking IDs, and incoterms for each shipment.
    • Export / import documentation status for ITAR or other controlled items.
    • Realistic transit time and customs risk for cross-border shipments.

    For backlog risk, the key is not only where the shipment is today, but whether ASN and logistics data are timely and accurate enough to update your MRP, commits, and shop floor schedules.

    8. Data attributes that determine actual usefulness

    The same nominal data can be either powerful or misleading depending on how it is managed.

    • Granularity: part-level and line-level data is more actionable than aggregated supplier totals.
    • Alignment: data keys (part numbers, PO lines, rev levels) must match your ERP/MES/QMS records.
    • Refresh rate: weekly or monthly updates are often too slow for volatile programs.
    • Data quality and validation: missing fields, inconsistent IDs, and manual spreadsheets increase error risk.
    • Traceability: being able to see who changed a commit, when, and why is important in regulated settings.

    In brownfield environments with mixed legacy systems, it is common to start with a small, validated set of data elements from critical suppliers and progressively expand as integrations stabilize.

    9. How this coexists with existing ERP, MES and planning systems

    Most plants already store some of this data in ERP/MRP, supplier portals, or email threads. Replacing those systems outright is rarely practical due to validation burden, change control, and downtime risk.

    • Use your existing ERP/MRP as the system of record for POs and requirements.
    • Pull in supplier commits, capacity flags, and quality risk indicators via interfaces or structured uploads.
    • Expose a consolidated backlog risk view to operations, planning, and quality, while leaving core transactional processes in place.
    • Introduce new portals or collaboration tools incrementally, prioritizing critical suppliers and high-risk parts first.

    In regulated environments, any new integration or automated decision logic should go through appropriate validation and change control, with clear audit trails of how supplier data was used to adjust schedules or commitments.

    10. Suggested minimum supplier dataset for backlog risk

    If you have to be selective, the following fields typically deliver the most value for execution risk assessment:

    • PO number, line, release, and your part number (with revision).
    • Confirmed commit date(s) and quantities, with status (firm/tentative).
    • Known constraints or special-process dependencies for that line.
    • Material availability status and any upstream shortages impacting that line.
    • Line-level OTD history and NCR count for that part over a defined lookback.
    • ASN and shipment status once goods are in transit.

    Starting with this core, you can then layer in richer capacity and change-notification data where supplier maturity and integration readiness allow.

  • counterfeit parts prevention

    Counterfeit parts prevention refers to the coordinated processes, controls, and governance used to avoid introducing fake, misrepresented, or unauthorized components and materials into a production or maintenance environment. In regulated manufacturing, it typically covers electronic components, mechanical parts, raw materials, and documentation that are falsely labeled, altered, or supplied outside approved channels.

    In practice, counterfeit parts prevention combines quality management, supply chain controls, and traceability so that only verified and authorized items are procured, received, stored, used, and serviced. It is especially emphasized in sectors such as aerospace, defense, medical devices, and critical infrastructure, where unapproved parts can create safety, reliability, or compliance issues.

    Typical elements in operational environments

    In industrial and manufacturing systems, counterfeit parts prevention commonly includes:

    • Approved supplier and source controls: Maintaining vetted supplier lists, defining authorized distributors, and managing supplier qualification and monitoring.
    • Incoming inspection and verification: Visual inspection, documentation checks, certificate verification, and sometimes testing to confirm identity, performance, and conformity.
    • Traceability and genealogy: Recording lot, batch, serial, and supplier data in MES, ERP, or QMS to trace components through assemblies, orders, and shipments.
    • Documented configuration control: Ensuring part numbers, revisions, and approved alternates are clearly defined and controlled so that unapproved substitutes are not used.
    • Storage and segregation practices: Physically separating suspect, nonconforming, or unverified items from released inventory, with clear status identification.
    • Supplier documentation control: Managing certificates of conformity, material test reports, and other supplier records, and linking them to specific lots or serials.
    • Suspect part handling: Defined procedures for identifying, quarantining, investigating, and dispositioning suspect or confirmed counterfeit parts.
    • Training and awareness: Educating purchasing, receiving, quality, and production personnel on counterfeit indicators and reporting channels.

    Relationship to standards and quality systems

    Many industry standards and customer requirements reference counterfeit parts prevention explicitly or implicitly through supplier management, risk management, and traceability clauses. For example, aerospace quality standards commonly address:

    • Evaluation and control of external providers that could introduce counterfeit items.
    • Additional verification steps when purchasing from brokers or non-original sources.
    • Requirements to document and report confirmed counterfeit parts to customers or authorities, where applicable.

    Operationally, counterfeit parts prevention often relies on integration between ERP (purchasing, supplier master data), MES (shop-floor usage and traceability), and QMS (nonconformance, supplier corrective action, and audits).

    What it includes and excludes

    • Includes: Controls to prevent introduction and use of fake, misrepresented, or unauthorized components; detection and handling of suspect parts; supply chain governance; and traceability practices that support investigation and containment.
    • Excludes: General product quality issues that result from design mistakes or normal process variation; those are typically handled under broader quality control and CAPA processes unless there is evidence of counterfeit supply.

    Common confusion

    • Counterfeit parts prevention vs. general supplier quality: Supplier quality management covers the overall conformity and performance of supplied items. Counterfeit parts prevention focuses specifically on authenticity and authorization, although it uses many of the same tools.
    • Counterfeit parts vs. nonconforming parts: A nonconforming part fails a requirement but may be genuine and from an approved source. A counterfeit part is misrepresented in origin, specification, or authorization, regardless of whether it appears to meet requirements.
  • single-source supplier

    Core meaning

    A **single-source supplier** is a supplier that is, in practice, the only viable or approved provider for a specific part, material, or service within an organization’s supply base. The customer may be able to buy similar items elsewhere in theory, but due to design, qualification, contractual, or operational constraints, all purchases of that item are routed to this one supplier.

    In industrial and regulated manufacturing environments, single-source suppliers are common for:

    – Custom-designed or proprietary components
    – Safety- or quality-critical items with formal qualification or validation
    – Specialized processes (e.g., certain coatings, heat treatments, or software modifications)
    – Tooling, fixtures, or equipment for which the OEM is the only approved vendor

    Use in operations and supply chain

    In real workflows, a single-source supplier typically means:

    – The item has one approved vendor in the ERP/MRP or vendor master for that part number.
    – Alternate suppliers exist only with significant requalification, redesign, or regulatory impact.
    – Lead time, capacity, and disruption at that supplier directly affect production, maintenance, or service levels.

    Organizations often:

    – Flag single-sourced parts in their planning or risk registers.
    – Apply additional monitoring, contractual controls, or inventory strategies around these items.
    – Coordinate closely with quality, engineering, and procurement before attempting to add or change a source.

    Boundaries and exclusions

    A single-source supplier **is not** the same as:

    – **Sole-source supplier**: Often used to mean there is literally no other supplier in the market (e.g., unique IP or monopoly). “Single-source” usually reflects the customer’s current sourcing choice and approvals, not global market reality.
    – **Preferred supplier**: A vendor that gets the majority of spend but can be substituted easily. Single-source status implies substitution is non-trivial.

    Single-source status is defined **from the buying organization’s perspective**, not the entire industry. Another manufacturer might have different approved sources for the same generic item.

    Risk and reliability considerations

    Because all supply for the affected item flows through one organization, single-source suppliers are commonly treated as higher risk in:

    – Business continuity and resilience assessments
    – Capacity and lead-time planning
    – Supplier risk and quality management reviews

    Common risk factors include:

    – Long or variable lead times
    – Fragile financial, geopolitical, or logistics context
    – Tight capacity relative to demand
    – Complex or lengthy qualification/approval cycles that delay switching

    Site context: maintenance and AOG-type scenarios

    In maintenance-intensive sectors (e.g., aviation, pharmaceuticals, continuous process plants), single-source suppliers are closely watched for items whose absence can halt operations, such as:

    – Safety-critical units or assemblies with unique approvals
    – Long-lead structural or custom parts
    – Components with unique repair capabilities or IP

    For these items, planners and reliability teams typically map single-source status when assessing downtime or “grounding” risk, and may adjust stocking policies, contingency plans, or engineering change priorities accordingly.

    Common confusion and misuse

    – **Market vs. internal single sourcing**: A part may be technically multi-source in the market, but if only one vendor is qualified and set up in the ERP, it functions as single-source for that plant or company.
    – **Temporary vs. structural**: A part may be temporarily single-source (e.g., during ramp-up of a second source). Some organizations track planned vs. structural single-source states separately.

    Careful use of terminology in specifications, contracts, and risk registers helps distinguish policy choices (choosing to buy from one source) from hard constraints (only one feasible or approved source exists).

  • contingency planning

    Contingency planning is the structured process of preparing an organization to maintain or restore critical operations when disruptive events occur. It focuses on identifying potential disruptions, defining prioritized responses, and documenting how people, systems, and facilities will operate under abnormal or degraded conditions.

    What contingency planning includes

    In industrial and regulated manufacturing environments, contingency planning commonly includes:

    • Identifying critical processes and assets, such as production lines, utilities, OT/IT systems, MES/ERP, labs, and quality release workflows.
    • Analyzing risks and impact of events like cyber incidents, equipment failures, power loss, supply interruptions, data loss, or facility inaccessibility.
    • Defining continuity and recovery strategies, for example manual workarounds, alternate sites, redundant systems, or predefined production rerouting.
    • Documenting step-by-step procedures for activating the plan, communicating roles and responsibilities, and escalating decisions.
    • Coordinating with related plans such as incident response, disaster recovery, emergency response, and business continuity.
    • Testing and maintaining plans through exercises, simulations, and periodic reviews as processes, systems, and regulations change.

    In the context of cybersecurity and frameworks such as NIST 800-53, contingency planning is often associated with protecting and recovering information systems and industrial control systems so that essential functions can continue or resume within acceptable timeframes.

    Operational meaning in manufacturing

    On the shop floor and in supporting functions, contingency planning typically shows up as:

    • Documented procedures for running production if MES or network connectivity is lost.
    • Predefined priorities for which products, lines, or customers are supported first during limited capacity.
    • Clear instructions for quality and release when electronic records are unavailable, including temporary paper records and later reconciliation.
    • Guidance for handling prolonged OT system downtime, including acceptable use of manual controls or alternate equipment.
    • Communication trees and notification steps for operations, IT/OT, quality, EHS, and management.

    What contingency planning is not

    • It is not the same as routine troubleshooting for minor issues or normal maintenance.
    • It is not limited to IT backup and restore, although backup and restore procedures may be part of the plan.
    • It is not only a paper exercise; effective contingency planning expects realistic execution, testing, and revision.

    Common confusion

    • Contingency planning vs. business continuity planning (BCP): BCP usually describes the broader, organization-wide strategy for continuing key business functions. Contingency planning often refers to more specific, system- or process-level plans that support that strategy.
    • Contingency planning vs. disaster recovery (DR): DR focuses mainly on restoring IT and OT systems and data after a disruption. Contingency planning is wider and includes how operations and people work during the disruption, including manual or alternate processes.

    Link to NIST 800-53 context

    Within NIST 800-53, the Contingency Planning (CP) control family addresses requirements for developing, implementing, and maintaining plans to continue or restore system operations after disruptions. For small manufacturers, this often involves right-sizing documentation and exercises so that critical OT and IT systems, such as MES, SCADA, historians, and quality systems, can be recovered in a way that supports regulatory and production needs.

  • AOG risk map

    Core meaning

    An **AOG risk map** is a structured representation of the process, part, and supplier risks that can lead to **aircraft-on-ground (AOG)** events—situations where an aircraft is unable to operate because required parts, repairs, or documentation are not available.

    It typically combines:

    – Critical aircraft parts, systems, or configurations that can cause AOG if unavailable or non-conforming.
    – Manufacturing and maintenance process steps that affect those parts.
    – Suppliers and logistics paths that provide those parts or services.
    – Risk indicators such as likelihood of disruption, detection capability, and potential operational impact.

    The result is a map—often visual but sometimes tabular—that links operational risks in factories, supply chains, and MRO (maintenance, repair, and overhaul) operations to their potential to create AOG situations.

    Use in industrial and aerospace workflows

    In aerospace manufacturing and MRO environments, an AOG risk map is commonly used to:

    – Identify which parts or assemblies are AOG-critical and where they are produced or controlled.
    – Trace how issues in upstream processes, quality controls, or suppliers could cascade into AOG events.
    – Prioritize monitoring, contingency planning, and escalation paths for high-risk items.
    – Align OT/IT, MES, ERP, and supply-chain systems around consistent AOG-critical object lists and risk attributes.

    Operationally, manufacturing, supply chain, quality, and engineering teams may reference the AOG risk map when:

    – Assessing the impact of process changes or capacity shifts on AOG-critical parts.
    – Evaluating new or alternative suppliers for components with AOG exposure.
    – Routing nonconformances, deviations, or concession requests involving AOG-critical items.
    – Coordinating responses to disruptions (e.g., late deliveries, quality escapes) that could ground aircraft.

    Structure and data sources

    An AOG risk map often aggregates data from multiple systems, for example:

    – **ERP/MRP**: part master data, criticality flags, demand profiles.
    – **MES/production systems**: routings, work centers, process history, WIP positions.
    – **Quality systems (QMS, LIMS, CAPA tools)**: nonconformance history, escape risks, defect trends.
    – **Supplier and logistics systems**: lead times, performance, single- or sole-source exposure.

    The “map” may be implemented as:

    – A visual node-and-link diagram connecting parts, processes, suppliers, and AOG risk levels.
    – A matrix or table with part numbers, plants, suppliers, and risk ratings.
    – A model embedded in analytics or operations-intelligence platforms that supports filtering and alerts for AOG risk.

    Boundaries and exclusions

    An AOG risk map:

    – **Includes**: risks specifically tied to aircraft being unable to depart or continue service due to missing, delayed, or non-conforming parts, documentation, or repairs.
    – **Can include**: manufacturing, maintenance, supply, and logistics risks where their consequence is framed in terms of AOG probability or duration.
    – **Excludes**: general enterprise risk maps that do not explicitly tie risks to AOG impact (e.g., purely financial or reputational risks without an AOG linkage).
    – **Is not the same as**: a full safety hazard analysis (which focuses on hazards to people and equipment) or a generic FMEA, although those analyses may feed into an AOG risk map.

    Common confusion and related terms

    – **AOG vs. general production risk mapping**: AOG risk mapping is specifically oriented to aircraft-grounding consequences, not just late orders or production delays. A part can be high risk for schedule yet low AOG risk if it does not impact aircraft dispatch.
    – **AOG risk map vs. critical part list**: A critical part list is typically a flat list of high-importance items. An AOG risk map adds structure, showing how those items link to processes, plants, suppliers, and potential failure paths.
    – **AOG risk map vs. bow-tie or fault tree analysis**: Bow-tie or fault tree diagrams analyze causal chains for specific events. An AOG risk map is broader, aggregating many potential causes and pathways into one coherent view focused on AOG exposure.

    Application in the site context

    Within aerospace factories and regulated manufacturing environments, an AOG risk map is often maintained as part of broader risk and operations-intelligence practices. It is used to align MES, ERP, QMS, and supply-chain data around a shared understanding of AOG-critical items, making it easier to:

    – Monitor production and quality signals that may affect AOG-critical parts.
    – Coordinate cross-functional response when disruptions occur.
    – Review and update risk assessments when there are changes in demand, suppliers, or process design.

    The map is generally kept as a living artifact, subject to both periodic review and event-driven updates when material changes occur in products, processes, or supply networks that influence AOG risk.