Supply Chain Risk

Supply Chain Risk

Supply Chain Risk refers to the danger that a company grinds to a halt because a supplier fails, a component is missing, or a purchased piece of software contains a vulnerability. In the tech and AI industry, this risk is especially high because only a handful of firms and countries supply central components.

Almost no product is created in a single place. A smartphone consists of parts from hundreds of suppliers across dozens of countries. This chain from raw material to finished device is called a supply chain. Supply Chain Risk is the danger that some link in this chain fails and, as a result, the entire production stalls. The failure can have many causes: an earthquake, a war, a company bankruptcy, a political export ban, or a hacker attack. It always refers to the same underlying problem: you depend on things you do not control yourself.

Why a single missing chip can stop an entire factory

A supply chain is only as strong as its weakest link. A car cannot be delivered 99 percent complete. If a control chip worth just a few euros is missing, the entire vehicle sits idle. That is exactly what happened in the auto industry in 2021 and 2022. Manufacturers had to close plants even though every other part was ready and waiting.

In the tech industry, there is a particular aggravating factor. Many key products come from very few suppliers. The most advanced chips are manufactured almost exclusively in Taiwan, above all by the contract manufacturer TSMC. The machines needed to produce such chips at that level of quality are built by only a single company in the Netherlands. Such bottlenecks are called a single point of failure: a point whose failure paralyzes everything else.

That is why Supply Chain Risk has long ceased to be a purely logistical issue. It is a political and financial issue. Investors ask how dependent a company is on a single supplier. Governments are pouring billions into building their own chip factories in order to reduce dependency.

How companies map their dependencies

The first step is taking stock. Companies compile lists of which parts come from where and which supplier stands behind the supplier. That sounds trivial, but it is difficult. Many companies know their direct suppliers but not their suppliers' suppliers. That is exactly where the most dangerous bottlenecks hide.

Afterward, each risk is assessed along two dimensions: how likely is the failure, and how severe would the consequences be? A rare but catastrophic event often receives more attention than a frequent, harmless one. This assessment gives rise to countermeasures. Typical ones include larger inventories, a second supplier for critical parts, and production sites spread across multiple regions.

Each of these measures costs money. A second supplier is usually more expensive, and a full warehouse ties up capital. For decades, the opposite was considered best practice: keeping inventories as small as possible, with parts arriving exactly when needed. This principle is called Just in Time, and it makes supply chains cheap but fragile. Today, many companies deliberately weigh how much security is worth how much additional cost.

Digital supply chains: libraries, models, cloud

Software also has a supply chain. Hardly any program is written entirely from scratch. Developers incorporate ready-made code building blocks from other people, often free ones from the internet. If such a building block contains a flaw, every program that uses it inherits it. In 2021, this hit the logging library Log4j, which was in use millions of times worldwide.

With AI, this chain grows even longer. A start-up’s chatbot often runs on someone else’s language model, which computes on someone else’s graphics cards in someone else’s data center. If the model provider changes its prices or discontinues a version, the product is immediately affected. The training data is also part of this: if it is flawed or was obtained in a legally questionable way, the problem migrates into the finished model.

In the news, you usually encounter this term in three contexts: export restrictions on chips, hacker attacks via a software supplier, and new laws such as supply chain due diligence acts that hold companies responsible for working conditions at their suppliers. A common misconception is that Supply Chain Risk only affects factories and shipping containers. For a pure software company, it can be just as existentially threatening.

Related Products

Latest News

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.