Risk management guidance is mostly written for organisations with dedicated risk functions, quarterly committees, and staff whose only job is thinking about what could go wrong. That describes very few mid-sized manufacturers. What follows is a version that a small team can actually run.
Identify: Work Backwards From Stoppage
Don’t start with a taxonomy of risk categories. Start with a simple question asked of each product line: what would have to fail for us to stop shipping this? Then follow each answer back through the supply chain.
This produces a concrete, specific list rather than an abstract one. It surfaces the sole-source component, the single certified operator, the tooling supplier with no backup, the plant that holds the only relevant certification. Abstract risk registers list things like geopolitical instability. This method lists things like the seal supplier in a specific town.
Assess: Two Axes, Kept Simple
For each identified risk, estimate likelihood and impact. Precision isn’t the point and false precision is actively harmful — a three-by-three scale is enough to sort a list.
Impact should be expressed in money and time: what does a week of this failing cost, and how long would recovery take? The recovery duration is usually the more decisive number, because it determines whether a mitigation is worth building in advance or can be handled reactively.
Mitigate: Four Options, in Order of Cost
Accept. For low-likelihood, low-impact risks, do nothing deliberately and record that you decided to. Most items on any honest list belong here, and saying so frees attention for the ones that matter.
Reduce the likelihood. Supplier development, better contracts, improved quality processes at source. Usually the cheapest genuine mitigation.
Reduce the impact. Second sources, buffer stock, alternative routes, documented process knowledge. Costs more, applies to risks you can’t prevent.
Transfer. Insurance, contractual liability. Useful for financial impact, useless for operational continuity — an insurance payout doesn’t restart your line.
Monitor: Attach it to Something That Already Happens
This is where most risk processes die. A register that requires a special meeting will be reviewed twice and then abandoned as workload rises.
Attach it instead to something with existing momentum: fifteen minutes in the monthly operations review, with only the top ten risks and only what changed. Supplier financial health, lead time trends, concentration shifts, mitigation actions overdue. Short, regular, and embedded beats thorough and quarterly, because the quarterly version stops happening in month seven.
The One Thing to Do First
If you do nothing else from this article, list every component with a single qualified source and no substitute, sorted by what a stoppage would cost. That list is typically shorter than people expect and represents most of your genuine exposure. Working through it in order is a better use of six months than building a comprehensive framework.
Expect the list to change as you work through it. Qualifying a second source removes one entry and occasionally reveals another you hadn’t seen. That’s the process functioning, not a sign the original list was wrong.
ticktick.ai tracks supplier concentration, lead time drift, and single-source exposure continuously, so the register updates itself between reviews.
