Supply Chain Fragility Is a Programme Risk — and the Register Is Looking in the Wrong Direction
The contract had allocated liability. It had not created foresight.
The Missing Component
A £48 million technology programme was reported green at the end of January. The prime supplier had confirmed that all major equipment was on schedule. Contract milestones were intact. The risk register contained a familiar entry about supplier performance, rated low probability and medium impact.
Nine days later, the programme learned that a £3 connector used inside every field device came from a single factory in an affected region of China. The prime supplier held six weeks of stock. The factory could not confirm when production would resume. No contractual milestone had yet been missed, but the programme’s deployment sequence was already becoming impossible.
The risk nobody modelled was not “supplier failure”. It was the dependence of an outcome on a component that sat two tiers below the contract and nowhere in the programme’s view.
That distinction matters in February 2020. Disruption to factories, transport and workforces is exposing a weakness that programme textbooks have tended to leave at the boundary marked procurement. Supply chains are treated as commercial arrangements to be managed by suppliers. Programmes, meanwhile, manage schedules, budgets, risks and dependencies among the parties they can see.
The result is a dangerous fiction: if the prime contract is controlled, the supply chain is controlled.
Contracts Are Not Maps
The programme manager typically knows the legal chain. The organisation contracts with a prime supplier. The prime contracts with manufacturers, logistics providers, software specialists and installers. Responsibility flows down through terms and service levels. Reporting flows back up.
Operational dependence does not follow that neat line.
A delivery outcome may depend on:
- A specialist component made at one site
- A testing laboratory with a four-week queue
- A firmware change controlled by a small subcontractor
- A customs route chosen for cost rather than resilience
- A field engineer certification held by only twelve people
- A data feed owned by a party outside the main contract
- A packaging or transport constraint that becomes critical only at volume
The commercial structure tells us who owes what to whom. It does not tell us where the programme can stop.
In the composite technology programme, the prime supplier was meeting its contractual duty to report material delay. It had not declared one because its inventory might still bridge the interruption. From a supplier perspective, that was reasonable. From a programme perspective, waiting for certainty destroyed options. Alternative connectors required a design check, test approval and a change to the installation kit. Each week of silence shortened the time available to qualify them.
The contract had allocated liability. It had not created foresight.
A supply chain becomes a programme dependency at the point where its failure changes the outcome — not when the contract finally records a breach.
The Risk Register Is Looking at the Wrong Level
Programme risk practice favours named events with owners and mitigations. “Prime supplier misses delivery” fits the form. The underlying network does not.
Supply fragility is created by combinations:
- Concentration at a site or region
- Long replenishment time
- Lack of a technically qualified substitute
- Low visibility below the first contractual tier
- Inventory calculated for efficiency rather than interruption
- Change approval that takes longer than available stock
- Several programmes competing for the same scarce capacity
None of these conditions alone guarantees failure. Together they determine whether a disruption can be absorbed.
Textbook risk assessment also encourages probability debates. Teams argue whether a factory interruption is likely, then apply a colour. That is the wrong question for a dependency with severe consequences and no quick substitute.
The useful questions are:
- How long can the programme continue without replenishment?
- How long would detection take?
- How long would a substitute take to qualify?
- What decision becomes impossible if we wait another week?
- Who has authority to spend money or change design before failure is certain?
These questions convert supply uncertainty into programme time.
“The Supplier Owns It” Is Not an Answer
The strongest defence of the conventional model is sensible: a programme cannot inspect every subcontractor and component. The prime supplier is paid to manage its chain. If the customer starts directing lower tiers, accountability becomes confused, commercial leverage weakens and the programme creates an administrative burden larger than the risk.
That objection is correct. Programme managers should not become purchasing agents for every screw and service.
But there is a difference between managing the supplier’s supply chain and governing the programme’s exposure to it. The prime supplier may own replenishment. The programme still owns the consequence of delayed deployment, the sequencing alternatives, the operational contingency and the decision to accept cost for resilience.
The practical boundary is materiality. Visibility should extend below the first tier where all four conditions apply:
- The item or capability is essential to the outcome.
- Substitution requires material time, approval or redesign.
- The interruption would exceed available buffer.
- The programme has a decision it could take before contractual failure.
If there is no useful decision, more data merely creates anxiety. If there is a useful decision, ignorance is not delegation.
A Different Dependency Conversation
The programme board does not need a map of every supplier. It needs a map of critical supply paths.
For each outcome-critical deliverable, ask the prime supplier to identify the constraint that sets the recovery time: component, capacity, site, person, approval, route or data. Record the available buffer, earliest warning, substitution time and decision owner.
A simple view is enough:
| Critical deliverable | Hidden constraint | Buffer | Substitute time | Decision before failure |
|---|---|---|---|---|
| Field device | Single-source connector | 6 weeks | 8–10 weeks | Fund qualification now |
| Installation wave | Certified engineers | 3 weeks | 12 weeks | Resequence regions and train |
| Customer migration | External address file | 1 cycle | 6 weeks | Agree manual validation route |
| Service readiness | Specialist test facility | 2 slots | 5 weeks | Reserve capacity before design freeze |
This changes the board discussion. Instead of asking whether the supplier is “on track”, it asks whether the programme can still act before the dependency becomes a delay.
In the connector example, the board authorised parallel qualification at a cost of £180,000. The original stock ultimately lasted longer than feared, and only part of the alternative order was used. Some regarded the spend as unnecessary because the worst case did not occur.
That is the familiar criticism of resilience: success can look like waste. Yet the decision purchased an option. It reduced the point at which the programme would become a passenger to events. The relevant comparison was not £180,000 against zero; it was £180,000 against an eight-week deployment interruption with 320 field staff already mobilised.
Data Must Cross the Commercial Boundary
This kind of governance depends on information that many programmes do not request until trouble begins.
The prime supplier should provide evidence for critical paths without exposing every commercial detail. Useful data includes:
- Current stock and committed demand
- Production and transport lead times
- Concentration by site or specialist capability
- Approved alternatives and qualification status
- Known interruptions and recovery assumptions
- Other customers competing for the same constrained capacity
- The date on which a programme decision loses value
Reporting should be triggered by deterioration in buffer or option time, not only by a missed milestone.
This is where technology and commercial governance meet. A programme dashboard that consumes supplier status but cannot represent tier-two concentration or time-to-substitute is not integrated reporting. It is contract administration with coloured boxes.
The Programme Manager’s Uncomfortable Responsibility
Supply fragility sits between disciplines, which is why it is so easily missed. Procurement sees contractual obligation. The supplier sees inventory and fulfilment. Technology sees design. Operations sees continuity. Finance sees working capital. Risk sees scenarios. The programme manager is the role that must see the consequence running across all of them.
That does not mean owning every action. It means refusing to let divided ownership become an unowned outcome.
As disruptions continue to unfold, some programmes will discover that their suppliers are resilient. Others will find that a low-cost, low-visibility dependency governs the entire schedule. The difference will not be explained by the size of the contract or the sophistication of the risk register.
It will be explained by whether somebody looked past the supplier name and asked what, exactly, the programme was waiting for.
Supply chains are not external to programme governance. They are programme architecture made of organisations, contracts, inventory, routes and time. Until we model them that way, the most consequential dependency will remain the one nobody thought belonged on the plan.