Ask most UK manufacturing owners how many single-source dependencies exist in their business, and you'll get a rough guess — "a few," "not many," "I'd have to check." Ask the same question after a structured supplier audit, and the number is almost always higher than the guess. Not because anyone was careless, but because single-sourcing accumulates quietly, one reasonable decision at a time, until nobody has stepped back to count the total exposure.
This is a practical checklist, not a theoretical framework. It's the same process I run on-site with clients, condensed into something you can genuinely work through this week.
Step 1: List every material category, not just the big ones
Start with a full list of everything you buy — raw materials, packaging, critical components, even indirect categories like specialist tooling or calibration services. The categories that get missed in an informal review are rarely the largest-spend ones; they're the smaller, easy-to-overlook categories where nobody thought to diversify because the spend never felt significant enough to worry about.
Step 2: For each category, count the approved suppliers — honestly
A supplier list showing three names for a category is not automatically diversified. If two of those three haven't received an order in eighteen months, you have one real supplier and two names on a spreadsheet. Count who you'd actually be able to call this week if your primary supplier failed tomorrow — not who's theoretically approved.
Step 3: Score each single-source category on two dimensions
Not every single-source dependency carries equal risk. Score each one on two axes: how difficult would this category be to replace (lead time, technical specification, geographic scarcity), and how critical is it to production continuing at all. A single-source dependency on a commodity material with a six-week lead time to requalify a new supplier is a very different risk than a single-source dependency on packaging that any local printer could produce next week.
High risk: hard to replace, critical to production
These are the categories that stop the line entirely if the supplier fails — specialised components, materials requiring long qualification periods, anything geographically concentrated with one or two global producers. These deserve active mitigation now, not after an incident.
Medium risk: hard to replace, not immediately critical
Important but with some buffer — either inventory on hand, or a production sequence that gives you weeks rather than days to respond. Worth a documented contingency plan, not necessarily an active second supplier relationship yet.
Lower risk: easy to replace regardless of criticality
Don't spend diversification effort here. If a category could genuinely be resourced within days, the risk is more theoretical than operational — the effort is better spent on the categories above.
Step 4: For every high-risk category, do one of three things
- Qualify a genuine second supplier — not a name on a list, an actual relationship with at least a small, live order history, so the capability is proven rather than assumed.
- Hold strategic buffer stock — a deliberate, calculated safety stock specifically sized against this supplier's realistic failure and replacement lead time, not a generic safety stock number applied uniformly across your inventory.
- Document and accept the risk consciously — sometimes diversification genuinely isn't economical for a given category. That's a legitimate business decision — but it should be a decision someone made deliberately, not a default that emerged from nobody looking.
Step 5: Review this annually, not once
A supplier risk map done once and filed away decays. Suppliers get acquired, change ownership structure, shift production geography, or quietly reduce the categories they serve. An annual review — even a half-day exercise — catches the drift before it becomes a live problem again.
"I look for two things on site: the number of single-source dependencies and the quality of the relationship with those suppliers. If the first is high and the second is informal, I know the risk profile without running any further analysis."
None of this requires sophisticated software or a dedicated risk function. It requires roughly a day of structured, honest inventory of what you actually depend on — and the discipline to act on what that inventory reveals, rather than filing it away until the supplier failure makes the decision for you.
Know your exposure before you need to.
The Tier 1 Diagnostic includes a supplier risk mapping workstream — every single-source dependency identified and prioritised, before it becomes a production stoppage.
See the Risk Diagnostic →