How to build a supplier risk heat map without a GIS team
Most procurement teams don't have a GIS analyst on staff, and most don't need one for day-to-day sourcing work. But the question keeps coming up at QBR time or right after a typhoon shuts down a port: how much of this category actually sits in one place? You can answer that without specialist software. It just takes longer than anyone wants to admit, and it has a shelf life.
What a spreadsheet tells you
Your vendor master has addresses, maybe lat/long if someone bothered to geocode them, spend by supplier, and whatever risk tier the last audit assigned. That's a list. A list doesn't show you that fourteen of your tier-2 connector suppliers sit inside the same three-kilometer radius outside Shenzhen, because nothing in a spreadsheet forces two rows to notice each other.
You can get partway there with pivot tables: group by region, by postal code, by country. That catches country-level concentration fine (everyone already knows "too much China" or "too much Vietnam" as a line item). It misses the finer thing that bites you, which is twenty different legal entities across three tiers of your supply base all drawing from the same industrial park, the same flood-prone river delta, or the same single port of exit. Country rollups can't see that. Postal codes barely can, and only if your data is clean enough to trust, which it usually isn't.
The manual geography audit, step by step
If you're doing this by hand, the process looks something like this. Pull every supplier address from your vendor master, including sub-tier where you have visibility (which, honestly, is rarely past tier 2). Geocode anything that's missing coordinates. Drop the whole set into a mapping tool, Google My Maps or a GIS trial account, color-coded by spend or by category. Then eyeball it for clusters: zoom in on anywhere the pins bunch up, cross-reference those addresses against known flood zones, seismic risk, or port catchments, and write up whatever you find.
This works. It's also the kind of project that eats two or three weeks of an analyst's time once a year, assuming nobody's on vacation and the address data doesn't need cleaning first (it does). The output is good on delivery day and stale within a quarter, because supplier lists change, new facilities open, and nobody re-runs the whole exercise until the next audit cycle forces it.
The other problem with manual pin-mapping is that it only shows you what you already thought to ask. A visual cluster of fourteen pins on a map tells you something is there. It doesn't tell you what's on the ground at that address: whether it's genuinely one industrial park or two adjacent ones that happen to be close, whether there's been new construction since your last site visit, or whether that "supplier facility" pin is a trading office three towns over from the real plant.
What procurement risk mapping tools should do
Any tool you evaluate for this should do two things a spreadsheet can't: plot your spend against real, physical geography instead of postal-code approximations, and surface the clusters for you instead of making a human stare at pins until something looks wrong. If it just recolors your existing spreadsheet by region, you haven't bought anything you couldn't build in an afternoon with a pivot table.
Sourcing Concentration was built for exactly the gap between those two approaches: a once-a-year pass that plots your category spend against supplier geography using current satellite imagery, so you get a ranked list of concentration clusters instead of a spreadsheet you have to eyeball yourself. It's built for the category manager who needs the answer to "how much of this sits in one place" without spinning up a GIS project to get it.
If your supplier geography audit is still a once-a-year scramble with pins on a map, it might be worth seeing what a dedicated pass at it looks like.