SourcingConcentration

Blog

Tier 1 versus tier 2 supplier mapping: what the gap costs

Most procurement teams have tier 1 mapped cold. You know who ships to you, what they charge, how they score on your vendor scorecard. Tier 2 is where the picture goes thin. You might have a name in a spreadsheet because a tier 1 supplier mentioned it in a business continuity questionnaire two years ago, but you don't know where that plant sits, what else runs through the same postcode, or whether it shares a loading dock with three other suppliers' subcontractors.

That gap is where concentration risk hides.

Why tier 1 data doesn't tell you where the risk sits

A tier 1 supplier list tells you who you pay. It doesn't tell you who makes the part. A contract manufacturer in Shenzhen can be your tier 1 relationship while the castings come from a forge two provinces over, one that also supplies four of your other "different" tier 1 vendors. On paper you've diversified sourcing across four contracts. On the ground you've got one forge, one river valley, one single point of failure.

Closing that gap is what n-tier supply chain mapping is supposed to do, and most teams know it in theory. Few have built it, because sub-tier visibility has traditionally meant chasing subcontractor disclosures through procurement questionnaires, and vendors have every incentive to answer those vaguely.

What the blind spot costs when it goes wrong

The cost shows up in a few predictable places, and none of them are hypothetical for anyone who's run a category through a real disruption.

There's the scramble cost. When a typhoon hits a port catchment or an industrial park loses power, the first 48 hours go to figuring out who's affected. Fixing anything comes after. If tier 2 exposure isn't mapped already, that discovery work happens live, during the disruption, instead of beforehand.

There's the false-diversification cost. Spend gets split across multiple tier 1 contracts specifically to manage risk, and that diversification gets reported up the chain as a win. If the tier 2 or tier 3 base underneath those contracts is actually concentrated in one location, that report is wrong, and whoever signed off on "low single-region exposure" inherited risk nobody told them about.

And there's the renegotiation cost. Once a cluster becomes visible to the market, after an outage, after a flood, after the port backs up, suppliers sitting in it have far less room to push back in the next sourcing round, because the buyer now knows there was no real alternative all along. Finding this out before the disruption rather than after is the difference between a negotiating position and a recovery plan.

Tier 2 risk is a geography problem

Most attempts at sub-tier visibility try to solve this with more disclosure: longer supplier questionnaires, deeper audit requirements, flow-down clauses demanding three tiers of names. That approach runs into the same wall every time. Supplier disclosures list names. They rarely list locations, and a name on a form doesn't show whether two "separate" sub-tier vendors share a building in the same industrial park.

The faster check is geographic. Plot the vendor list you already have, tier 1 and whatever tier 2 names you've collected, against the physical ground they sit on. Overlay flood zones, port catchments, industrial park boundaries. Clusters show up on their own. You don't need a new disclosure program to see that six vendors you'd filed as separate risk lines sit on the same stretch of road.

That's the gap Sourcing Concentration is built for: a concentration map that plots your category spend against its physical footprint once a year, so the industrial park nobody flagged in a questionnaire shows up as a cluster on a plan instead of a surprise during the next disruption.

If your tier 1 list looks diversified and nobody's checked what's underneath it, that's the exposure worth running down first.

← Back to the blog