
Dependency concentrates one level below the relationships most supply chain programs monitor.
That is the whole argument, and everything below is how to act on it. A large organization already knows its tier one suppliers in detail, with scorecards, quarterly reviews, audit histories, negotiated terms, and named relationship owners. That work is real and it is the foundation this builds on. The next level down is where it compounds.
Why does tier one visibility miss the exposure?
Because a dozen tier one suppliers present as a dozen separate relationships, and the dependency they share is invisible at that level. Mapped one level further, those same suppliers may resolve into a single tier two producer, or a single packaging substrate from one region, which is a dependency with a size, a location, and a name.
This is the shape of the exposures boards ask about after the fact. The disruption is rarely exotic and the supplier is rarely obscure. What separates the organizations that handled it well is that they already knew several relationships converged on one point, and they knew it because the network had been resolved deep enough to hold that connection.
Step 1: Resolve the entities before mapping anything
The same producer appears in procurement under a trading name, in the vendor master under a legal name with a suffix, in the quality system under a plant designation, in logistics under a shipping code, and in an external risk feed under a registered entity name. Five sources describing one company, and nothing in the estate states that they are one.
Resolution establishes that first, across suppliers, sites, parts, purchase orders, shipments, and lanes, with a confidence value on every match. Skip this step and every count downstream is wrong: the concentration analysis double counts, the spend rollup understates, and the alternative sourcing options include a supplier you already depend on under a different name.
Step 2: Assemble the map from four sources, not one
No single source describes the layer below tier one completely. Four contribute, and each covers something the others miss.
Declared
What suppliers state in procurement platforms and questionnaires. Direct and specific, and dependent on the supplier both knowing and being willing to say.
Implied
What product and bill of material structure implies about who must be upstream. Strong for engineered products, weaker where components are commoditized.
Observed
What commercial multi-tier risk services observe across their own coverage. Broad, and uneven by region and sector.
Established
What trade and shipment records establish about goods actually moving. The hardest of the four to dispute, and blind to anything that does not cross a border or move physically.
Where they agree, the picture is strong. Where they disagree, the disagreement is information about which part of the map to establish next.
Step 3: Score the map at the attribute, never at the supplier
This matters more here than almost anywhere else on a supply chain program, because the parts of a supplier picture vary enormously in quality.
Spend may be reliable enough to negotiate on this quarter. Contract terms may be the strongest part of the picture. Sites and country of origin may be solid and corroborated across systems. Declared sub-tier sourcing may be the weakest thing on the page and the attribute most worth establishing next.
Held per attribute, each of those is available for exactly the decisions it can carry. Held as one supplier score, the strong parts get dragged down by the weak ones or the weak parts disappear inside an average, and in both cases a planner loses the detail that would have told them where to commit.
Step 4: Quantify the concentration three ways
Once the network is resolved and scored, concentration is measurable by producer, by region, and by substrate. Those are three different exposures and they call for three different responses.
A producer concentration is addressed by qualifying an alternative supplier. A regional concentration is addressed by qualifying an alternative geography, which takes longer and costs more. A substrate concentration may not be addressable at all in the short term, which is worth knowing before a disruption rather than during one.
Step 5: Connect external signal to internal position
Ingesting external signal is the straightforward half. Weather, port congestion, carrier events, trade restrictions, and supplier distress are all available on subscription.
The valuable half is holding that signal against the specific suppliers, parts, open orders, and inventory positions it concerns, so a change outside arrives already attached to the orders it affects. That converts an alert into a set of options with availability and lead times, each carrying its own confidence, which is the form a team can act on at two in the morning.
What does the finished map change?
It moves a risk register from describing your contracts to describing your dependency.
Those are different documents. A contract register tells you who you have agreements with. A dependency map tells you what stops if a single point fails, which is the question every post-disruption review actually asks. Planning also improves for a quieter reason: buffers sized against how suppliers actually perform, rather than against how they were expected to perform, tend to earn their keep.
See the whole chain
The PolyPhaze white paper See The Chain covers the three agent layers, how alternative sourcing produces options rather than alarms, and how industry packs carry sector semantics. Download the full sub-tier supply chain mapping ebook for the complete approach.
Frequently asked questions
What is sub-tier supplier mapping?
Sub-tier supplier mapping establishes who your suppliers buy from, one or more levels below your direct relationships. It converts a set of separate tier one relationships into a quantified dependency on the shared producers, regions, or substrates that sit underneath them.
Where does sub-tier supply chain data come from?
Four sources, each partial: what suppliers declare in procurement platforms, what bill of material structure implies, what commercial multi-tier risk services observe, and what trade and shipment records establish. A usable map states how strongly each part of it is supported.
Why score supply chain data per attribute rather than per supplier?
Because the parts of a supplier record differ sharply in quality. Spend and contract terms are often well corroborated while declared sub-tier sourcing is thin. One score for the supplier hides that difference, and hiding it is what leads teams to commit against the weakest part of the picture.