Ask most operations teams where their supply chain is most exposed, and you'll get a confident answer about the obvious risk: the single-source component, the one high-volume lane, the supplier everyone already worries about. Those risks are real, but they're also the ones already being watched. The damage more often comes from the risk nobody flagged, because it never looked urgent enough to review.

A resilience audit that only checks the known risks is really just a status update. A more useful version starts by asking a different question at every node: not "is this working right now," but "what would have to go wrong here for us not to notice until it was too late." That reframing surfaces a different list: the report that's manually reconciled once a month, the backup supplier who was qualified two years ago and never re-checked, the lead-time assumption baked into a planning model that hasn't been tested against a real disruption.

The output of a good audit isn't a heat map for its own sake. It's a short, ranked list of specific, actionable fixes: re-qualify this backup supplier this quarter, automate that manual reconciliation, stress-test this lead-time assumption against a real scenario. Resilience isn't built by eliminating risk; that's not possible in a live supply chain. It's built by shortening the time between something going wrong and someone noticing.

See how this works as an advisory engagement