In short: Dual sourcing at tier one stops being diversification when both suppliers buy the same input from the same sub-tier plant, and every tier one measurement is blind to that concentration. A usable map can be built without full disclosure, drawing on correlation analysis of past disruptions, customs and shipment records, component level bills of material, and targeted questions on the few parts that matter. Entity resolution is the hard technical part, since the same plant appears under several names, addresses and legal entities across sources, and an unresolved duplicate hides exactly the concentration you are looking for. Knowing about a dependency does not remove it, so what happens to a finding should be settled before the mapping starts.
Your tier one scorecards are green. Financial health good, delivery performance strong, no quality issues, dual-sourced on everything critical.
Then a plant you have never heard of, in a country you do not buy from directly, stops producing, and eleven of your suppliers tell you the same week that they cannot deliver. They were all buying the same component from that plant, and none of them mentioned it because none of them was asked.
The concentration was never at your tier. It was two levels down, and every measurement you had was blind to it.
Why dual-sourcing at tier one is not diversification
The assumption behind dual-sourcing is that two suppliers fail independently. That assumption breaks whenever both suppliers depend on the same thing upstream.
The canonical documented case is still the best illustration. In March 2000 a lightning strike started a small fire at a Philips semiconductor plant in Albuquerque. Two of the customers affected were Ericsson and Nokia, competitors sourcing from a common upstream plant, and Norrman and Jansson wrote the episode up in 2004 in the International Journal of Physical Distribution and Logistics Management as the trigger for Ericsson's rebuild of its supply chain risk practice. The fire itself was contained in minutes. The consequences were measured in hundreds of millions and in market share, and the concentration that caused them was invisible from the tier one scorecards on both sides.
Put numbers on the assumption and the size of the error becomes obvious. Suppose each of your two qualified suppliers has a three percent chance in any year of failing to deliver. If they really are independent, both failing together is three percent times three percent, which is nine in ten thousand, or roughly once a millennium. That is the figure implicitly underwriting most dual-sourcing decisions.
Now suppose two of those three points come from a shared sub-tier plant and only one point is specific to each supplier. Both fail together whenever the shared plant goes down, which is two percent, plus the vanishing case where both suffer their own independent failure, which is one percent times one percent, or one in ten thousand. The joint failure rate is about two point zero one percent, more than twenty times the nine in ten thousand you thought you had bought.
Look at what the dual-sourcing actually purchased. Exposure went from three percent to just over two, a reduction of about a third, against a reduction of ninety-seven percent that everyone in the approval chain believed they were getting. The arrangement was worth having and it was worth roughly a thirtieth of its assumed value, and no scorecard anywhere in the process would have shown the difference.
Common upstream dependencies are more prevalent than most procurement organisations expect, for reasons that are structural rather than accidental. Specialist processes concentrate: there may be only a handful of plants worldwide producing a particular grade of material or performing a specific treatment. Cost pressure at your tier one pushes them toward the same low-cost source you would have chosen. And qualification burden means that once a sub-tier supplier is approved by a customer, every supplier serving that customer tends to use them.
The result is that a supply base that looks diversified on paper converges to a small number of nodes at tier two or three, and the convergence is invisible from where you sit.
Getting the map without full disclosure
The obvious answer is to ask your suppliers for their supply chains, and it works partially. Suppliers treat their sourcing as commercially sensitive, and reasonably so, since disclosing it invites you to go direct.
Four practical routes, usually combined.
Ask, but scope it. Full bill of materials disclosure will be refused. Asking specifically about single-source dependencies for the components you buy, without requiring names, gets a better response rate. A supplier will often confirm that a component is sole-sourced even when they will not say from whom, and that alone tells you where to look.
Use qualification records. In regulated and safety-critical industries, sub-tier suppliers are named in approval documentation for reasons unconnected to procurement. That documentation is a map somebody has already built.
Infer from the component itself. For specialist materials and processes, the set of plants capable of producing them is small and often publicly known. If you buy a component requiring a specific process, the sub-tier is constrained regardless of who your tier one is, and you can establish the concentration without any disclosure at all.
Watch the correlation. When two nominally independent suppliers experience the same disruption at the same time, they share something. Recording those coincidences over time builds a dependency map from behaviour rather than from documents, and it is the one method that requires no cooperation whatsoever.
That last one is worth making precise, because it is the cheapest analysis in this entire piece and almost nobody runs it. Build a table of suppliers by month for the last three years, with a flag for any month in which a supplier missed a commitment materially. Then compare observed co-occurrence against what independence would predict. Supplier X flagged in six of thirty-six months runs at seventeen percent. Supplier Y flagged in four of thirty-six runs at eleven percent. If they are independent, the expected number of months where both are flagged is seventeen percent times eleven percent times thirty-six, which is about two thirds of a month. Observe three such months and you are looking at four and a half times the independent rate.
That is not proof of a shared dependency, and it is a very strong reason to ask the question. Sort every pair in your supply base by the ratio of observed to expected co-occurrence, take the top twenty, and you have a list of specific pairs to investigate with data you already hold in your delivery performance records. The analysis takes a day and it needs nothing from anyone outside your own business.
The entity resolution problem
Whichever routes you use, the data arrives as names, and names are a mess.
The same company appears as three different legal entities, with and without suffixes, transliterated differently, at addresses that changed. Two genuinely different companies share a similar name. A subsidiary appears under both its own name and its parent's.
Until this is resolved, the concentration analysis cannot work, because the whole point is counting how many of your suppliers depend on the same upstream entity, and if that entity appears under four spellings the count is four ones rather than one four.
String similarity matching gets you most of the way, using a measure that weights common prefixes, since corporate names diverge at the end more than at the start. The Jaro-Winkler measure, published by Winkler in 1990 for exactly this problem in census record linkage, has that prefix weighting built into it and is the sensible default for company names. Address and registration-number matching resolves the rest. Expect to review the borderline cases by hand, and expect that step to be the bulk of the effort.
There is a symptom that tells you the resolution has failed, and it is easy to miss because it looks like good news. If your concentration report comes back showing that almost every sub-tier node serves exactly one of your suppliers, with no node serving three or four, the honest reading is that the matching did not work. Real supply bases are lumpy: a handful of nodes carry a disproportionate share and a long tail carries the rest. A flat distribution is the signature of one entity counted under several spellings, and the report is showing you a diversified supply base that does not exist. Check the flatness before you circulate the finding, because a concentration analysis that finds no concentration is the one result nobody questions.
This is unglamorous and it is the actual work. A sub-tier programme that produces a beautiful network diagram from unresolved entities is producing a picture of its own data quality.
Reading the map
Once you have a graph of suppliers, components and products, three analyses are worth running and each answers a different question.
Where used. For a given sub-tier supplier, which of your products depend on them, traced up through the components and the bill of materials. This is the exposure calculation and it is the one that turns an abstract dependency into a revenue number.
Concentration. For each sub-tier node, how many of your tier one suppliers depend on it. Nodes with high counts are where your apparent diversification collapses, and they are the priority for the qualification programme.
Path enumeration. For a given component, all the routes it could reach you by, with the lead time along each. This tells you whether an alternate exists in principle and how long the alternate path takes, which is different from whether the alternate is qualified.
The third one produces the most surprising results, because the shortest path is frequently not the one currently in use, and the reason is usually historical rather than economic.
What to do with a concentration you cannot remove
Sometimes the answer is that there is genuinely only one source, and no amount of qualification effort changes that. Specialist capacity takes years to build and some of it is not going to be built.
Three responses that do not require an alternate.
Hold more. Inventory is the crude answer and it is the one that works when nothing else does. Size the buffer against the realistic recovery time rather than against demand variability, since this is a different risk with a different shape.
The two calculations give answers of completely different magnitudes and it is worth seeing them side by side once. An item consuming 800 units a week with a weekly standard deviation of 150 and an eight week lead time carries a service buffer somewhere around 700 units at a normal target. Now ask what a fourteen week recovery from a sub-tier plant failure requires, and the answer is fourteen times 800, which is 11,200 units, roughly sixteen times the service buffer. Those are answers to different questions and the second one does not come out of any safety stock formula, because the driver is duration of loss rather than variability of demand. Deciding to hold some fraction of that 11,200 is a capital decision for the business to take with the number in front of it, and the useful contribution from planning is to produce the number rather than to bury the exposure inside a service level.
Contract for priority. A commitment to allocation in a shortage is worth negotiating before there is a shortage, and it is nearly impossible to obtain during one. This costs something in normal times and that is what it is buying.
Design it out. The durable fix for a sole-source dependency is frequently an engineering change rather than a procurement one, and it needs a long runway. Feeding the concentration map into design review is how a sub-tier programme produces value beyond monitoring.
The limits
Sub-tier mapping decays. Suppliers change their sourcing without telling you, and a map built two years ago describes a supply chain that has moved. Refresh cadence is a real cost and the mapping should be scoped to the exposures that justify it rather than attempted across the whole base.
Depth has diminishing returns. Tier two is usually where most of the recoverable insight sits. Tier three adds meaningfully in some industries and in most it adds effort faster than information. Going deeper because it is possible rather than because a specific exposure warrants it is a common way for these programmes to consume a lot of budget and produce a diagram.
There is also a limit that no mapping addresses. Knowing about a dependency does not remove it, and a programme that maps thoroughly without a linked qualification or design effort has bought awareness of a problem it has not resourced anyone to fix. Deciding what happens to the findings should be settled before the mapping starts, not after the first alarming result.
Start with the correlation analysis on past disruptions. It costs nothing, it requires no supplier cooperation, and it will point at the shared dependencies you already have evidence for.