Insights · Model behaviour
The tier-2 question: why model a supplier you don't buy from?
Upstream risk doesn't travel down the chain the way the diagram suggests. Three things decide whether it reaches you, and none of them is how far away it happened.
Draw a supply chain and it looks like plumbing. The mine feeds the parts maker, the parts maker feeds you. One pipe. So if the mine floods, the parts maker stops, and you stop, which means the risk number sitting on your parts maker already has the mine baked into it.
Why bother modelling the mine at all?
It's a fair question, and the answer is worth real money.
The intuition assumes something that usually isn't true
The argument only works if trouble upstream always becomes trouble at your door. Sometimes it does. Most of the time it doesn't, because there is stock sitting in between.
If your parts maker holds thirty days of that raw material and the mine is back in three weeks, nothing reaches you. Nothing at all. The disruption was real, it was upstream, and it cost you zero.
Now turn it around. Your parts maker has a fire. The mine is running perfectly. You stop anyway.
Two suppliers, two entirely separate sets of reasons to fail. Neither one is a copy of the other, and neither one's number can stand in for the other's.
Three things decide whether upstream trouble reaches you
Not how many steps up the chain it happened. These:
- Stock on hand. How long you keep running after a supplier stops. Short outages die here and never reach you.
- A second source. Whether anyone else can supply the same thing, and how fast you can switch. This caps your exposure no matter how long the original outage drags on.
- Time to get going again. Supply comes back, but your line doesn't hit full rate the same morning. Those days cost you too, and you only pay them if the disruption got past your stock in the first place.
The smallest test there is
One supplier. One supplier behind it. A $5bn company. We simulated 200,000 years and asked what a bad year looks like: the loss you'd want capital ready for.
Then we changed exactly one thing: took away the upstream supplier's twenty days of stock. Ran it again.
| Upstream stock | Bad-year loss | Direct supplier's share |
|---|---|---|
| 20 days | $83.2M | $28.4M |
| None | $89.5M | $28.4M |
Your direct supplier's number doesn't move by a cent. Nothing about its risk changed. The entire $6.3M sits on the upstream supplier, because that's whose risk it actually is.
And the original question. Does your direct supplier having a bad year tell you the one behind it did too? It doesn't:
Knowing one had a bad year tells you essentially nothing about the other. If upstream risk were quietly folded into your tier-1 number, that second figure would run toward 100%. It doesn't move at all.
What if you never map tier 2 at all?
That's the honest baseline for most companies. Tier 1 is on the map because you have contracts with them. Whoever stands behind them often isn't on the map at all.
So we ran the same network again with the tier-2 supplier simply deleted.
The bad-year figure falls from $83.2M to $65.8M, about a fifth. The average year falls further, from $40.4M to $28.4M.
Now look at what didn't change. The tier-1 supplier's own figure is $28.4M either way, to the cent. This isn't a distortion, it's an omission. You get a complete number for the supplier you mapped and a silent zero for the one you didn't. The mine still floods at the same rate. You just stopped counting it.
The natural correction is to leave tier 2 off the map but make tier 1 carry its weight: add the two criticalities together and put the total on the supplier you do know about. That lands at $105.2M, a quarter too high. You miss in the other direction instead of landing.
Two separate things go wrong. The first is that two suppliers don't add up. When both are down in the same week your line stops once, not twice. Squashing them into a single supplier forces their bad weeks to coincide every time, which is the worst case rather than the usual one. That alone puts you about 11% high, and no choice of inputs removes it.
The second is that one supplier can only hold one level of stock. The real pair had five days behind one and twenty behind the other. Whichever you pick is wrong for the other, and that swings the answer by another fifteen points.
A tier-2 supplier isn't a bigger number for your tier-1 supplier. It's a separate clock with its own stock behind it, and nothing you do to tier 1's inputs will reproduce it.
A third supplier doesn't change the shape
Add another direct supplier, this one with a qualified backup vendor, and nothing about the logic changes. Each supplier still shows up once, on its own terms.
Two things stand out. Removing the upstream stock costs about the same $6M whether the network has two suppliers or three. That lever only ever touches the supplier it belongs to. And taking the backup away from the new supplier costs $39M, six times more.
That is the whole argument for modelling more than one tier. Not to count a single failure twice, but to know which of these two cheques is worth writing.
But does the model match reality?
This is the part that matters, and it's the part most models skip. A model that reacts to its inputs is not the same as a model that's right.
So we built a second simulation that shares no code with the first: a plain day-by-day calendar of the actual chain. Mark every day the parts maker is down for its own reasons. Mark every day it's down because the mine ran dry and the stock was gone. Count the days of output you really lost. That's the physical answer, with no model in the way.
Then we ran the model against it, sliding the stock level from zero to ninety days.
The model tracks. Both fall as stock rises, and they bend in the same place. Past thirty days of stock the mine can no longer reach you at all, and the real chain goes flat.
The model doesn't quite go flat, and it runs 9% to 39% high. We know exactly why. It subtracts your stock once a year, from the total days the supplier was down, instead of once per disruption. A year with two separate thirty-day outages against thirty days of stock should cost you nothing at all. The model sees sixty days of outage, subtracts thirty days of stock, and charges you for thirty.
That's a model assumption and you should know about it. It also errs in the safe direction: it over-states, never under-states. For a number whose job is to tell you how much capital to hold, that is the right way to be wrong. It bites hardest when your stock runs about as long as a typical outage.
The field most people leave blank
Everything above turns on one input, and it's the one most people skip: how much of your output actually stops when this supplier stops.
Leave it blank and the model prices that supplier on how much you spend with it. That sounds reasonable. It is quietly false, because it assumes a supplier can only cost you its share of your purchasing, which is wrong for every bottleneck ever recorded.
Take two suppliers. A specialty seal maker: half a percent of what you buy, sole source, and every unit you build needs the seal. And a large components supplier: twenty percent of what you buy, with alternatives on the market.
Priced on spend, the seal maker is a rounding error: $0.7M a year against the big supplier's $27M. Tell the model what each one actually stops and the ranking inverts: the seal maker carries $111M, twelve times the big supplier.
Its number moved 165-fold. Not because the model turned pessimistic, but because it was finally told the one thing that mattered.
That figure is yours to supply and yours to defend. What share of output really stops? How many days of stock stand behind it? Could you re-source, and how fast? Nobody can look those up for you, and no default can guess them. But they are the difference between a risk number that ranks your suppliers by invoice size and one that ranks them by what they can actually do to you.
Leave them blank and the model falls back on a flat discount by depth, tier 2 at 60% and tier 3 at 30%, roughly the same as assuming every supplier everywhere sits behind about a week of stock. For ranking a hundred companies off public filings, where nobody discloses their buffer stock, that's a defensible average. It is what the SciRisk 100 does, and why its figures are for screening rather than for deciding where your own money goes. For your own network, you can do much better than an average.
Try it on yours
Build the network you actually have, and for each supplier fill in the four fields underneath the basics:
- Criticality
- the share of your output that stops when they stop
- Unrecoverable
- how much of that output you never make up
- Buffer days
- how long you keep running after they stop
- Workaround days
- how fast you could switch, if you could at all
Two tests worth running the moment you have it built.
Find your most critical supplier and set its buffer to zero. That is the number you are carrying today if the stock you think you have turns out not to be there.
Then sort your suppliers by what the model says they cost you, and compare that against the list sorted by spend. If those two lists are in the same order, you haven't filled in the criticality yet, because in a real network they never are.
The takeaway
Your upstream supplier isn't your direct supplier's shadow. It fails for its own reasons, on its own schedule, and whether that reaches you comes down to stock, alternatives and restart time: the same three things that govern every other supplier you have, at any depth.
None of which the model can work out on its own. It knows how disruptions behave; only you know what your suppliers actually hold up. Give it that and it will tell you which supplier can stop you. Skip it and you'll spend your resilience budget strengthening the one that was never the problem.
Put your own tier-2 suppliers in front of the engine
Every figure above came from the production ESCRC engine on a two-supplier worked example. Build the network you actually have, fill in criticality and buffer days, and run the same two tests on it.
SciRisk ESCRC is an analytical estimate. It is not a credit rating, investment recommendation or statement of financial condition.