Demystifying Supply Chain Risk Assessment
As artificial intelligence systems become increasingly embedded in global supply chains and regulatory frameworks evolve to address emerging risks, organizations face unprecedented challenges in conducting comprehensive due diligence. In this paper, we present the MITRE System of Trust™( SoT™) framework as a structured methodology for supply chain risk assessment and explain its architecture, practical applications, and alignment with emerging regulatory requirements.
This paper provides a comprehensive mapping of SoT risk categories, factors, and measures to the European Union’ s Artificial Intelligence Act and Ecodesign for Sustainable Products Regulation( ESPR), demonstrating how this question-based framework serves as a foundation for compliance with modern supply chain governance requirements. We also highlight natural alignments between SoT and standards from the Object Management Group( OMG) and the Digital Twin Consortium( DTC), which together enable organizations to build adaptive, riskresilient supply networks grounded in trustworthy data and end-to-end traceability. Through detailed analysis and concrete examples, we illustrate how SoT’ s 700 + risk factors and 2,200 + risk measures provide a systematic approach to identifying, evaluating, and documenting supply chain risks across supplier, supply, and service domains.
1 INTRODUCTION
Modern organizations operate within increasingly complex and interconnected supply chains, where risks cascade across multiple tiers of suppliers, component manufacturers, and service providers. The 2020 SolarWinds compromise demonstrated how a single third-party vendor vulnerability could compromise thousands of organizations globally, including government agencies and Fortune 500 companies [ 1 ]. Similarly, the COVID-19 pandemic exposed critical dependencies on geographically concentrated supply chains, resulting in widespread shortages of essential goods and semiconductor components.
Concurrent with these supply chain vulnerabilities, two parallel transformations are reshaping the governance landscape. The European Union’ s Artificial Intelligence Act( EU AI Act), which entered into force on August 1, 2024, establishes comprehensive requirements for AI system providers and deployers, with particular emphasis on supply chain due diligence [ 2 ]. Obligations for General Purpose AI( GPAI) models took effect on August 2, 2025. The full high-risk AI system requirements were originally set to apply from August 2, 2026, though the European Commission’ s proposed Digital Omnibus on AI( November 2025) seeks to extend those deadlines, with proposed backstop dates of December 2, 2027 for Annex III systems and August 2, 2028 for product-embedded systems, pending final adoption [ 7 ]. The substantive obligations are unchanged by the Omnibus; only enforcement timelines are proposed to shift. The Ecodesign for Sustainable Products Regulation( ESPR), effective July 18, 2024, mandates detailed product lifecycle information through Digital Product Passports( DPPs), creating unprecedented transparency requirements across supply chains touching the EU [ 3 ].
EDM Association – Journal of Innovation 79