Demystifying Supply Chain Risk Assessment
In the sections that follow, we describe the SoT framework’ s architecture and methodology, explain how it aligns with the EU AI Act and ESPR, demonstrate its relevance to digital twin data quality, and offer guidance on implementation. We offer this not as a theoretical survey but as a practitioner’ s account grounded in decades of supply chain security work with government and industry stakeholders.
This paper applies SoT through three connected lenses. AI governance concerns the policies, evidence, and decision rights needed to manage AI-enabled suppliers and systems. Digital twin enablement concerns the trusted provenance, data quality, and interface evidence needed for product and supply chain twins to be reliable. Regulatory compliance concerns converting obligations such as the EU AI Act and ESPR into auditable supplier questions, evidence requests, and remediation actions. Sections 3 and 4 show how the same SoT question library supports all three lenses rather than treating them as separate independent efforts.
2 UNDERSTANDING THE SYSTEM OF TRUST FRAMEWORK
FRAMEWORK ARCHITECTURE
The System of Trust framework is a comprehensive library of supply chain risk assessment questions developed by MITRE Corporation based on decades of supply chain security research and collaboration with government and industry stakeholders [ 4 ]. Unlike automated assessment tools or scoring systems, SoT functions as a reference framework. It is a structured knowledge base from which organizations select relevant questions based on their specific context, industry, and risk priorities [ 5 ].
The framework employs a hierarchical structure organized across three primary domains: SoT™ Three Primary Risk Domains
Supplier Risks( RC-1): Factors related to the organizations providing products or services, including their financial stability, organizational security posture, susceptibility to external influences, quality culture, and ethical practices.
Supply Risks( RC-2): Concerns regarding the physical products or components themselves, encompassing malicious taint, counterfeit risks, hygiene issues, and availability considerations.
Service Risks( RC-3): Factors specific to service delivery, including service quality, resilience, security, and integrity.
For clarity throughout this paper, RC refers to a Risk Category and RF refers to a Risk Factor within the SoT Body of Knowledge( BoK).
Within these three domains, SoT identifies 15 top-level risk areas as shown in figure 1.
80