Supply Chain Intro and Table of Contents Supply Chain August 2026 | Page 87

Demystifying Supply Chain Risk Assessment
example of such an implementation approach is provided in the“ Practical Example: Applying SoT to an AI Supply Chain Supplier” part of Section 5.
POSITIONING SOT RELATIVE TO OTHER FRAMEWORKS
Several other approaches address adjacent parts of this problem. The NIST AI Risk Management Framework and ISO / IEC 42001 frame AI risk governance and AI management systems [ 10 ], [ 11 ]. NIST SP 800-161r1-upd1 and the Secure Software Development Framework address cybersecurity supply chain risk management and secure software acquisition [ 12 ], [ 13 ]. OMG SysML and SACM support formal system models and auditable assurance evidence [ 14 ], [ 15 ]. SoT complements these approaches by translating higher-level governance, security, and assurance objectives into reusable supplier-, supply-, and service-facing questions.
Approach What it contributes How SoT complements it
NIST AI RMF [ 11 ]
ISO / IEC 42001 [ 12 ]
NIST SP 800-161r1-upd1 [ 13 ]
NIST SSDF [ 14 ]
OMG SysML / SACM [ 15 ], [ 16 ]
AI risk functions for govern, map, measure, and manage.
Management-system requirements for organizations developing, providing, or using AI.
C-SCRM strategy, policies, plans, controls, and product / service risk assessment.
Secure software development practices and acquisition vocabulary.
Formal system models and auditable claims, arguments, and evidence.
Converts governance intent into supplier-facing questions, evidence requests, and remediation actions for AI components and services.
Adds supply-chain due-diligence detail for assessing whether suppliers can support AI management-system objectives.
Provides a granular question library across supplier, supply, and service domains to instantiate assessments.
Extends software assurance into SBOM, AI-BOM, provenance, pedigree, and AI component trust questions.
Produces evidence objects that can populate assurance cases and digital twin data-quality records.
The resulting relationship is complementary rather than competitive: SoT does not replace AI governance frameworks, C-SCRM controls, software security practices, or digital twin interoperability standards. Its distinctive contribution is operational. It translates higher-level obligations into supplier, supply, and service questions that produce evidence artifacts suitable for procurement, audit, assurance cases, and digital twin data pipelines.
3 THE REGULATORY IMPERATIVE: AI GOVERNANCE, DIGITAL TWINS, AND SUPPLY CHAIN TRANSPARENCY
With the framework’ s architecture and methodology established, we turn to the regulatory environment driving adoption. Two major regulatory instruments, the EU AI Act and the ESPR, create specific supply chain due diligence obligations that SoT is well positioned to address. We examine each in turn, then address the cyber-resilience requirements that integrated digital supply chains introduce.
EDM Association – Journal of Innovation 83