Demystifying Supply Chain Risk Assessment
Integration with existing systems requires thoughtful planning rather than wholesale replacement. Most organizations have established vendor management systems and procurement workflows. In practice, the most effective approach maps SoT questions to existing assessment categories, supplementing current questionnaires with SoT measures that address identified gaps. In digital twin environments, SoT data collection should be designed as a structured feed into the twin’ s data model from the outset, using OMG-standard APIs and interchange formats to ensure interoperability as the system scales.
Scoring and interpretation require upfront investment because while SoT provides a default scoring and weighting approach, that approach involves and recommends contextual tailoring for organizational priorities and risk thresholds. In addition, SoT does not enforce the default as the only viable approach, and integration with existing organizational systems and processes may require something slightly different from the default. We recommend starting with simple binary scoring before developing more nuanced weighted systems as expertise develops. In AIassisted deployments, SoT’ s structured output provides a well-defined training signal for machine learning models. Those models must, however, themselves be assessed using SoT’ s RC-695 and RC-698 categories before deployment in any due diligence workflow.
7 FUTURE DIRECTIONS AND RESEARCH OPPORTUNITIES
We believe the work described here represents the current state of a rapidly evolving area. Several research directions hold promise for extending SoT’ s reach and utility.
Automation and AI integration is the most immediate frontier. Future research might explore how AI systems can assist with SoT implementation by automatically suggesting relevant questions based on supplier characteristics, analyzing response patterns to identify inconsistencies, or correlating assessment results with subsequent supplier incidents. BoK version 1.5 addresses the reciprocal question: how SoT can assess the AI systems used for this purpose [ 5 ]. The RC-695 and RC-696 categories provide a self-referential capability. Organizations can use these risk factors to evaluate AI-powered procurement or assessment tools before deploying them in due diligence workflows. We offer that an AI system automating SoT questionnaire analysis is itself a high-risk AI application in many supply chain contexts, and RF-1344 through RF-1352 provide the measures needed to assess it.
Digital twin and OMG standards integration offers a specific research opportunity at the intersection of SoT and digital twin platforms. Developing reference architectures for SoT-as-a- Service that feed structured risk assessment results into DTC DTSIF-compliant supply chain digital twins in real time would enable continuous, automated compliance monitoring rather than periodic manual assessment. This would transform supply chain governance from an audit function into an operational capability. The DTC’ s use-case library and OMG’ s standards development process provide starting points for formalizing these integrations as standardized reference architectures rather than bespoke implementation guides.
92