Supply Chain Intro and Table of Contents Supply Chain August 2026 | страница 97

Demystifying Supply Chain Risk Assessment
Cross-border regulatory harmonization presents a third research direction. As multiple jurisdictions develop supply chain risk regulations, opportunities exist for mapping SoT to diverse frameworks. Beyond the EU AI Act and ESPR, future work might address alignment with NIST Cybersecurity Supply Chain Risk Management practices and emerging regulations in other regions. We believe SoT’ s design, which builds from both the ground up and the top down simultaneously [ 18 ], positions it well to serve as a universal framework adaptable to multiple compliance contexts without requiring parallel development efforts.
Relevant complementary frameworks include the NIST AI Risk Management Framework( AI RMF) and NIST SP 800-161 Cybersecurity Supply Chain Risk Management guidance. These frameworks provide governance, measurement, and supply-chain-oriented controls that align naturally with SoT’ s structured assessment methodology and catalog of risks.
8 LIMITATIONS
This paper is intended primarily as a practitioner-oriented framework and integration discussion rather than a formal empirical validation study. While the paper describes representative deployment patterns and governance outcomes, additional longitudinal research and independent benchmarking would strengthen understanding of SoT effectiveness across industries and regulatory environments.
9 CONCLUSION
The MITRE System of Trust framework addresses a fundamental challenge facing modern organizations: how to conduct comprehensive, systematic supply chain due diligence in an era of increasing complexity and regulatory scrutiny. SoT’ s structured reference library encompasses 2,200 + established risk measures and a growing set of AI-specific categories in BoK v1.5, organized into a hierarchical framework that spans supplier, supply, and service risk domains in a way that is both comprehensive and practically navigable.
In this paper, we have demonstrated SoT’ s practical utility through two intersecting lenses. The first is regulatory mapping. The framework’ s risk categories align directly with EU AI Act obligations for value chain due diligence, data governance, and cybersecurity assessment. SoT’ s supply domain questions address ESPR Digital Product Passport requirements for material composition, manufacturing traceability, and product lifecycle data. The second is alignment with digital twin and modeling standards. SoT assessments provide the trust foundations that DTSIF-structured supply chain digital twins require. OMG’ s SysML and SACM standards provide the formal modeling and assurance structures through which SoT evidence can be organized and presented to regulators.
The worked example presented in Section 5 further demonstrates how SoT assessments can support measurable governance outputs including risk scorecards, evidence requests, remediation tracking, and auditable approval decisions. Organizations need not implement all
EDM Association – Journal of Innovation 93