Supply Chain Intro and Table of Contents Supply Chain August 2026 | Seite 98

Demystifying Supply Chain Risk Assessment
2,200 + risk measures uniformly. SoT enables risk-based assessment approaches, applying 50 questions to low-risk vendors while deploying 200 + measures to strategic suppliers of critical components or high-risk AI systems. Regulatory frameworks will continue evolving. ESPR’ s phased implementation extends through 2029, and AI governance requirements are proliferating globally. Organizations with SoT implementations can map new obligations to existing risk categories rather than developing entirely new assessment frameworks from scratch.
The framework’ s ongoing development signals that SoT is evolving in step with the regulatory and technological landscape it supports. BoK v1.5’ s dedicated categories for AI Model Integrity( RC-695), AI Infrastructure Security( RC-696), and AI Governance and Compliance( RC-698) are the most recent evidence of this. As AI systems become simultaneously the subject of supply chain risk regulation and tools for conducting supply chain risk assessment, we believe frameworks that address both dimensions within a unified methodology may become increasingly important. As the comparison above suggests, SoT ' s contribution is not to replace NIST, ISO, OMG, or DTC approaches, but to make their high-level obligations operational at the supplier and evidence-collection layer. Ultimately, SoT supports a transition from subjective judgment toward more systematic supply chain due diligence methodologies. It enables organizations to build the evidence-based, audit-ready, and continuously adaptable supply chain governance that regulators, trading partners, and digital twin platforms increasingly demand.
REFERENCES
94
Note: Generative AI tools( LLMs) were used to support preliminary information gathering and synthesis; all substantive analysis, validation, and conclusions were performed by the author( s).
[ 1 ] Cybersecurity and Infrastructure Security Agency( CISA).( 2021). SolarWinds and Active Directory / M365 Compromise. https:// www. cisa. gov / news-events / cybersecurityadvisories / aa20-352a
[ 2 ] European Parliament and Council.( 2024). Regulation( EU) 2024 / 1689 on Artificial Intelligence( AI Act). https:// eur-lex. europa. eu / eli / reg / 2024 / 1689 / oj
[ 3 ] European Parliament and Council.( 2024). Regulation( EU) 2024 / 1781 on Ecodesign for Sustainable Products. https:// eur-lex. europa. eu / eli / reg / 2024 / 1781 / oj
[ 4 ] MITRE Corporation.( 2020). System of Trust Framework. https:// sot. mitre. org / framework / system _ of _ trust. html
[ 5 ] MITRE Corporation.( 2026). System of Trust Body of Knowledge version 1.5. linked from https:// sot. mitre. org /
[ 6 ] MITRE Corporation.( 2024). AI Assurance: A Repeatable Process for Assuring AI-enabled Systems. https:// www. mitre. org / news-insights / publication / ai-assurance-repeatableprocess-assuring-ai-enabled-systems