Category Archives: Supplier Management

Source-to-Pay+ part 3: Corporate Risk

In Part 1 we noted that Risk Management went much beyond Supplier Risk, and the primitive Supplier “Risk” Management application that is bundled in many S2P suites. Then, in Part 2, we noted that there are risks in every supply chain entity; with the people and materials use; and with the locales they operate in. These risks come in all shapes and sizes. And any single risk can sink the company.

Today we are going to talk about some of the internal corporate risks and outline the function specific baseline capabilities that such a solution will normally possess.

Capability Description
Reputation/Brand A significant risk to a company is its reputation/brand, especially if it’s primarily selling to consumers. And the problem with reputation/brand damage is that it can come from anywhere. Quality issue that leads to a defect that causes consumers harm. Raw materials that are harmful to human health and might cause cancer, or worse, if consumed, inhaled, or even touched. An offensive statement (to a group of people) by an executive. A targeted online misinformation campaign by a disgruntled customer. Environmentalists who claim the organization is doing unnecessary environmental damage. Forced and Slave Labour. The repercussions of continuing to buy cobalt and copper from the congo while turning a blind eye to rampant sexual violence and rape. (An average of 48 victims are treated per day by Medicins Sans Frontieres, that’s 17,520 per year. And this has been going on for over a decade.)

And in these difficult times, you also have to deal with

  • Sourcing from countries engaged in “special military exercises” that have effectively started wars with other countries and
  • Sourcing from countries whose response to terrorist attacks have resulted in 10X the number of casualties caused by the terrorists.

In these two situations, it might be the case that most of your consumer base doesn’t care, but some will praise you while staying the course and helping the side they think is right (or good) while others will go out of their way to aggressively attack your brand for helping the side they think is wrong (or evil). And so on.

As such, the platform needs to be able to monitor news sources and social media. It must look for stories that could blow up, sentiment that could propagate, and events associated with related entities that could propagate. It must tie into multi-tier manufacturing systems and monitor raw materials, quality control systems to monitor production quality, It must tie into CSR/EHG systems to make sure the company is being environmentally conscious. And so on.

Sanctioned Entities An organization that does business with organizations on sanctioned or denied lists can get in serious trouble. It can be prohibited from doing business with government entities, fined, and the executives (criminally) charged. But it’s not just entities, it’s individuals as well. And it’s not just potential employees or contractors, but (potential) investors as well.

Its critical that the system tie into all sanction and denied party lists of every country it does business in, all lists of organizations that have had lawsuits brought against them (and the results if the lawsuits have been concluded), and lists of individuals who have investments in related corporations.

Fraud Every organization that makes money is at risk of being defrauded. That fraud can come from employees, including top executives, suppliers, third parties, and cyber criminals.

Such a system should integrate into the Supplier/Vendor Master and ensure that all invoices are coming from valid entities, the purchase order system to ensure the invoices match purchase orders and the payment amounts are valid, the payment system to make sure the payments go to accounts known to be associated with the vendor who sent the invoice, and no payments made without an invoice or appropriate counter-signed / doubly approved payment approval.

Such a system should also look at connections. Connections between the individuals in the organization who cut the PO, claim the services were delivered, make the payment, and the individuals who sent the invoice, verified the delivery, and accepted the payment.

Such a system should also integrate with the cyber monitoring and internet security systems and look for unusual activity that could indicate potential fraud.

Employees Employees are the biggest internal risks. And not just those who are looking to commit fraud, which will, hopefully, be a very small percentage of employees. There are also those who (might) have a conflict of interest, which could sway them in their decision making. And then there are the rest of the employees, who are human and make mistakes. Small mistakes like accidentally approving an invoice for 5K from a vendor who didn’t actually deliver the services, and might never deliver the services, because there are no processes in place to verify the delivery from approved vendors who have delivered in the past. Big mistakes like not locking down a port that allows a hacker to get into the local payment systems and alter the bank account for the 500K payment going out tomorrow. And everything in between.

This system should not only integrate with background check systems for employees who have access to the payment systems, but those who have access to restricted/classified IP, sensitive systems that need specialized training, and so on.

It should also integrate with certification and training systems to track an employee’s certifications and training.

GHG/Carbon In today’s climate, it’s important for a large company to track it’s internal carbon usage, not just the supply chain.

It’s likely that the organization will have it’s own system for carbon tracking. Such an organization will need to make sure the system is configured to track internal emissions and chain emissions separately, assign internal emissions to the company and the outbound chain as appropriate, and export the summaries to the corporate risk tracking system.

GDPR/Privacy GDPR is here, it must be respected, and failure to do so can be costly. But it’s not just GDPR an organization needs to be concerned with as privacy regulations are cropping up all over the world, and many countries in which the organization does business as a buyer, a seller, or both.

An organization must identify the private data it maintains on its employees, contractors, representatives of third parties, and the public. It must ensure such data is secured, encrypted, accessible only by those with explicit authority, and tagged as data the organization is legally allowed, or required, to keep and data that does not fall under that category. The location of such data must be indexed and the data, as well as all backups thereof, must be easily erased if someone asks to be forgotten (with the exception of any data the organization is legally required to maintain), and that must include all backups.

Contract The organization has contractual risk, both in the contracts with its suppliers as well as the contracts with its customers, and with respects to the contracts it never signed, but implied when it made the first order or purchase from a supplier. These risks include the losses from failure to complete its obligations as well as risks from suppliers and customers failing to complete theirs as well as force majeure risks and lack of of assignment to third parties and/or lack of adequate insurance coverage.

It’s critical that the Corporate Risk System integrate with all of the contract systems used by the organization, track contracts by risk type, identify lack of key clauses, and identify areas where lack of contracts or insurance put the organization at significant risk.

Epidemics/Pandemics The pandemic was not the last epidemic/pandemic the organization is going to face. More are coming. The organization needs to identify which parts of the operation are most at risk, what can be done to prepare for it, and what is in place when the worst happens.

As to how the system should support the planning, monitoring for, detection, and response to an emerging epidemic/pandemic, that’s probably organization dependent. But any Corporate Risk system that doesn’t at least recognize the need is not meeting the full problem.

A corporate risk system will also contain a host of generic analytics/planning/monitoring capabilities, but since many of these are, or at least should be, common among multiple types of risk systems, and since stand alone risk-focussed analytics applications are also part of the plethora of offerings out there, instead of discussing these generic features in this and every other article describing a particular focus/type of risk application, we will instead discuss these capabilities in an article dedicated to Risk Analytics and Monitoring near the end of this series.

Source-to-Pay+ part 2: End-to-End Risk Management

In Part 1 we noted that Risk Management goes much beyond Supplier Risk, and a primitive Supplier “Risk” Management application (which we prefer to label Supplier Uncertainty Management since it’s not full blown risk management, and there’s uncertainty as to how much it will actually do for you) is only the beginning of what your organization will likely need.

When it comes to risk, there are risks in:

  • your company
  • your suppliers
  • their suppliers
  • third parties you interact with (which may not be [direct] suppliers of goods or services)
  • your carriers
  • your supply chain network (ports, warehouses, [cross]docks, etc.)

These risks can be with

  • your people
  • your board
  • your investors
  • your supplier’s people, board, or investors
  • the materials your suppliers use
  • the locale they operate in
  • the suppliers your suppliers use
  • the locale they operate in
  • the carriers
  • the ports your carriers use
  • the warehouses used for interim storage
  • and any other part of, or player in, the supply chain

And the types of risks are numerous. They include, but are far from limited to:

  • unskilled/uncertified people
  • sanctioned/prohibited individuals and entity
  • restricted / banned materials
  • use of underage / forced / slave labour
  • geo-politics
  • economics / currency fluctuations
  • natural disasters
  • labour unrest / strikes
  • fraud / theft
  • the internet
  • and so on

And you need a very extensive application to identify, analyze, monitor, mitigate, and manage these risks. In fact, you may even need a suite of these applications, especially when you consider that most applications consider risks from the viewpoint of:

  • the company (especially those that offer GRC applications)
  • the supplier / third party (SRM/SUM+ / TPRM)
  • supply chain visibility
  • … w/or in-transport visibility
  • w/or multi-tier (manufacturing chain) visibility
  • cyber monitoring

And such an application will need entity/function specific capabilities as well as generic capabilities. The generic capabilities might include, but not be limited to:

  • data feed/stream integration
  • metric definition
  • trend analysis
  • user defined reports
  • data / trend monitoring
  • (mitigation) plan creation
  • plan management

Risk is broad, and the solution footprint needs to be broad as well. In the next few articles we will tackle some of the major application areas we noted above.

Source-to-Pay+ Part 1: The Beginning.

Once upon a time
not so long ago …

SI ran The 39 Steps … err … The 39 Clues … err … The 39 Part Series to Help You Figure Out Where to Start with Source-to-Pay and helped you understand what each of the six core technologies in Source-to-Pay do, how to evaluate them, and the order of implementation necessary to maximize short-term results (which is the only thing the CFO cutting the check for the systems cares about). Not that it should be hard, given that, as the doctor explained, if your organization is a mid market, the answer to Per Year, How Much Should You Outlay for Source to Pay? 120K! (because Yes Mid-Markets, 120K is More Than Enough for Source-to-Pay!). That’s cheap, and if you can’t get a 10X ROI on that, the doctor would be surprised. (Yes, you’ll need some integrations and some services, and that will double or triple the price and you may only see a 5X or 7X ROI, but still.)

But the reality is, especially in today’s turbulent times (where me and my wine is not enough), even full Source-to-Pay is not enough. Risks abound, and even if your Supplier Management Platform has an Uncertainty (Risk) module, there’s more than supplier risk to worry about. There’s third party, supply chain, logistics, geographic, natural disaster, and many other risks that Supplier Risk Management, which we prefer to call Supplier Uncertainty Management (due to the lack of depth, action management, support for mitigation planning, etc. we prefer NOT to call these Risk modules), applications in Source-to-Pay typically don’t address.

Then we have Corporate Social Responsibility (CSR), Environmental & Social Governance (ESG), and Carbon / Scope 1,2,3. Today, a non-responsible company that buys from suppliers who are particularly environmentally unfriendly, don’t treat their workers well, or, even worse, use forced or slave labour is the one that gets the consumer backlash, and possibly the civil AND criminal liability (with certain jurisdictions introducing laws making the last company down the chain responsible). A company that just hoards profit and doesn’t make an effort to give back is frowned upon. And a company that stays on dirty power when there is an alternative, wastefully uses fresh water, or unnecessarily consumes non-recyclable resources in its day to day operations is just being dumb. Moreover, when you consider that Carbon Tracking is Important — But a Calculator or a Credit is Not A Solution! but What You’re Really Concerned About is YOUR e-Liability, that it’s not just about tracking, but reducing where possible, and that there are real baselines given that it’s impossible to mine, process, produce, ship, or consume without emitting carbon, it’s not easy to figure out what you need.

When you are buying direct, you have to consider the supply chain as well as the implications of a change in the supply base. The ink on the contract is when the fun truly begins. The product has to arrive on time, on budget, damage free, at the right location. This requires logistics coordination, and if the contract will change the supply base configuration, this is something that should be considered up front. So logistics/network analysis is creeping into Sourcing.

Then there is the issue of T&E — what happens when it’s put on the card, because its too small to bother with a Procurement effort (it never is, although it’s not always worth the time of a Procurement Pro, and that’s why you need an appropriate T&E/Tail Spend system to make sure the end buyer gets it right) or someone is trying to bury something that they know is not truly needed, off contract, or shouldn’t be expensed.

Plus, at the end of the day, you have to pay … and most Source-to-Pay end at the OK-to-Pay. What do you do when it’s time to pay?

And so it goes.

As such, it’s time to start another multi-part series to help you, dear reader, understand the extended Procurement landscape and what you should be looking for in such systems. We’re not going to attempt to tell you what to implement first, as that will depend upon what your biggest need is, which will usually depend on what the biggest risks are to the organization at the current time — unidentified spend, risk of supply, breaks in the supply network, forthcoming legislation, global payments, and so on. We’re just going to take an area and explore it, for as many articles as it takes. More to come. Much More.

B2B Marketplaces Have Their Place But …

… don’t look to them as a foundation for supplier collaboration! While it’s nice to see Procurement platforms and technologies getting noticed in Financial publications, the juxtapostion of the headline and subheading on this recent Financial Express article made us go “OI! YOY! YOI!”.

The headline was great:
Integration of B2B marketplaces into supply chain networks for increased efficiency

… it’s exactly what Finance needs to hear as B2B Marketplaces are a great solution for commodities or products typically bought spot-buy on the open market, and much more efficient than sending out an RFP for something you can find and buy quicker, easier, and cheaper online, and definitely better than searching half a dozen supplier sites to find the right product at the right price.

And the subheading started off great:
A notable opportunity for enhancing Supply Chain Management (SCM), as rated by 53% of businesses, lies in collaborative efforts with suppliers.

… because collaborative efforts are not only a great way to increase efficiency, but also increase value by lowering cost, increasing quality, adding capability, etc.

But the way the sub-header ended was head-scratching to say the least:
The answer lies in utilizing user-friendly and efficient B2B marketplaces.

NO! No, No, No, NO! If you want to collaborate with suppliers, you need a modern Supplier Management solution that focuses on supplier development, innovation, and collaboration.

B2B Marketplaces were created to help buyers find (new) suppliers to buy from and to help suppliers widen their potential customer base when buyers find their products in a search and check them out. They were not setup for collaboration and the extent of “collaboration” on the majority of these platforms is asynchronous messaging. That’s not collaboration! Not even close.

In comparison, a Supplier Management platform with

  • Relationship Management will not only support asynchronous messaging, it will also support collaborative project/product plans and a best practice/knowledge base for both parties
  • True Network Management and not just an integrated online marketplace will also support a true bi-directional graph, bi-directional search, classification, and anonymous (peer)
    reviews
  • Proper Discovery will not only support simple searches, but deep location, product, capability, and multi-factor searches; proactive web-search and web-site monitoring; anonymized ratings and reviews; and deep product sheets and history management
  • Orchestration Management will support multi-tier linkages, cascading onboarding, and multi-tier supplier support so that you can quickly and easily onboard the supplier onto your own personal Supplier Management instance that you can customize to your liking
  • Enablement Management will add an integrated supply-centric portal, sustainability guidance, and true supplier-led innovation support

In other words, this article, which could have focussed on the core value of B2B Marketplaces and introduced them as a first step into the Procurement world, with an entire suite of valuable tools to help an organization, missed the mark.

For more information on what a proper Supplier Management platform should do, as well as a list of vendors who offer these platforms, see parts 15 to 20 of our The 39 Steps … err … The 39 Clues … err … The 39 Part Series to Help You Figure Out Where to Start with Source-to-Pay.

Supplier Management

Part 15: Supplier Management is a CORNED QUIP Mash

Part 16: Supplier Management A-Side

Part 17: Supplier Management B-Side

Part 18: Supplier Management C-Side

Part 19: Supplier Management D-Side

Part 20: Over 90 Supplier Management Companies to Check Out

Synching with State of Flux — Do the Oscillations Resonate?

It’s been a few years since SI checked in with State of Flux, so when the oscillations recently synched, it was time to see what this long-time leader in Supplier Relationship Management (SRM) has been up to. With it’s long history in helping clients actually manage supplier relationships, and 15 years doing global supplier research (having just completed its global benchmark survey for it’s 15th annual supplier management study which will be released later this year), it’s not only a grand-daddy of the space but one which gets wiser with age.

If you review the previous posts on State of Flux and their SupplierBase solution (which was, once upon a time, called Statess), you’ll see that State of Flux offers an extensive Supplier Relationship Management platform that, to various extents, offers capabilities in:

  • supplier & prospective supplier management (& onboarding)
  • supplier performance management / KPI tracking
  • supplier compliance management [intelligence]
  • supplier risk management
  • supplier contract management
  • supplier ESG management
  • supplier innovation (challenge) management
  • supplier reporting / snapshots
  • supplier relationship / plan management

We’re not going to repeat anything we covered before, especially in our posts on

… but we are going to highlight recent improvements or capabilities that were not highlighted before (which may or may not have been there in 2016).

We’re going to take the “modules” one by one, and cover them in the order above, starting with: supplier & prospective supplier management.

You can’t have SIM/SRM without supplier onboarding and basic supplier management, and in terms of the management, they have it down quite well. You can customize your profiles, track as little or as much as you want to on your suppliers (by supplier type), quickly pop-up an overview card or a status card (on how many outstanding actions, items, messages, meetings, KPI flags, risk flags, data updates, etc. you need to review and deal with), and dive into any area of tracked data in any of the categories we are going to cover below.

In terms of onboarding it’s good, but it’s one of the oldest parts of the platform and a bit slow, so, to that end, it is currently being updated end-to-end to take advantage of all recent stack and technology improvements, streamline the process, improve the response time, and enhance the UX.

Moving on to supplier performance management / KPI tracking, as per past coverage, they’ve always had this down pat and can support multi-level KPIS, roll-up and down divisions, departments, and teams as required in any split you want, normalize all metrics to a common scale for (dashboard) display and comparison automatically, and give you deep insight.

The only real weakness is that they don’t yet have an (Open)API or support integrations to any other enterprise systems where key performance data resides. (It is on the roadmap, but we don’t have an expected release date.) As such, you are limited to their import functionality, and will likely need to export all the data you need in CSV and manually (schedule) the imports, or having an API custom developed on demand (which they can do during system implementation) to any system you need integration to.

With respect to supplier compliance management, which they call Intelligence, they’ve always been good here, and have supported certification/compliance document tracking for years, but with their generic survey capability and extensive experience, upon setup, they can help you build / provide you with templates, for a whole host of compliance needs and requirements and go as broad and deep as you desire. They can also track certificates, insurance, product spec sheets, and any other documents that you require.

And then there’s supplier risk management which, like compliance, they’ve been good at for a while, and like compliance, not a lot of new capability (that will get your attention). Their platform takes a buyer-centric approach to risk — the buying organization defines what’s important to them from a performance/relationship perspective, what the risks are, the information that will help them assess that risk, builds the questionnaires and surveys they need the suppliers to answer, includes those in onboarding / innovation challenge / ESG / contracting initiatives, and then build metrics to assess them.

The only external risk data feed / risk score they can import out-of-the-box today is CreditSafe, which is retiring, but they have an integration with S&P Global Partnership forthcoming to replace it. Also, as per above, they don’t yet have an (Open)API to allow you to plug and play risk data feeds of your choice, but can custom integrate any you need upon system implementation. You have to send surveys or load well-formatted CSV files. Better integration/load capabilities are on the roadmap, but there is no committed date yet for general release, nor decision as to how complete a public API will be. So if you can’t send surveys, you will have to export the data into flat files and load them.

Now for supplier contract management. This is where you quickly notice one of the most significant enhancements to the platform since SI last covered it. While it still doesn’t do authoring or version tracking, and they do integrate with Zoho for that if you want it, they have implemented a full end-to-end contracting process model that consists of the following steps:

  • request – where it captures the contract type, the product/service category and template, and the necessary approval routing;
  • creation – where it captures all of the necessary metadata, and then the contract document and/or integrates with zoho for the creation of the contract document (and version tracking)
  • review – where it forces the appropriate people to review their portions, confirm review and okay and issue, and potentially sends the contract back to negotiation
  • final review – where key parties have to sign off before it is sent to the managers/owners for approval
  • supplier signature – which can be through DocuSign integration
  • buyer signature – which can be through DocuSign integration

The process is so good that an average mid-sized enterprise won’t need a Best-of-Breed (BoB) standalone CLM, and just a basic authoring solution, like Zoho, to get contracts under their control.

Tackling supplier ESG management, this is a relatively new module that allows an organization to track it’s ESG initiatives, the associated data, supplier assessments and reviews, associated challenges, and select data to support the supply base / supplier development plans (which we’ll discuss down the virtual page). It’s not meant to be an ESG Calculator, Scope 3 solution, or similar offering. The whole point of it is that it’s not just compliance or risk, but an area on its own that must be managed.

With regards to supplier innovation (challenge) management, this is one of their classic areas of functionality, as they were one of the first pure SRM platforms to include it as sometimes the only way for a supplier to be right for you is if they can come up with a better solution to your problem or product production through a challenge.

That being said, it’s not NPD/NPI, it’s not full project management, and it’s not even full innovation (but more challenge) management (as that may require CAD/CAM diagrams, extensive on-line design/visual collaboration, etc.), but it gets the job done, it’s easy to use, it’s streamlined, and it can be fit easily into overall supplier profiles and programs.

We’re not sure how much has changed in underlying reporting and dashboarding capability, but we can say it does look a lot cleaner and seems to load a lot faster than years ago. Also, not only are they highly configurable (as you would expect in a modern BoB solution, although there are limits on how much is self-serve vs. State of Flux configuration), but as they have learned and advanced through the years (through their consulting practice and fifteen years of research), their out-of-the-box configurations have improved by the year to the point where most organizations should get the majority of the metrics and insight they need with out-of-the-box configurations.

Finally, we’ll tackle the core of the platform the supplier relationship / plan management capability. This is where they’ve done the most work, or at least the most improvement, since SI covered the solution last. While it’s not to say that, regardless of what was and was not said above, they have not made improvements across the entire platform in the past six years, as they most certainly have, it is to say that only a few areas are really standing out as being considerably improved (and not just updated/progressed as expected).

What really stands out here is their integrated support for supplier-based strategic and joint business plans based on a full relationship profile and a 360-degree relationship assessment. The depth of detail that is captured around:

  • the relationship context
  • the relationship SWOT
  • strategy / development goals
  • 360-degree interaction
  • governance (with respects to roles and responsibilities on both sides)
  • risks
  • contracts
  • spend / category information (which must be loaded)
  • projects / action plans

is second-to-none. If this is the type of capability you are looking for with regards to strategic supplier management, this is the capability you really need a demo of, and not a third party overview. You need to see it to get the full depth of the capability and potential for your organization.

In addition, they have improved their meeting/calendar/communication management functionality and you can schedule all of your meetings inside the platform as well as manage all of your communications, including those through e-mail, so you maintain the complete interaction history with the supplier and its personnel.

In other words, it’s not only managing the supplier data, or the interaction, but all aspects of the relationship as well as the plans to improve that relationship. It’s rather unique in that way. It may not be best-in-class in specific functionality, and you may need to augment certain areas for risk, innovation/NPD/NPI, ESG, etc., but you have the central management platform and data store that you need to power your supplier-centric sourcing and procurement eco-system.

If this sounds like what you want in a strategic supplier relationship management platform, then the State of Flux SupplierBase solution should definitely be on your shortlist. Especially when they can offer full service around integration, best-practice consulting, training, and research findings to jump-start a program or shift an existing one into high gear.

Postscript: We’ve covered State of Flux, and their philosophy to leading SRM practices, quite a bit in the past. Here are some in-depth series from 2015 and 2016.