When Was The Last Time You Did A Full Audit Of Your Supply Chain!

When a single event puts over 25T of global trade in jeopardy, or about 20% of Global GDP, you know you need a full end-to-end understanding of your critical supply chain.

The event I’m talking about is the 2026 US-Iran War that saw the Strait of Hormuz closed.

1. Global trade in goods and services is about 35% in US Dollars.
2. 80% to 90% of all traded goods move by ship through canals, straits, seas, and oceans.
3. About 8% of maritime trade by volume passes through the Strait of Hormuz.

Do the math, and it’s easy to see that the blockage / closure of the Strait puts over 25T of global trade in jeopardy, because wars in the Middle East tend to drag out for years!

The world was not ready for this. (They thought the US would never risk a war with Iran because of that … especially when the US could have continued last year’s strategy of just bombing uranium enrichment sites once per year as they neared completion and prevented Iran from ever reaching nuclear potential that way.)

Most company’s supply chains were even less ready — especially since some sectors saw way more than 20% impact, especially when it’s (one of) the largest trade route(s) for certain products like LNG (20%+/-), (crude) oil/petroleum (25%+/-), fertilizers (33%+/-), and sulfurs (50%+/-). Multi-national businesses without alternate sources or routes at their immediate disposal were put in instant financial jeopardy (and risk of bankruptcy)

As a result, you need more than supply chain visibility, you need full end-to-end supply chain awareness for all critical product lines, and that requires a full audit. You need to know where everything is coming from, what routes it’s taking to get to you, what alternatives exist (and to what extent — can you replace all, part or none), and what financial impact its disappearance would entail.

Even if you can get it at a reasonable price, supply chain insurance isn’t going to be enough anymore. As with any insurance, there will be exclusions for war, terrorism, etc. unless you pay astronomical prices, conflict zones will be excluded, and when a disaster wipes out an area and affects many clients at once, payouts won’t be quick and you can expect a massive amount of paperwork and effort will be required to get one (as the insurer won’t have enough cash on hand and will have to delay and delay until they can liquidate assets, which is difficult to do in crashing markets that result from economic disasters).

When something happens, you need to be able to react, reroute, and reorder quick. That will require not only deep visibility, but pre-defined mitigation plans when key regions, routes, or resources are impacted. The only way you will know this is if you do a full audit and associate each product to (sub-tier) suppliers, locations, countries/zones, and routes. That way, when a critical event (is likely to) happen(s), you can immediately identify the affected parties, locations, routes and associated products, and determine what you need to do in order to ensure continued supply. It might be switching plants, distribution routes and methods, or even suppliers.

If you haven’t done a supply chain audit in a few years, or ever, you should do one ASAP. You don’t want to be caught off guard when the next major disruption happens!

Why it’s just easier to do your job in the Age of AI

Every year articles make the rounds on how to do nothing at work or look busy to either slack off or keep your annoying cow-orkers away so you don’t end up having to do their work too. Now, a few in 2006 really annoyed me and I decided to point out how stupid they all were by selecting one in particular and pointing out just how stupid it was because it was harder and more work to follow the advice then to just do your job for your 35 hours a week you had to work.

But I’m not here to tackle another inane article about how to slack off or avoid responsibility, because hopefully by now you’re not dumb enough not to fall for it, especially since smart managers (and workforce monitoring solutions) aren’t either.

I’m here to tell you why it’s just easier to do your job in the age of AI than to try to use AI to do it for you.

1. You’ll have to tell the AI what you want at least 3 times. Maybe 10. Or More.

Gen-AI LLMs should be called Artificial Idiocy. There’s nothing intelligent about them. They don’t understand anything. It’s all a Grand Illusion. Automated puppet-theatre … and we’re the suckers born every minute for using it.

As a result, they produce a lot of good sounding text that sounds close to what you need, but upon further review, always misses one or more key points of your request … until you repeat it and rephrase it ten times ten different ways and your strive to perfection slowly reduces to anything acceptable whatsoever.

2. You’ll still have to edit the final outputs and execute the work in the tools it can’t drive because they don’t have the APIs for the LLM to execute.

So, after spending hours trying to get it to output the perfect report and process, you have to go edit, finish, and execute that process. Spending as much time as if you just skipped the AI in the first place.

3. You have to deal with the consequences of the errors you miss.

If you’re using a modern Procurement system which is AI-first and allows external AI to drive it, a request to “restock the supply room at the lowest cost” can result in ten times the amount of printer ink, paper, pens, and cleaning solvent you go through in a year because it hit a volume break at the production plant and skipped the intermediate supplier, ignoring the fact that you have to rent a warehouse for the truckloads of cleaning solvent you just ordered for your office building (even though you only use one floor — it assumed you wanted enough for the twenty story office building).

You’ve spent too much, have no room for the inventory, and have to explain to your boss why ordering years worth of office supplies was a good idea.

4. You have to explain the AI bill that was five fold what you planned.

While also explaining that it was your idea, not the AI’s, to screw everything up.

It’s always easier, and less risky, to use your Human Intelligence, and not the AI, to get your job done.

So, You Didn’t Succession Plan — What Do You Do Now?

Back when SI first started talking about talent in year one, we noted that the most important thing you need to do is succession plan — because even if you do everything right, acquire and keep the right talent, and thrive … it will all come to an end when the talent gets lured away, retires, or dies (and it does happen).

You see, if you succession planned, you would have done a number of things that, frankly, you should have started 20 years ago (if you were in business then), or the year you started (if you weren’t).

1. Captured their knowledge from day one

You would have acquired a KMS (Knowledge Management System) and started capturing their knowledge from day one. Even if it’s not directly tied to the systems they use, you’d at least be capturing key knowledge that your junior people don’t have.

2. Captured key artifacts from day one

Furthermore, as time went on, you’d acquire systems for all of their major tasks and ensure that all of the key steps were done online in those systems. No bypasses allowed. Sure, how they made the decisions would be in their head, at least to the extent it’s not captured in the KMS, but all the steps, and artifacts would be there for whomever comes next.

3. Identified at least one internal successor for each critical resource and have that individual mentored by the critical resource ASAP

So that, even if the potential successor isn’t ready for a senior role when the critical resource is no longer available, at least you’ll have retained some of the knowledge, some of the artifacts, and some of the capability. And if you can find a suitable replacement externally quickly, that person will be much more effective as they’ll have a capable right hand resource, artifacts, and knowledge.

But you didn’t do any of this. So what do you do?

Well, first take Wouk’s advice and get it out of your system:

When in danger or in doubt,
Run in circles, scream and shout

Second, identify and acquire a suitable successor as soon as possible, even though it could be costly. You need someone suitable who’s ready, not half ready.

Third, you need to acquire the expertise and systems to jump start the replacement.

  1. Get a KMS ASAP. Don’t make the same mistake again.
  2. Acquire systems that will be used to automate key functions, as well as capture, store, and index all the key artifacts for quick look up that are needed to execute them — no disconnected email, documents on various cloud drives and untracked laptops, or other haphazard solutions.
  3. Hire expert consultants who are former practitioners to help populate that KMS with key knowledge and execution systems with templates and as much process knowledge as those systems can hold.

You’ll still have a rough time sailing choppy seas … but you might not sink if you start on the right track now. No guarantees, but it’s likely your only chance. The Age of AI Hype has proven dumb systems and inexperienced kids can’t do the jobs of senior talent, and since you forced so much of that talent into early retirement with your AI BS, you’re in trouble if you can’t retain a few grey hairs and start training the next generations to take over now.

… so What’s the Real Future for Procurement Tech?

Yesterday we pointed out that SOFIA Killed BOB and Replaced POE with a Black Box Agent, which forces us to ask what’s the real future for Procurement Tech?

As we noted in our last post, twenty (20) years ago the debate was BOB (Best-of-Breed) vs POE (Platform Oriented Enterprise — a [mini] Suite solution).

It was a real debate — best-of-breed modules gave you what you wanted and delivered value, but a slew of disconnected modules is not very productive. (Mini) Suites solved the dis-connectivity problem, but came with their own problems. Given that most were quickly built out on top of one or two core modules, and modules beyond those were barely MVP (that even startups would be shy releasing), you were sometimes lucky to get the 60% to 80% functionality the vendor promised.

SOFIA ((Solution Orchestration Framework Integration Architecture) was supposed to end the debate. Real orchestration solutions that would allow organizations to BYO-BOB (bring-your-own-best-of-breed) for any and all modules they wanted to construct their ProcureTech (and, hopefully, SupplyTech) platforms, but fell short. Part of the reason is that they started as intake to make the big suites usable, and didn’t start building a true, native, orchestration architecture — making it difficult for them to quickly and easily orchestrate the plethora of platforms that customers throw at them. The other part of the problem is that the majority of (classic) SaaS platforms weren’t built to be orchestrated, and, frankly, can’t be.

And using AI-first tools to quickly vibe-code the most common MVP modules customers want that can be “orchestrated out of the box”, doesn’t solve the problem. It just devolves the solution into a classic POE solution (but with less security — one of the big flaws of vibe coding). So SOFIA isn’t solving anything either.

Now, if you ask GAIN, the future is “AI Employees” (which aren’t real). Like any LLM-based solution, they will work great until a Grade A Hallucination results in buying millions of dollars of the wrong product, selecting a sanctioned supplier, or sending money to a dark-web criminal organization. Then it won’t. (At first, it will just order 3,000 pairs of gloves for an automated cafe for a lone worker, because it’s cheaper. LLM-based AI has already done that. Look it up.)

Probabilistic AI (where hallucinations are a core function that CANNOT be trained out) is not the answer and should never be used for more than suggestions.

So what is?

An enterprise SaaS platform rebuilt on a proper intake and orchestration platform (that supports rules-based agentic automation, i.e. [A]RPA) that was originally built to be domain independent and just solve the data and workflow integration challenges. In other words, if Coupa rebuilt on Tonkean (which won’t happen for so many reasons), that could be close to the answer. Zip and Oro were built too quick or too focussed to be the answer. It will be true orchestration platforms you don’t yet know that get acquired by tier-2 suite players with a lot of tech debt that rebuild on those orchestration platforms (that also built native intake) which can seamlessly integrate with next-gen SaaS platforms with secure, full, open APIs that allow for full data push and pull and programmatic function and workflow execution.

In other words, it will be domain specific SOFIAs. Not POE (which is too limited) and not Fake AI Employees.

The question is, who will create theirs first?

SOFIA Killed BOB and Replaced POE with a Black Box Agent …

What’s the real future of Procurement Tech?

Twenty (20) Years Ago, we asked What about BoB? when the debate in ProcureTech between BOB (Best-of-Breed) vs. POE (Platform Oriented Enterprise) was getting drowned out by the emerging suite players.

Did you go out and assemble your own suite of best-of-breed modules to suit your needs, and then pay the consultancy integrators big bucks to integrate them, or simplify your life, settle for a 60% to 80% solution and buy a suite that gave you an all-in-one solution (and bypassed difficult and expensive integration requirements) that was hopefully strongest where your core needs were?

It was a valid hot debate because most suites were centred on one (or two) strong modules that the firm was founded on, with the other modules either hastily built to what the firm considered an MVP so that they could sell a (mini) suite or acquired (and partially integrated) so they could have a suite, even though some of the modules were loosely connected (and sometimes even built on entirely different UX philosophies with noticeably different user interfaces).

Furthermore, twenty years ago, the bigger the suite was, the worse or more disconnected part of the suite was. In the beginning, most vendors started as e-Sourcing or e-Procurement and mini S2C and P2P suites were built up around those modules, respectively. S2P suites were usually built by one mini-suite vendor acquiring another (or, in rare cases, a CLM or SXM vendor realizing they needed both and getting the help of an investment firm). You had frankensuites built from three (3) primary solutions (and, in some cases, fattened up by additional acquisitions over time), which felt as disconnected as they were to use. However, the one-vendor-throat-to-choke and one-implementation-team comforted the C-suite and those purchases were easier than trying to get permission to acquire a bunch of best-of-breed solutions and then write a big cheque to an integration consultancy that you hope can get the solutions to all work together, at least until major solution upgrades, in which case the consultancy will have to come back and upgrade the integration.

Then orchestration came along and SOFIA (Solution Orchestration Framework Integration Architecture) was supposed to settle the debate once and for all. With modern orchestration solutions, you were supposed to be able to bring your own best-of-breeds, integrate them all with modern orchestration, and either use their native intake, or bring your own, to open up their solutions to everyone who needs access. That was the theory. The practical reality is different.

I’m not sure if it’s still the case, but for years, neither you nor your consulting and integration partners could integrate your own solutions with Zip — Zip had to do it internally because it was too complicated and needed to be done a specific way. Oro, first designed to make Ariba usable and then to make other major last-generation suite solutions usable, provided you with a similar situation — partner solutions are pre-integrated and easy to onboard, other solutions took time. Then there’s Tonkean, now part of Coupa, that could integrate anything if they did it and you gave them the time to do it. Time being the key word. (They were essentially assembling an application for you … no quick out-of-the-box configuration!)

None work(ed) out of the box, and there’s two reasons for that.

The first is that you can’t quickly MVP generic orchestration solutions that are flexible, powerful, easy to use and work with today’s SaaS — the Enterprise has to be carefully thought out and designed and the coding talent needed is not the script-kiddie drop out talent that many (AI-first) firms are employing.

The second is that most platforms, frankly, weren’t even built for integration, which means that they definitely weren’t built for orchestration. Modern orchestration requires more than the ability to push some data in, and pull some data out. First of all, it requires the ability to push all data in and pull all data out. Secondly, it requires the ability to programmatically trigger and execute functions and workflows from external sources. Most platforms don’t support that (well). As a result, orchestration platforms don’t work. If the platform doesn’t have, and completely expose, its API (through secure channels to apps with appropriate security credentials), orchestration is not truly possible.

As a result, most of the big orchestration providers are trying to use AI-first tools (and vibe coding, which, as we’ve made clear many times, only produces vibes that are please to the smug sniffing coders who use it, not good code) to quickly code their own S2P apps and modules, and essentially reverting to a POE (2.0) solution — internalizing their orchestration solution as a platform oriented enterprise to build a next-gen classical suite solution. (Oxymoron intended!)

But is that the future? (Hopefully not!)