Supply-Chain Security · SC-Q12

Question: Is the supply-chain security program periodically reviewed for effectiveness and improvement?

Why This Matters

Continuous review keeps the TPRM program aligned to evolving risks, regulations, and market conditions.

Maturity

0 — Unaware
No review or metrics on TPRM performance.
1 — Ad Hoc
Reviews triggered only after issues.
2 — Defined
Annual program review scheduled.
3 — Managed
Metrics and audit results analyzed for improvement.
4 — Integrated
Feedback from risk, legal, and procurement included.
5 — Optimized
Continuous assurance and dashboard for program maturity.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |Collect basic feedback from recent assessments. | | 1 → 2 |Schedule annual TPRM review meeting. | | 2 → 3 |Analyze KPIs and audit findings for trends. | | 3 → 4 |Include cross-functional inputs (Risk, Legal, Finance). | | 4 → 5 |Publish dashboard and maturity progress annually. |

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Tracking | Airtable | Improvement log | | Visualization | Metabase | Program metrics | | Scheduling | Google Calendar | Annual review alerts |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO/IEC 27001 | 9.3 / 10.2 | | NIST CSF 2.0 | GV.MA | | NIRMATA Mapping | SC-Q12 drives supply-chain program improvement. |