Risk Management and Business Continuity: How to Turn Supply Chain Uncertainty into a Competitive Advantage

Only 551 out of 1,000 companies have a business continuity plan: learn how to structure risk management in the supply chain using practical methods and tools

Edited by the Bonfiglioli Consulting
Editorial Team Each publication is based on industry studies, field research, and analysis of global trends, integrated with the knowledge and expertise gained through transformation projects, with the goal of promoting corporate culture.

Published on May 7, 2026

Table of Contents

How to build a structured risk management and business continuity system for the supply chain: from mapping strategic, operational, financial, and external risks, to analyzing the supply base using the Kraljic matrix, to defining effective contingency plans and applying Pro-FMEA. A practical guide for B2B companies seeking to reduce operational disruptions, increase reliability for customers and stakeholders, and compete effectively even in scenarios of crisis and geopolitical volatility.


Risk Management is the structured process by which an organization identifies, assesses, and responds to risks that threaten business continuity. Today, it is no longer the exclusive domain of specialists: it is a managerial tool that determines a company’s ability to compete even under adverse conditions.

In recent years, companies have learned—often the hard way—that business continuity can no longer be taken for granted. Shortages of critical materials, supplier unavailability, supply chain disruptions, cyberattacks, market volatility, geopolitical tensions, and skills shortages: what was once considered an exceptional event is now part of the everyday competitive landscape.

The data confirms this. According to our biennial Benchmarking Study | What’s Next in Operations? — conducted among over 100 companies across 22 industrial sectors, with a sample comprising 85% C-level executives and 83% companies with over 100 employees, predominantly B2B (87%) — only 55% of companies have implemented business continuity systems. The average Supply Chain Maturity Level stands at 67%, indicating widespread fragility in terms of responsiveness and digitization, with a heavy reliance on manual processes and difficulties in managing fluctuations in demand and supply issues.

Un grafico a dispersione mostra cinque categorie della supply chain in base al punteggio e alla maturità della digitalizzazione, evidenziando la Business Continuity. Ogni categoria è contrassegnata da un triangolo colorato, descritto nella legenda a destra. Le etichette e gli assi sono in italiano.

The real question, then, is not whether a disruption will occur, but how prepared the company is to prevent, manage, and overcome it.

Why shift from emergency management to a culture of prevention?

One of the most common mistakes organizations make is treating risk as a secondary concern—something to be covered by a generic "contingency" fund or addressed only when it arises. It’s a convenient but dangerous approach. An unspecified financial reserve is no substitute for a prevention system and, above all, does not build organizational capacity.

Managing risk effectively means making a cultural shift: recognizing that business continuity is not simply a reaction to an incident, but the ability to prepare in advance what is needed to continue operating even under adverse conditions.

A reactive approach leads to decisions made under pressure, unexpected costs, eroded margins, delays, penalties, and reputational damage. A proactive approach, on the other hand, allows you to assess threats in advance, develop coherent countermeasures, reduce the likelihood of an event occurring, and limit its impact should it happen. In other words: it’s not just about defending against risk. It’s about managing it.

Why is procurement now at the heart of business resilience?

While business continuity is a cross-functional responsibility, it is within procurement that many critical issues become decisive. Procurement is no longer a purely transactional function: it is a strategic lever that directly impacts the company’s ability to ensure service, quality, flexibility, and economic sustainability.

Today’s supply chains are more extensive, more interconnected, and more vulnerable. The outsourcing of non-core activities, pressure on lead times, increasing customization, logistical complexity, dependence on distant markets, and the financial fragility of some suppliers have vastly expanded the scope of supply risk.

Added to this are external factors that are difficult to control: price volatility, currency fluctuations, regulatory changes, environmental events, geopolitical tensions, and cyber risk. All of this calls for a fundamental reevaluation of how the supplier base is designed, assessed, and managed. It is no longer enough to simply seek the best price: we must understand which supplies are truly critical, where vulnerabilities lie, and where to balance efficiency and resilience.

Supply chain resilience is now a matter of organizational and strategic design.

What are the four categories of risk that need to be managed?

A common mistake is to view supply risk management as an issue limited to the availability of materials. In reality, the risks that impact business continuity are numerous and interdependent:

  • Strategic risks: related to costs, quality, service levels, sustainability, and the configuration of the procurement portfolio. The risk is not just "missing a component," but making decisions that weaken competitiveness in the medium term.
  • Operational risks: processes, product development, data security, human capital, compliance, and operational reliability. These manifest in day-to-day operations: late deliveries, non-compliance, information inefficiencies, and excessively long response times.
  • Financial risks: supplier solvency, supply chain liquidity, and partners“ ability to sustain business continuity and investments.
  • External risks: these can be analyzed through a PESTEL lens—political, economic, social, technological, environmental, and legal factors that can suddenly alter the procurement landscape.

The managerial challenge lies in shifting from viewing risk as an isolated event to viewing it as a system.

How to Build a Business Continuity System in Procurement?

To make risk management truly useful for Operations, a method is needed. An effective approach goes beyond simply taking a snapshot of risk; it guides the organization through a structured five-step process:

  1. Risk Assessment — Potential critical events are identified, data is collected, vulnerabilities are analyzed, and the organization’s actual exposure is understood. Without this phase, risk remains a subjective perception.
  2. Strategic Analysis of the Supply Base — The focus shifts from abstract risk to a concrete analysis of the procurement portfolio: product categories, dependencies, critical issues, volume concentration, geographic location, partner stability, and level of substitutability.
  3. Definition of Risk Contingency Plans — We select the actions to be taken, with defined priorities, owners, timelines, and activation thresholds.
  4. Execution — A contingency plan is only as good as its ability to be executed. This requires dedicated teams, clear procedures, training, and operational discipline.
  5. Continuous Improvement — Every event, every deviation, and every weak signal becomes a learning opportunity. Resilience is not a state achieved once and for all; it is a skill that is honed over time.

🎬 Want to see these 5 steps applied in practice?
Watch Bonfiglioli Consulting’s Digital Talk on Demand: Business Continuity System for an Antifragile Supply Chain.
Access the free video →

How do you assess risk in the supply chain in a structured way?

One of the most important aspects of risk management is establishing prioritization criteria. Not all risks deserve the same level of attention or the same level of investment.

A qualitative assessment matrix allows you to cross-reference two fundamental dimensions: probability of occurrence and severity of impact. This is an essential step that enables the organization to distinguish between risks that can be monitored through routine management, risks that require periodic attention, and risks that demand proactive plans and frequent interventions.

But the assessment cannot be limited to internal perceptions. Market information, external sources, historical data, price data, currency trends, industry intelligence, and predictive models are all necessary. In an unstable environment, the quality of decisions also depends on the quality of the signals the company is able to detect. For this reason, Procurement must evolve toward a Business Intelligence approach: not just managing orders, but interpreting the context.

What is the purpose of the Kraljic matrix in risk management?

Not all items and not all suppliers carry the same weight for the business. Continuing to manage them using a one-size-fits-all approach means wasting attention where it’s not needed and underestimating what’s truly critical.

The Kraljic Matrix is one of the most effective tools for segmenting procurement categories based on two variables: impact on the business and complexity of the supply market. Its utility is tangible: it allows for the assignment of differentiated strategies depending on the nature of the risk.

Where market risk is high and the impact on the business is significant, the relationship must be managed strategically—with supplier development plans, partnerships, and shared visibility. Where the impact is more limited, the approach can be more tactical or transactional. The goal is not to classify for the sake of it: it is to use segmentation to guide decisions on where to invest, where to maintain a presence, where to diversify, and where to simplify.

What should an effective contingency plan include?

The value of risk management is measured when it translates into concrete action. An effective contingency plan is not a generic document, but an operational tool. It must clarify what to do, who does it, when to activate it, and with what objectives.

The essential elements are:

  • Business continuity policy: purpose, scope, and guiding principles
  • Mapping of critical procurement processes and related business processes
  • Maximum tolerable downtime and target recovery times
  • Design of continuity solutions (multiple sourcing, dual sourcing, selective inventory buildup, review of supplier geographic location, agreements with local partners)
  • Clear operational procedures with defined roles, responsibilities, and training requirements
  • Escalation and communication plans

The key point is that actions must not be improvised: they must be consistent with the nature of the risk and the assigned priority level.

What is Pro-FMEA and how does it apply to procurement?

Among the most useful tools for putting prevention into practice is Pro-FMEA (an adaptation of the FMEA—Failure Mode and Effects Analysis—method applied to procurement). Its value lies in enabling risks to be analyzed in a structured manner before they result in damage.

In supplier relationships, the most common failure modes are well known: non-delivery, late delivery, non-conforming delivery, increased direct and indirect costs, and compliance issues. The Pro-FMEA approach allows you to:

  • Identify failure modes and describe their effects
  • Estimate severity, probability, and detectability
  • Identify causes and evaluate existing controls
  • Develop a risk priority index to guide decision-making on corrective actions

The strength of this tool lies in shifting the conversation from the vague "there might be a problem“ to the concrete ”this is the failure, these are the causes, this is the effect, this is the priority, this is the action.“ This is where risk management ceases to be theory and becomes an operational discipline.

Digital Technology as an Enabler of Business Continuity

No business continuity system can function without visibility. And today, visibility also relies on digital tools. Dashboards, business intelligence tools, KPI monitoring, vendor ratings, real-time segmented portfolios, service and quality indicators—all of these make risks easier to understand and enable a more timely response.

Digital solutions do not replace managerial judgment, but they enhance its quality. They enable organizations to detect early warning signs, measure the performance of the supply base, verify the effectiveness of corrective actions, and trigger escalation mechanisms. At the same time, technology must be integrated into a coherent organizational model: roles are needed to take responsibility for it, along with regular management routines—flash meetings, periodic reviews, and daily management.

Sustained continuity over time is not achieved solely through radical interventions. It is built through disciplined, fact-based day-to-day management.

Resilience, reliability, competitiveness: the true return on risk management

When risk management and business continuity are approached methodically, the benefits extend far beyond the reduction of threats. The organization gains:

  • Clarity in decision-making and speed of response in critical situations
  • Reduced supply chain disruptions and unexpected costs
  • Greater reliability toward customers, stakeholders, and financial partners
  • Faster recovery from adverse events
  • A competitive edge in a market where trust is an asset

The most advanced companies have understood this: they do not seek a perfect supply chain, because they know it does not exist. They build a supply chain capable of absorbing shocks, adapting, learning, and bouncing back. And it is precisely this capability that makes the difference between those who are overwhelmed by complexity and those who manage it.

Frequently Asked Questions About Risk Management and Business Continuity in the Supply Chain

What is Risk Management in the supply chain?

Supply chain risk management is the structured process by which an organization identifies, assesses, and manages risks that could threaten business continuity. It includes mapping vulnerabilities, assessing the likelihood and impact of critical events, and defining response and prevention plans.

What is a Business Continuity System, and why is it important?

A Business Continuity System is the set of processes, tools, and operational plans that enable an organization to continue operating—or to quickly resume operations—following a critical event. It is important because it reduces downtime, limits financial and reputational damage, and increases the trust of customers, partners, and stakeholders.

What are the main supply chain risks that need to be managed?

Supply chain risks fall into four main categories: strategic risks (costs, quality, sustainability), operational risks (processes, compliance, human capital), financial risks (supplier solvency, supply chain liquidity), and external risks (geopolitical, environmental, regulatory, and technological factors that can be analyzed using the PESTEL framework).

What is the Kraljic Matrix, and how is it used in risk management?

The Kraljic Matrix is a tool for segmenting the procurement portfolio that classifies product categories based on their impact on the business and the complexity of the supply market. In risk management, it helps identify which suppliers and categories require a more intensive monitoring strategy and where it is advisable to diversify, develop partnerships, or simplify management.

What is Pro-FMEA as applied to procurement?

Pro-FMEA is an adaptation of the FMEA (Failure Mode and Effects Analysis) method applied to procurement. It enables the identification of potential failure modes in supplier relationships—such as non-delivery, non-conformity, or cost increases—the estimation of their severity, probability, and detectability, and the creation of a risk priority index to guide corrective actions before the problem occurs.

How do you develop an effective contingency plan for the supply chain?

An effective contingency plan must include: a business continuity policy with objectives and guiding principles, a mapping of critical procurement processes, the maximum tolerable downtime, continuity solutions (dual sourcing, selective inventory buildup, agreements with alternative suppliers), clear operational procedures with defined roles and responsibilities, and escalation and communication plans.

How many companies have implemented business continuity systems?

According to Bonfiglioli Consulting’s biennial Benchmarking Study, conducted among over 100 companies across 22 industrial sectors, only 55% of companies have implemented business continuity systems. The average Supply Chain Maturity Level stands at 67%, highlighting a widespread vulnerability in the ability to respond to operational disruptions.

What is the difference between reactive and preventive risk management?

A reactive approach to risk means intervening only after a critical event has already occurred, with decisions made under pressure and unexpected costs. A proactive approach, on the other hand, allows companies to assess threats in advance, develop coherent countermeasures, reduce the likelihood of an event occurring, and limit its impact. The difference is not just operational—it is cultural and strategic.


Do you want to build a practical risk management system for your supply chain?