The 4 Types of Supply Chain Risk (and How to Assess Each)
Not all supply chain risk behaves the same way. This guide breaks risk into its four core types, supply, demand, operational and external, and shows you how to assess each one so you can see where your network is genuinely exposed.

The four main types of supply chain risk are supply risk, demand risk, operational risk and external risk. Supply risk sits upstream with your suppliers, demand risk sits downstream with your buyers, operational risk lives inside your own processes, and external risk comes from the wider world your network can't control. Almost every disruption you'll face is a version of one of these four, and the reason categorising them matters is simple: you can't assess, compare or reduce a risk you haven't first named.
Treating 'supply chain risk' as one undifferentiated worry is what leaves you reacting to disruption instead of getting ahead of it. Break it into its four types and each one comes with its own signals to watch, its own metrics to score, and its own set of moves to make. Here's how to think about each, and how to assess where you're actually exposed.
1. Supply risk
Supply risk is the threat that something upstream fails to reach you: a supplier goes under, a single-source component dries up, a Tier 2 factory you didn't know you depended on stops shipping. It's the most familiar type because it's the most direct, and it's often the most dangerous because so much of it hides below Tier 1. You may have a clear read on the suppliers you contract with and almost none on the suppliers they depend on.
To assess supply risk, start by mapping where your inputs actually come from, then score each supplier on the factors most likely to interrupt supply. Financial health tells you whether a supplier can keep operating. Geographic concentration tells you whether a single event could take out several sources at once. Single-source dependency tells you where you have no fallback. Lead-time variability tells you how much slack you really have. The goal is a ranked view of which suppliers, if they failed tomorrow, would hurt you most.
2. Demand risk
Demand risk is the mirror image: the threat that what you supply no longer matches what the market wants, when it wants it. It shows up as demand that swings faster than you can respond to, forecasts that miss, sudden shifts in buyer behaviour, or the bullwhip effect amplifying a small change at the end of the chain into a large one at your end. Where supply risk is about inputs failing, demand risk is about outputs and signals decoupling from reality.
To assess demand risk, look at how volatile your demand actually is and how well your forecasts have held up against it. Forecast accuracy over recent periods tells you how much you can trust your own numbers. Demand variability tells you how much buffer you need. Concentration on the buyer side matters too: if a large share of your volume depends on a small number of buyers, their decisions become your risk. The aim is to know where your demand signal is weakest and where a single shift would leave you over or under-committed.
3. Operational risk
Operational risk, sometimes called process risk, is the risk that lives inside your own four walls: production breakdowns, quality failures, IT or system outages, capacity constraints, or the loss of a key person or facility. These are the risks you have the most control over, which is exactly why they're easy to underestimate. They rarely make headlines, but they cause a steady drip of disruption that adds up.
To assess operational risk, look for your internal single points of failure. Which processes have no redundancy? Which facilities can't be substituted? Where does throughput depend on one machine, one system, or one person's knowledge? Useful signals include historical downtime, quality defect rates, capacity utilisation running close to the limit, and how quickly you've recovered from past internal failures. The stronger your view of where your own operations are brittle, the fewer surprises you'll get from within.
4. External risk
External risk is everything outside your network that can still reach into it: geopolitical events, natural disasters, regulatory change, economic shocks, and shifts in trade policy such as tariffs or sanctions. You can't prevent these, and you often can't predict their timing, but you can absolutely map your exposure to them and rehearse your response. This is the type most likely to hit several parts of your network at once, which is what makes it so damaging when it's ignored.
To assess external risk, translate broad macro threats into exposure specific to you. Which of your suppliers, routes or facilities sit in regions exposed to geopolitical or climate risk? Which of your inputs are subject to changing trade or regulatory regimes? Scenario planning is the tool that turns this from a vague worry into a set of concrete decisions: model a port closure, a tariff, or a regional shock, and see how the impact would propagate through your network before it happens rather than after.
How to assess all four together
Naming the four types is the start; the discipline is assessing them consistently and continuously. Score each supplier, process and dependency against the risks that apply to it, on the same scale, so you can compare exposure across very different parts of your network and rank where to act first. Then keep the picture current. Supplier financial health, demand volatility and geopolitical exposure all move constantly, so an assessment you run once a year is out of date almost immediately. The organisations that stay ahead of disruption treat risk assessment as a live feed, not an annual audit.
This is also where the limits of older tools show. Correlation-based analytics can tell you that two things tend to move together, but not which causes which, so they can't tell you what would happen if you acted differently. Causal AI models the underlying cause and effect across your network, which is what lets you see how a shock in one of these four categories would ripple into the others, and act on a recommendation you can actually defend.
If you want the full method for turning these four types into a working programme, see our guide to supply chain risk management, the pillar this article sits under.
Questions this piece raises
What are the four main types of supply chain risk?
The four main types are supply risk (something upstream fails to reach you), demand risk (demand and your supply decouple), operational risk (a failure inside your own processes), and external risk (a geopolitical, regulatory, economic or natural event outside your network). Most disruptions are a version of one of these four.
What is the difference between supply risk and demand risk?
Supply risk is upstream: a supplier, component or sub-tier source failing to deliver. Demand risk is downstream: demand shifting, forecasts missing, or buyer concentration leaving you over or under-committed. One is about inputs failing, the other about outputs and signals decoupling from reality.
How do you assess supply chain risk across these types?
Score each supplier, process and dependency against the risks that apply to it, on a consistent scale, so you can compare exposure across the network and rank where to act first. Then keep it current: supplier health, demand volatility and geopolitical exposure move constantly, so assessment should be continuous rather than an annual audit.
See Causal AI applied to your supply chain.
A structured, 45-minute session with a senior solutions architect.
Request a Demo
Related insights

Sub-Tier Supply Chain Visibility: Seeing Beyond Tier 1
Most disruption starts in the suppliers you can't see. This is what sub-tier supply chain visibility means, why seeing beyond Tier 1 is so hard, and a practical way to map the Tier 2 and Tier 3 dependencies that actually threaten you.

Supply Chain Risk Assessment: A Step-by-Step Framework
A supply chain risk assessment only drives decisions if it's built on a repeatable framework. This is the six-step method: map your network, identify and score risks, build a risk matrix, assign mitigation, and keep it current.


