Subcontractor Risk Assessments Official Use Only Subcontractor Risk Assessments OFFICIAL USE ONLY May be exempt from public release under the Freedom of Information Act (5 U.S.C. 552), exemption number and category - Exemption 5 – Privileged Information Department of Energy review required before public release Name/Org: James Burton/10222 Date: 9/24/2018 Guidance (if applicable) N/A Supply Chain Risk Management (SCRM) Official Use Only Official Use Only
Subcontractor Risk Assessments Official Use Only Subcontractor Risk Assessments A Subcontractor Risk Assessment (SRA) is designed to help uncover subcontractor risks in a way that is: Fast Efficient Comprehensive Sandia uses internal feedback and audits, along with the best commercially available supplier screening tools, big data tools, and supplier analytics and metrics in SRAs. Official Use Only Official Use Only
Eight Risk Subcategories roll up into one Comprehensive Risk Rating Subcategories of a Subcontractor Risk Assessment Subcontractor Risk Assessments Include an Overall Risk Rating and Eight Subcategory Risk Ratings Eight Risk Subcategories roll up into one Comprehensive Risk Rating Official Use Only
Risk Analysis Tools – Restricted Party Screening Official Use Only Risk Analysis Tools – Restricted Party Screening Restricted Party Screening is checked using the Visual Compliance tool from eCustoms, a provider of export, trade, and OFAC compliance solutions. Daily batch screening is performed on each subcontractor. Restricted Lists consulted include: Debarments, Export-related, Sanctions Programs (e.g. OFAC, U.N.), Restricted/Wanted Lists. For this subcontractor, an alert was discovered with an associated debarment by the Defense Logistics Agency. Official Use Only Official Use Only
Risk Analysis Tools – Financial Health Sample Company, Inc. Risk Analysis Tools – Financial Health Financial Health of Subcontractors is checked at the beginning of subcontracts and periodically on subcontract renewals. Financial health is monitored using internal contract auditing (ICAS) results, Dun & Bradstreet Supplier Risk Manager, and other big data analysis tools. Primary Financial Health Indicators SSI = Supplier Stability Index (low score is good) Predicts a supplier ceasing operations SER = Supplier Evaluation Risk Rating (low score is good) Predicts Business Health Risk Paydex = A D&B payments indicator (high score is good) Assesses historical payment performance Failure Score aka Financial Stress Score (high score is good) Assess financial stress CCS Class = Commercial Credit Score Class Assesses likelihood of payment delinquency Official Use Only
Risk Analysis Tools – Risk Events Sample Company, Inc. Risk Analysis Tools – Risk Events Risk Events/Indicators are checked using Dun & Bradstreet Supplier Risk Manager to see if a subcontractor has any financial, legal, or government flags for things such as Liens, Criminal proceedings, or is included on certain excluded parties lists. For this subcontractor, risk flags were found for: Liens/Claims Family EPA and OSHA findings Official Use Only
Official Use Only
Risk Analysis Tools – Counterfeit Indicators Sample Company, Inc. Risk Analysis Tools – Counterfeit Indicators Counterfeit Indicators from subcontractors are checked using internal records (Suspect Counterfeit Program), Dun & Bradstreet Tier N analysis, data from the Government Industry Data Exchange Program (GIDEP), or data from the Electronic Resellers Association International (ERAI). For this subcontractor, internal Sandia records show a Suspect Counterfeit part issued at Sandia, case #2016003, in which an item sent to Sample Company, Inc for a repair was in turn shipped out to a 3rd party for the work to be performed. When the part was returned to Sandia, an attached valve assembly was found to be suspect, turned into Sandia’s S/CI team, and ultimately to the Inspector General. Official Use Only
Risk Analysis Tools – Foreign Corporate Linkages Sample Company, Inc. Risk Analysis Tools – Foreign Corporate Linkages Foreign Ownership is checked using a Corporate Linkage Feature in Dun & Bradstreet Supplier Risk Manager. For this subcontractor, The branch company in Albuquerque and its parent in Basking Ridge, NJ are ultimately owned by a Global Ultimate in Japan. Sample Company, Global Ultimate Sample Company, Parent Sample Company, Inc Official Use Only
Risk Analysis Tools – Non-US Labor Risk at Domestic Sites Sample Company, Inc. Risk Analysis Tools – Non-US Labor Risk at Domestic Sites Non-US Labor Risk at Domestic Sites is indicated using H-1B and Green Card data that is publicly available from United States Department of Labor web sites. For this subcontractor, Some foreign workers at domestic sites. Some foreign workers from Sandia Sensitive countries (India, China) Official Use Only
Tier 2 and Tier 3 Country Analysis Sample Company, Inc Tier 2 and Tier 3 Country Analysis 345 domestic Tier-2 suppliers High risk country Tier-2 suppliers from China, India and Israel. Tier 3 becomes more problematic with a major increase in foreign companies China, India, Pakistan, Saudi Arabia, Israel, Ukraine, Russia, Taiwan Official Use Only
Elements of Subcontractor Risk Assessment Official Use Only Elements of Subcontractor Risk Assessment 76 Data Elements roll up into Eight Risk Subcategories Non-US Labor Restricted Party Screening Lower Tier Supply Chain Financial Health Risk Events/Indicators Past Performance Currently researching additional, new data elements... Official Use Only Official Use Only
Risk + Action Risk Mitigation Recommendations for Buyers & Users including contract language Engineered holds in purchasing system for highest risk suppliers Official Use Only
Risk and Action: What We Do With the Results? Risk Mitigation Language in Subcontracts Risk Documentation in ERP System Official Use Only
? ? ? ? ? ? QUESTIONS Supply Chain Risk Management (SCRM) Jburton@sandia.gov or SCRM_DS@sandia.gov Official Use Only