DI-MGMT-82255A
Supply Chain Risk Register
The Supply Chain Risk Register records risk identification information and current status on risks affecting products and services from the prime contractor, its suppliers, and subcontractors, enabling Government oversight of risk handling plans.
Approval DateFebruary 3, 2023
AMSC NumberF10375
Preparing Activity11 (AFLCMC/LZS)
Project NumberMGMT-2022-029
OPR—
DTIC ApplicableNo
GIDEP ApplicableYes
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Supply Chain Risk Register will be used to contain the risk identification information and current status on risks relative to the products and services to be provided by the prime contractor, its suppliers, and subcontractors. The Supply Chain Risk Register will provide the Government with information to oversee and proactively develop or execute risk handling plans.
a. This Data Item Description (DID) contains the format, content, and intended use information for the data deliverable resulting from the work task described in the solicitation.
b. This DID supersedes DI-MGMT-82255.
Preparation Instructions
1Reference documents.DI-MGMT-82256A, DoDI 5000.90, DoDM 4140.01, DoD Risk Issue and Opportunity Management Guide Jan 2017. Copies of the DoD Directives can be found at https://www.esd.whs.mil/DD/ while the DoD RIO Management Guide is available at https://acqnotes.com/wp-content/uploads/2017/07/DoD-Risk-Issue-and-Opportunity-Management-Guide-Jan-2017.pdf.
2Format.Government directed electronic format shall be used to the fullest extent possible; however, if none identified, the contractor's electronic format, Microsoft Excel version .xlsx, is acceptable. A Supply Chain Risk Register template can be provided upon request from [email protected]. 3Content.The Supply Chain Risk Register shall include the following:
3.1Contract Information.The contract information section shall identify the following:
3.1.2Contract number and date of award (including the latest modification).
3.1.3Procurement Instrument Identification Number (PIIN).
3.1.4Supplemental Procurement Instrument Identification Number (SPIIN).
3.1.5Delivery order number/Task order number.
3.1.6Contract Line Item Number (CLIN).
3.1.7Date of reporting period.
3.1.8Security classification.
3.1.9USD(R&E) Critical Technology List (if applicable).
3.1.10Distribution statement.
3.1.11Destruction notice.
3.1.12Cybersecurity Maturity Model Certification (CMMC) certification level (Note: DoDI 5000.90 3.4.a).
3.2Risk Information.List of all supply chain risks, segregated into proscribed risk categories of identified and potential supply chain risks, which shall include the following information:
3.2.1Unique Risk Identifier (e.g., 7.2.1).
3.2.2Risk category (i.e., Foreign Ownership, Control or Influence (FOCI), Political and Regulatory, Economic, Environmental, Product Quality and Design, Manufacturing and Supply, Transportation and Distribution, Financial, Compliance, Technology and Cybersecurity, Human Capital, or Infrastructure).
3.2.5National Item Identification Number (NIIN).
3.2.7Brief description of each supply chain risk.
3.2.8Location or risk event.
3.2.9Triggering event or root cause(s).
3.2.10Initial risk assessment.
3.2.11Risk tolerance level (risk appetite) determined by Program Manager.
3.2.12Residual risk levels (acceptable level of risk).
3.2.13Likelihood of occurrence.
3.2.14Potential impact and consequence. Refer to Section 3.3 Risk Reporting Matrix.
3.2.15Risk handling response (e.g., Mitigate: Order safety stock, Avoid: Search for substitute materials).
3.2.16Estimated start and completion dates for risk handling plan.
3.2.17NOTE: Reference DI-MGMT-82256A SCRM Plan for definitions of supply chain risk categories.
3.3Risk Reporting Matrix.Assess supply chain risks in accordance with Chapter 3 of the Department of Defense (DoD) Risk, Issue, and Opportunity Management Guide for Defense Acquisition Programs (hereafter referred to as the Risk Management Guide). Copies of this document are available online at DoD Risk Issue and Opportunity Management Guide Jan 2017.
3.3.1The risk likelihood rating levels and probability of occurrence shall be as follows:1 - Not likely (>1% to <=20%); 2 - Low likelihood (>20% to <=40%); 3 - Likely (>40% to <=60%); 4 - High likelihood (>60% to <=80%); and 5 - Near certainty (>80% to <=99%).
3.3.2The risk consequence levels shall be as follows:1 - Minimal impact; 2 - Minor impact; 3 - Moderate impact; 4 - Significant impact; and 5 - Critical impact.
3.4.1Provide the current status on each risk in the Supply Chain Risk Register.
Schema v3.0Community-maintained · Verify against ASSIST