DI-MGMT-82256A
Supply Chain Risk Management (SCRM) Plan
The Supply Chain Risk Management (SCRM) Plan defines the contractor's structured SCRM strategy for identifying, assessing, handling, and monitoring supply chain risks associated with the products and services to be provided.
Approval DateFebruary 3, 2023
AMSC NumberF10374
Preparing Activity11 (AFLCMC/LZS)
Project NumberMGMT-2022-030
OPR—
DTIC ApplicableNo
GIDEP ApplicableYes
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Supply Chain Risk Management (SCRM) Plan defines the structured, contractor-proposed SCRM strategy relative to the products and services to be provided by the prime, its suppliers, and subcontractors. The SCRM plan will include a systematic process used to identify, assess, handle, and monitor supply chain risks associated with the product or service to be provided. This information will be used by the Government to maintain oversight of the contractor's holistic SCRM Plan to effectively handle risks within the supply chain.
This Data Item Description (DID) contains the format, content, and intended use information for the data deliverable resulting from the work task described in the solicitation.
This DID supersedes DI-MGMT-82256.
Preparation Instructions
1Reference documents.DI-MGMT-82255A, DoDI 5000.90, DoDM 4140.01. Copies of the DoD Directives can be found at https://www.esd.whs.mil/DD/.
2Format.Government directed electronic format shall be used to the fullest extent possible; however, if none identified, the contractor's electronic format, Microsoft Word version .docx, is acceptable.
3Content.The SCRM plan shall contain the following:
3.1Cover and Title Page.This page shall identify the following:
3.1.1SCRM Plan date of issue;
3.1.2SCRM Plan document number;
3.1.4Contractor's name and address;
3.1.7Security classification;
3.1.8USD(R&E) Critical Technology List (if applicable);
3.1.9Distribution statement; and
3.1.10Destruction notice, if applicable.
3.1.11Cybersecurity Maturity Model Certification (CMMC) certification level (Note: DoDI 5000.90 3.4.a)
3.2Revision Control.The SCRM plan shall contain a list of all revisions identifying the following information:
3.2.1Each revision number;
3.2.2Date of each revision;
3.2.3Pages affected by each revision; and
3.2.4Summary of major content changes.
3.3Table of Contents.The table of contents shall identify each major section title, paragraph number, and starting page number for each major section.
3.4Section Contents.The SCRM Plan shall address each major section identified below:
3.4.1Scope.This section shall include:
3.4.1.1Defining SCRM applicability to the prime and all suppliers, subcontractors, associated integrators, and vendors;
3.4.1.2Defining SCRM as the coordinated, holistic approach, involving all supply chain stakeholders, which identifies, assesses, handles, and monitors supply chain risks associated with weaknesses, vulnerabilities, and threats, addressing both services and products; and
3.4.1.3Defining the supply chain as the linked activities associated with providing materiel from a raw material stage to an end user as a finished product.
3.4.2SCRM Strategy.This section shall provide an overview of the contractor's overall SCRM strategy. It will include how the contractor plans to identify, assess, handle, and monitor risks in the lifecycle supply chain that have the potential to jeopardize the integrity of assets, compromise related intellectual property, disrupt the flow of critical goods or services needed for continued Department of Defense (DoD) operations, unexpectedly drive materiel cost increases to programs, or compromise national security.
3.4.3Responsible Organizational Component.This section shall include:
3.4.3.1Contractor's organizational SCRM construct; and
3.4.3.2Contractor's primary and alternate focal points' contact information to include names, duty titles, addresses, telephone numbers, and email addresses.
3.4.4SCRM Processes and Procedures.This section shall describe:
3.4.4.1Processes for: Protecting products and services throughout the entire lifecycle; identifying, assessing, handling, and monitoring potential supply chain threats, weaknesses, and vulnerabilities; and analyzing identified potential disruptions for the program's supply chain, suppliers, products, technologies, and services; and
3.4.4.2Process for revising the SCRM Plan in accordance with government guidelines during the lifecycle of the program, and for providing a copy of the SCRM plan to the Government Product Support Manager or Program Manager.
3.4.5Supply Chain Risk Identification.This section shall describe in detail:
3.4.5.1Processes and tools utilized to identify supply chain risks and associated root causes as early as possible;
3.4.5.2Intelligence-based and counter-intelligence-based techniques and commercial business tradecrafts employed to uncover and map supplier networks; and
3.4.5.3Process for communicating supply chain risks to affected stakeholders and the Government Program Support Manager or Program Manager.
3.4.6Supply Chain Risk Assessment.This section shall include:
3.4.6.1Process to scan the contractor's supply chain network (to include sub-tier suppliers), applying risk categories, to identify and assess supply chain risks that could impact the Government's program;
3.4.6.2Contractor's methodology for assessing all vendors or sources of supply to identify potential threats and vulnerabilities;
3.4.6.3Processes for analyzing root causes and assigning a risk rating by assessing the likelihood of occurrence; and determining severity of impact to the contractor's supply chain.As proscribed in DoDM 4140.01 Supply Chain Materiel Management Policy, SCRM owners assess supply chain risk by determining the severity of impacts to 1.) integrity of goods and services; 2.) assurance of supply; and 3.) economic efficiency to the contractor's supply chain.
Processes for assessing SCRM risk impacts are specific to risks originating from the supply chain and do not encompass all enterprise or program risks. However, successful supply chain risk management does enable Program Managers to proactively manage risks associated with cost (economic efficiency), schedule (assurance of supply), and performance (integrity of products or services).
3.4.6.4Process to focus attention on critical risks and document in the Supply Chain Risk Register; and
3.4.6.5Process to report the Supply Chain Risk Register to the Government Product Support Manager or Program Manager on a quarterly basis.
3.4.7Supply Chain Risk Handling.This section shall include:
3.4.7.1Supply chain risk handling plans to combat identified and potential supply chain risks.It shall include:
3.4.7.1.1A descriptive title for each supply chain risk;
3.4.7.1.2Root cause or trigger of each risk;
3.4.7.1.3Possible risk handling plan to alleviate each risk; and
3.4.7.1.4Description of events and activities intended to accept, avoid, mitigate, or transfer the risk, success criteria for each planned event, and residual risk rating (acceptable level of risk). Reference DI-MGMT-82255A Supply Chain Risk Register.
3.4.7.2Methodology to prioritize potential supply chain risks;
3.4.7.3Process to capture risks and associated details, relative to the products and services to be provided, in a risk register.
3.4.8Supply Chain Risk Monitoring.This section shall include:
3.4.8.1Process for the persistent and comprehensive monitoring and re-evaluation of supply chain risks and corresponding risk handling plans;
3.4.8.2Process for reporting risk monitoring information to the Government Product Support Manager or Program Manager quarterly; and
3.4.8.3The Supply Chain Risk Register will include a unique risk identifier, risk category and description, risk rating, risk handling response, responsible POC, expiration date, and current status. Reference DI-MGMT-82255A Supply Chain Risk Register.
3.4.9SCRM Training.This section shall describe in detail:
3.4.9.1SCRM training that promotes an understanding of the basics of SCRM as a practice, the nature of risks facing supply chains, and the recommended approaches;
3.4.9.2SCRM-related course numbers, titles, sources, and descriptions;
3.4.9.3Number of personnel trained in each of the aforementioned courses; and
3.4.9.4Duty titles of personnel trained.
Schema v3.0Community-maintained · Verify against ASSIST