The bottom line
Your supplier scorecard measures the companies that invoice you — tier-1. It cannot see the coating house behind three of them. Tier-2 data is missing not because a pipeline was not built, but because nobody has agreed to send it, there is no contractual reason to, and there is no shared key to match it if they did. A lakehouse will not make a supplier disclose anything; it holds the answers you obtain — through narrow disclosure clauses at renewal, critical-path mapping, external risk data and inference from your own BOM and lead-time drift. Scope to the parts that can stop a line, and you get a shortlist in the low tens, not twelve thousand answers.
In This Article
The scorecard reads 98% — then the line stops
A pattern that repeats across the manufacturing estates I work in. The supplier scorecard reads above 98% on-time-in-full for the quarter. Then a line stops for a week and a half, because a coating house in another country — a business the manufacturer has no contract with, no record of and could not have named — loses a furnace. That coating house serves three of the tier-1 suppliers on the scorecard.
The dashboard is not wrong. It measures exactly what it was built to measure: the behaviour of the companies that invoice you.
Here is the part most vendors skip. Tier-2 data is missing not because the pipeline has not been built, but because nobody has agreed to send it, there is no contractual reason for them to, and if they did there would be no reliable way to match it to what you already hold.
What multi-tier supply chain visibility actually means
Multi-tier supply chain visibility is knowing which sub-tier companies and physical sites your critical components depend on, beyond the tier-1 suppliers you contract with directly. Tier-1 is who invoices you; the risk often lives two or three levels up, at a site you have never heard of.
The published research matches what I see in estates. In McKinsey's 2021 survey of senior supply chain executives, just under half said they understood the location of their tier-one suppliers and the key risks those suppliers face — but only 2% could make the same claim about suppliers in the third tier and beyond.
Why your tier-1 suppliers will not tell you who their suppliers are
Their sourcing is their margin. If you know the sub-component in your assembly costs your supplier USD 4.20 from a plant in Gujarat, you know roughly their gross margin on you. Disintermediation is a live fear, not a paranoid one — procurement organisations do go direct once they know who the real maker is.
There is no contractual obligation, either. The master supply agreement you signed years ago covers quality, delivery, audit and insurance, and says nothing about disclosing sub-tier sources. And frequently the tier-1 does not know — a supplier who buys a finished sub-assembly is in the same position you are, one level down. Add confidentiality terms in their own contracts, and the fact that whatever they do send arrives as a PDF that is accurate on the day and stale by the quarter when they dual-source a part.
The identifier problem nobody demonstrates in the sales meeting
Suppose the disclosure arrives: a name, a country and possibly a city for each sub-tier company. There is usually no shared key across tiers to match it against what you hold.
It is worse than a missing key, because the entity you care about is not the entity in the data. Risk sits at a site — the plant with the furnace, in the flood plain, on the coast — not at the corporate name on the invoice. Resolving named companies to physical sites, across tiers, is a modelling and stewardship exercise, not an import. That is what makes a "12-week multi-tier rollout" implausible.
Four practical routes to partial visibility
None gives you the full map. Together, on a scoped set of parts, they give you enough to act.
| Route | What it gets you | What it costs | Honest limit |
|---|---|---|---|
| Contractual disclosure at renewal | Named sub-tier sources for parts you specify | Negotiating capital, at renewal only | Point-in-time; enforcement is weak; you must be willing to trade something |
| Critical-path mapping only | Deep visibility on 20–40 components | 6–12 weeks of procurement and engineering time | Everything outside scope stays dark — and something outside scope will bite |
| External risk-data providers | Broad coverage, event alerting, corporate hierarchies | Annual subscription, five to six figures USD | Coverage of your specific sub-tier links is thin; inferred links are not verified |
| Inference from BOM and lead-time anomalies | Early signal without supplier co-operation | Analytics effort on data you already own | Signals correlation, not causation — tells you something is wrong, not who |
Contractual disclosure is the only route producing authoritative data, and it opens only at renewal or new-part introduction. The clause that works is narrow: for parts on a named critical list, disclose the manufacturing site and any single-source sub-tier dependency, notify on change, permit an audit of that claim. External providers are useful and oversold in the same breath — good at what is publicly recorded (ownership, distress, sanctions, hazard by location), weak on verified part-level links. Inference from your own data needs no permission at all.
Scope to the components that can stop a line
The instinct to map the whole supplier base is why most of these programmes stall. A mid-market manufacturer with 900 suppliers and 12,000 active part numbers does not need 12,000 answers. Screen on five questions and rank:
- Does this part have an alternate source qualified today — not a name on a list?
- What is the requalification time if the current source disappeared: under six weeks, or over six months?
- Is the part written into a customer contract or a regulatory approval, so you cannot substitute unilaterally?
- What revenue is exposed if the line using it stops for two weeks?
- Does it involve a process with few global operators — specialist coating, heat treatment, a single resin grade, a custom die?
In the estates I have worked in, that screen reduces thousands of part numbers to a shortlist in the low tens. That is a conversation procurement can actually have with a supplier, and a data model you can actually maintain.
What a lakehouse genuinely contributes
Microsoft Fabric will not make a supplier disclose anything. What it does is hold the answers you obtain in a form that survives staff turnover and can be queried against operational data.
That means a supplier master with hierarchy — a governed table of supplier sites with geocoordinates, parent legal entity and ownership, plus a relationship table modelling supplies-to links with effective-from and effective-to dates. A risk fact table — one row per site, per risk type, per assessment date (financial, geographic, single-source, geopolitical, quality). Geospatial concentration analysis, so a cluster of sites in one flood plain becomes visible instead of anecdotal.
And the part that pays for itself without supplier co-operation: anomaly detection on tier-1 behaviour as a proxy. Lead-time drift, widening delivery variance, price movement and partial shipments usually move before on-time-in-full does, because a supplier absorbs upstream pressure internally until it cannot. Unify, predict, act — applied to a problem where the unify step is the hard one.
What regulation is forcing — and what it is not
Compliance is the strongest lever procurement has for prising sub-tier data loose, so be precise about what is actually in force as of August 2026.
| Regime | Catches | Applies from | Sub-tier demand |
|---|---|---|---|
| EU CSDDD — Directive (EU) 2026/470 | EU firms >5,000 staff & €1.5bn turnover; non-EU >€1.5bn EU turnover | 26-Jul-2029 (transposition 2028) | Risk-based scoping, not full mapping |
| CSRD (Omnibus I) | EU firms 1,000+ staff, turnover >€450m | FY starting 2027 | Disclosure, not tracing |
| German LkSG | 1,000+ staff in Germany | In force; interim until CSDDD | Direct suppliers as standard |
| EU Deforestation Regulation | Operators placing listed commodities on the EU market | 30-Dec-2026 (micro/small 2027) | Genuine upstream traceability to geolocation |
| EU Forced Labour Regulation (EU) 2024/3015 | Products placed on or exported from the EU market | 14-Dec-2027 | Prohibition/enforcement, not a due-diligence mandate |
| UK Modern Slavery Act 2015, s54 | UK-connected turnover ≥ £36m | In force | Transparency statement only |
The CSDDD detail that matters is what the Omnibus I amendments did not do: the final text does not require exhaustive mapping of every tier. It sets a risk-based scoping exercise using reasonably available information, and permits prioritisation towards direct business partners. Germany's LkSG limits risk analysis to direct suppliers as standard; obligations deeper are triggered only by substantiated knowledge. The direction of travel is risk-based prioritisation, not total mapping — if a platform pitch tells you the law now requires you to map your whole n-tier chain, it is overstating the position.
Where this breaks, and what it does not fix
Coverage claims will not survive contact with your parts list — every multi-tier platform demonstrates well on documented electronics and automotive parts, where trade data is rich, and thinly on everything else. Disclosure decays: a sub-tier list obtained at renewal is accurate the day it is signed. Knowing the risk does not reduce it — discovering that a sole-source coating house sits behind 40% of your assemblies gives you a decision (qualify an alternate, hold buffer, redesign the part), and each costs money and takes months.
Inference generates false positives — lead-time drift has ordinary explanations, a shipping lane, a customs change, a new planner. Entity resolution is never finished, because suppliers restructure, rename, get acquired and open plants. And your bargaining power is what it is: if you are 2% of a tier-1's revenue, no clause and no platform changes the fact that they can decline.
What to do first
Three questions, answerable this week without buying anything:
- Run the five-question screen above and count the parts that survive it. Get to a number.
- How many master supply agreements renew in the next twelve months, and does any contain a sub-tier disclosure clause?
- Do you hold at least twenty-four months of promised-versus-actual receipt dates per supplier–part? If yes, the lead-time drift analysis can start immediately.
If the first question gives you a number in the low tens, you have a scoped programme. If it gives you a shrug, that is the first piece of work — and it belongs to engineering and procurement, not IT. We build the supplier master, the risk model and the anomaly detection on Microsoft Fabric, OneLake and Power BI, with Power Automate closing the loop into procurement's workflow. We do not sell a multi-tier data feed, because the useful part of that data comes from your contracts, not a subscription.
The first move is not a platform selection — it is the five-question screen, run until you have a number. If it lands in the low tens, you have a programme procurement can actually run. Book a diagnostic with Amit — no slides, no pitch deck, no obligation to proceed. We will help you scope the parts that can stop a line, and build the supplier master and anomaly detection behind them.
Free Assessment
Where does your operation sit on the data maturity curve?
8 questions. 3 minutes. You get a scored breakdown across data infrastructure, analytics readiness, and automation potential — with a specific next step for your industry.