
Nearly every organization we've worked with agrees, at the level of conversation, that supply chain resilience matters. But when we ask 'are you more resilient this year than last year?', we rarely get a clear answer. The reason is simple: unlike cost or service level, which both have a number attached and get tracked on a monthly or quarterly cycle, resilience usually stays a qualitative conversation that happens after a crisis — not a metric monitored before one.
Part of the problem comes from the academic maturity models typically proposed for measuring resilience: five-level, multi-criteria frameworks that are valuable as research but, when an organization needs to decide where to invest next month, are usually too abstract to translate directly into action.
The practical framework we propose maps directly onto the same three layers of resilience — supplier diversity, real-time visibility, and decision speed — and defines one or two measurable metrics for each. For the diversity layer: what percentage of spend on critical items (not all items) has a qualified, pre-approved backup supplier? For the visibility layer: what's the average time to detect a disruption at the second or third tier of the supply chain (not just the direct supplier)? For the decision-speed layer: what's the average gap between detecting a disruption and an actual decision to reallocate capacity or switch suppliers?
The practical starting point is the same ten-item exercise introduced in our three-layer resilience piece: list ten items whose absence would halt a production line or lose a key customer. The difference this time is scoring each item on all three metrics, on a simple 0–2 scale. The result is a small heat map that shows exactly which items, on which layer, carry the biggest gaps — not one generic, unusable number for the whole organization.
A common mistake at this stage is turning the framework into a comprehensive annual checklist filled out once a year — usually right after a crisis — and then forgotten. These metrics earn their value when they hold a fixed slot in the same governance cycle where cost and service level get reviewed — the quarterly S&OP meeting or strategic review — rather than living in a separate, one-off risk workshop.
A second common mistake is trying to push every item to the highest possible score on all three layers. Resilience has a cost, and the investment isn't unlimited. The goal of this framework isn't producing one final number to report upward — it's identifying the two or three biggest gaps to prioritize investment against, and consciously accepting that the remaining gaps are, for now, an acceptable risk.
After one or two quarterly cycles, that same simple heat map lets you ask a much sharper question than 'are we more resilient?': 'is the gap on the items we prioritized three months ago smaller today?' That's what turns resilience from a qualitative post-crisis conversation into a trackable metric before one hits.