What is a named supplier site list in supply chain risk management?

A named supplier site list is the register a control tower or insurer keeps of specific, addressable locations tied to a supply chain: this tier-2 plant in Tainan, that distribution center outside Houston, the warehouse in Valencia that holds six weeks of safety stock for one program. Each entry is a physical site, with a lat/long or a street address, because that's the unit a hazard touches.

Most risk teams have a supplier directory. Far fewer have a site list that's actually usable the day a typhoon makes landfall or a river crests. The difference matters more than it sounds like it should.

Site list vs. supplier directory

A supplier directory tells you who you buy from: company name, contract value, category, maybe a risk score from a rating agency. It's built for sourcing decisions, audits, and spend analysis.

A named site list is narrower and more literal. It answers one question: where, physically, does this supplier's work happen? For a single supplier that can mean one site or a dozen, raw material processing here, final assembly there, a regional DC somewhere else entirely. Insurers building schedules of locations for named-storm or flood exposure need the same thing for a different reason: you can't price or monitor exposure you haven't placed on the ground.

The gap shows up the moment an event hits. A directory tells you "Supplier X is affected," which is true of almost nothing and almost everything at once, since most suppliers run multiple sites and only some sit in the damage zone. A site list tells you which specific address does.

What goes into the register

A working named site list usually carries:

  • Site name and a precise address or coordinate pair, not a city or postal code
  • The supplier or tier it belongs to
  • What runs there: manufacturing, warehousing, cross-dock, raw material intake
  • Which programs, SKUs, or policies depend on that site
  • A point of contact, if the list is also used for outreach

What it doesn't need is a risk score baked in. Scoring belongs to a separate layer. The list itself is just an inventory of where things are, kept current enough that when a hazard footprint gets published, someone can run it against the register in minutes rather than spend the afternoon tracking down addresses from old supplier questionnaires and shipping labels.

That currency is the part most organizations underinvest in. A site list built once during supplier onboarding and never revisited drifts. Suppliers move lines between plants, open new facilities, consolidate others. An outdated register gives you false confidence: you check the list, see nothing in the flood zone, and miss the fact that the supplier relocated the relevant line eighteen months ago.

Why event monitoring depends on having one

A site list on its own tells you where things are. It doesn't tell you what just happened to them. For that, the register has to be checked against something live: a flood extent, a quake's shake intensity, a cyclone's wind field, the moment that footprint exists.

This is where a lot of control towers and claims teams get stuck. They have the list. They don't have a fast way to check it against an actual event footprint, so they wait on supplier self-reports or a field adjuster's drive-out, which can take days while allocation calls and claims reserves are already being made upstream.

Supplier Impact Assessment takes that same named site list and checks each entry against the footprint of a flood, quake, or cyclone the moment that footprint exists, returning a per-site call: inside or outside the damage area, visible damage or none. It's the step that turns a static register into something you can act on within hours of the event, instead of days.

If your organization already keeps a named site list, the next question is simply how fast you can run it against the next event, and that's worth a conversation.

Start a pilot

← Back to the blog