How to Run a Supply Chain Risk Assessment on Your Current BOM

Laura V. Garcia
|  Created: October 7, 2026
At a Glance

Learn how to run a supply chain risk assessment on your BOM in six steps. Flag high-risk parts, read lifecycle alerts, and build a response workflow.

Go Deeper with AI:
How to Run a Supply Chain Risk Assessment on Your Current BOM

Nearly two-thirds of electronics manufacturers report limited component and material availability or extended lead times. Importantly, none describe current conditions as readily available with excess supply, underscoring that supply risk remains widespread. 

That risk shows up one part at a time. A part quietly discontinued, a distributor suddenly out of stock, a price that jumped without warning. BOMs are full of surprises that derail a build and eat into margins.

The fix is a repeatable process, backed by live supply chain data, that finds and mitigates risk before it reaches the schedule. This guide walks procurement and engineering through six steps to assess the BOM in front of you and shows how a connected BOM environment can help teams assess risk faster, respond more consistently, and stay agile when supply conditions change.

Key Takeaways

  • A risk assessment is only as current as the BOM data behind it, which is why a connected, live-updating source is preferable to a stale spreadsheet.
  • Flag single-source, near-EOL, long-lead-time, low-inventory-coverage, and price-volatile parts, but clean and normalize the data first, or the analysis is built on noise.
  • Lifecycle status and supply status are different things. Active, NRND, last-time-buy, and obsolete describe a part’s lifecycle, while allocation is a temporary supply constraint. Each calls for a different response.
  • Severity should reflect sourcing options, design reach, and production stage, with responsibilities split between procurement and engineering and one named owner per flagged part.
  • Pre-approved alternates and a documented decision trail turn a response workflow from reactive scrambling into a repeatable, auditable habit.

Step 1: Get Your BOM Into One Connected Place

Risk isn’t static; your reports shouldn’t be either.

A spreadsheet pulled last month is already wrong. Parts have moved, prices have shifted, and lifecycle statuses have changed, yet nothing in the file reflects that. Every hour between the export and the analysis is an hour of drift nobody’s accounting for.

The fix is connecting the BOM to a live data source instead of checking distributor sites part by part. Pull current pricing, stock, and lifecycle status directly into the BOM so the numbers update on their own. In practice, that means moving off a hand-maintained spreadsheet and into a cloud-based BOM tool with an up-to-date connection to manufacturer and distributor data.

This is the step teams skip, and it’s the one that makes everything after it useful or a waste of time. 

Managing a BOM well starts with centralizing it, not with the analysis itself. Once the BOM lives in a shared environment, procurement and engineering stop working from different versions of the same list.

Step 2: Run BOM Analysis to Flag High-Risk Components

With the BOM centralized and live, scan it for the parts actually worth worrying about:

  • Single-source parts: no qualified second supplier, so any disruption at that one source has nowhere to fall back to.
  • Parts nearing EOL: manufacturer discontinuation notices or last-time-buy windows on the horizon, even if the part is still available today.
  • Long-lead-time items: anything stretching well past your typical build schedule, which turns a routine order into a scheduling risk.
  • Low inventory coverage: parts where available stock and open orders don't cover the forecasted build schedule. Pair your own on-hand and open-order data with live market stock to see the gap early, while there's still time to act.
  • Price volatility: line items with recent or trending cost increases. Individually small increases compound across a full BOM, eroding margin before anyone notices.

These flags matter most in combination. A single-source part that's also nearing EOL and quoted at long lead times is a very different problem from one that trips only a single flag.

Before trusting the scan, clean the data. Duplicate entries, inconsistent manufacturer part numbers, and mismatched formatting will skew the analysis. BOM normalization isn’t a separate chore; it’s what makes this step trustworthy.

Step 3: Interpret Shortage and EOL Alerts Correctly

Not every alert means the same thing, or requires the same level of response. 

Active, not recommended for new designs (NRND), last-time-buy, and obsolete each describe a different point in a part’s lifecycle and should trigger a different action:

  • Active: The manufacturer is still producing the part. Lifecycle risk is generally low, but supply risk isn’t zero (allocation, back-orders, long lead times). Keep checking stock and lead times against your build schedule.
  • NRND: The manufacturer is steering new designs away from the part. You can still buy it and existing designs can keep building, but it's often the first sign a discontinuation is coming. Keep it out of new designs, find every existing design that uses it, and qualify an alternate now. 
  • Last-time-buy (LTB): Fixed window to place a final order. Compare on-hand stock and open orders against forecast and service needs, place the order before the deadline, and start qualifying an alternate or planning a redesign in parallel.
  • Obsolete: Window has closed. Tally remaining stock against remaining builds. If coverage runs out, move to a pre-approved alternate or redesign. The part should not appear in any new design.
  • Allocation: This is a different signal; a temporary supply-and-demand imbalance, not a lifecycle change. The response is to manage coverage: check inventory and open orders, confirm future supply, look for additional sources if needed, and decide whether a temporary bridge buy or alternate is required.

Urgency must also match runway. An EOL notice with an 18-month last-time-buy window is not the same problem as one with 60 days left. But don't count on a formal notice arriving at all. In 2025, more than half of electronic component EOL events came without a manufacturer Product Change Notification (PCN).

Step 4: Assign Ownership and Severity to BOM Risk

Once a part is flagged, someone needs to own what happens next.

A workable split: procurement flags the part and surfaces the supply-side facts (lead time, pricing, source count); engineering assesses what it actually touches in the design. That assessment depends on knowing everywhere the part is used, down to the specific board revision. Name one owner for each flagged part, even when both teams contribute, so the response doesn't stall between them.

Weight severity by three things:

  • Sourcing: single-sourced or qualified alternates available?
  • Reach: how many active designs use it?
  • Stage: how close is each design to manufacturing?

Use those factors to assign a simple severity tier: critical, worth watching, or safe to ignore for now. The exact thresholds will vary by organization, but a part with limited sourcing options, broad design exposure, and a production-stage dependency deserves faster action than a part with multiple sources used only in an early prototype.

For example, a single-sourced part in one early prototype is worth watching. The same part shipping in five products is critical, because the time and options available to respond shrink as a design moves closer to production.

Document the tier assignment so the same criteria can be applied the next time a similar part is flagged.

Step 5: Build the Response Workflow

Severity only matters if it routes to a different response.

For parts you already know are risky, define alternates before you need them. Pre-approved alternates in the part library turn a flagged risk into “here’s what we already approved.” If no approved alternate exists, the response may require a cross-functional review to qualify a new source, redesign around a different component, or secure enough inventory to bridge the gap.

When a flagged item is critical, or a swap would change the schematic or layout, route it through a formal change and approval step so engineering signs off before anything moves. AI-powered change order impact analysis can help by predicting how a proposed change affects components, assemblies, timelines, and designs, giving reviewers a clear picture of the change’s reach instead of assembling one by hand. Structured design reviews then keep the decision moving instead of stalling in email. Clean like-for-like swaps with matching specs should move fast without the full redesign process.

Forcing every swap through the heaviest process available doesn't make the BOM safer; it just trains the team to ignore the process when speed actually matters.

Whichever path it takes, document the decision: what was flagged, what was considered, what was chosen, and who approved it. That record turns the next audit or retrospective into a non-event.

Say a board-to-board connector is flagged NRND. A where-used check shows it in three designs: one in prototype, one two months from release, and one already shipping, and no qualified alternate exists. The shipping product and the lack of an alternate make this critical. Because connectors are tied to footprint and enclosure fit, even a close match may need a layout review, so the prototype should switch now while it costs almost nothing, and the near-release design needs the swap decided before it locks. Procurement sizes remaining coverage, engineering starts qualifying an alternate, and the decision and its approver are recorded for next time.

Step 6: Make It Recurring, Not One-Time

A risk assessment run once is already stale by the next distributor update. Tie the cadence to events, not the calendar, instead of relying on an annual review that misses everything in between.

In practice, that means re-running the check whenever a design is released, a BOM revision is created, a part's lifecycle or stock status changes, and before you commit to a purchase order or build. A light periodic sweep still has a place as a safety net, but it shouldn't be your main line of defense.

This is what BOM health looks like once it’s routine: a steady, low-effort check built into how the team already works.

This guide starts with one BOM, but the same event-driven cadence scales across every active design. For that bigger picture, see Real-Time BOM Intelligence: What Risk Monitoring Looks Like Across All Your Active BOMs.

Quick-Reference Checklist

  • Centralize the BOM with a live data connection.
  • Clean and normalize part data before analyzing it.
  • Flag single-source, near-EOL, long-lead-time, low-inventory-coverage, and price-volatile parts.
  • Read status correctly: NRND, last-time-buy, and obsolete are lifecycle codes; allocation is a supply constraint.
  • Assign clear ownership and a severity tier based on sourcing, reach, and stage.
  • Pre-approve alternates, route critical or design-impacting changes through approval, and document every decision.
  • Run the check on a recurring cadence.

Run This Process Without Leaving Your Design Environment

Every step gets faster with the right platform underneath it. Altium Agile Teams brings up-to-date component pricing, availability, and lifecycle status directly into your BOM, so procurement and engineering work from the same numbers in the same place instead of reconciling exports after the fact.

  • Steps 1–2: Altium Agile Teams centralizes your BOM in a cloud portal with the latest pricing, availability, and lifecycle data from Octopart and IHS Markit, with SiliconExpert and Z2Data integrations available. BOM normalization and cleanup happen in the same place.
  • Step 3: Lifecycle status is surfaced on every line item, and lifecycle controls help keep obsolete or draft items out of releases.
  • Step 4: Where-used tracking down to the specific board revision shows exactly which designs a flagged part touches. Role-based permissions control who can view, edit, and approve.
  • Step 5: Alternates are defined proactively in a shared library. Configurable workflows and structured design reviews with sign-offs route critical or design-impacting changes to engineering approval while letting clean like-for-like swaps move without friction. AI-powered change order impact analysis gives reviewers a predicted impact before sign-off. 
  • Step 6: Audit trails and event logs record changes and actions automatically. Review comments and tasks capture the reasoning, so the decision record builds as the team works. Global workspace access and single sign-on let distributed teams run the same event-driven checks without losing governance.

Centralize your BOM, connect it to up-to-date supply chain data, and build a response workflow your whole team can trust.

Learn more about Altium Agile Teams →

About Author

About Author

Laura V. Garcia is a freelance supply chain and procurement writer and a one-time Editor-in-Chief of Procurement magazine.A former Procurement Manager with over 20 years of industry experience, Laura understands well the realities, nuances and complexities behind meeting the five R’s of procurement and likes to focus on the "how," writing about risk and resilience and leveraging developing technologies and digital solutions to deliver value.When she’s not writing, Laura enjoys facilitating solutions-based, forward-thinking discussions that help highlight some of the good going on in procurement because the world needs stronger, more responsible supply chains.

Related Resources

Related Technical Documentation

Back to Home
Thank you, you are now subscribed to updates.