The Approved Supplier That Was No Longer Assured
A critical supplier can remain listed as approved while the evidence, actions and review status behind that decision quietly drift out of date.
Synthetic scenario. Illustrative only — does not describe any real organisation, supplier, patient, programme or event.
Scenario at a glance
- Industry context
- Aerospace and defence supplier assurance
- Primary persona
- Head of Supplier Assurance
- Trigger event
- A customer challenge and supplier tooling disruption reveal that a previous continuation decision relied on expired evidence, an unreviewed supplier change and open remediation actions.
- Assurance failure type
- Critical supplier assurance gap; stale evidence; supplier change not reviewed; action closure without linked evidence.
- Scenario shape
- Weak signal → missed ownership → unclosed action → missing evidence → assurance failure → business impact
What happened
Northmere Aerospace & Defence Ltd is a fictional mid-sized aerospace and defence manufacturer delivering a controlled-technology subsystem into a prime contractor programme. It has supplier assurance, supplier quality, cyber supply-chain, export-control, procurement and programme assurance teams.
A tier-2 specialist supplier, Kestrel Embedded Systems Ltd, had been approved eighteen months earlier after submitting supplier quality evidence, certification records, a security questionnaire, an access-control attestation, a controlled-data handling acknowledgement and software release process documentation.
Since approval, three assurance-relevant changes occurred.
First, Kestrel moved part of its test environment to a hosted tooling provider. The change was mentioned in a procurement email thread, but it was not logged as a supplier change requiring cyber, export-control, resilience or programme assurance review.
Second, Kestrel’s cyber evidence became stale. The latest access-control attestation and privileged-access review were overdue, and a cyber finding relating to MFA coverage and supplier-admin access sat between Cyber Supply Chain and Supplier Assurance.
Third, Supplier Quality had an open corrective action for inconsistent release-evidence packs. The action was later marked closed after the supplier confirmed its process had been updated, but sample evidence had not been uploaded or reviewed.
A programme gate arrived. The supplier appeared as approved, and the programme review showed no major blockers. The pack did not clearly show that cyber evidence had expired, the hosted tooling change had not been reviewed, and the release-evidence corrective action had been closed without linked closure evidence.
Two weeks later, Kestrel disclosed that a tooling disruption and access-control issue affected its ability to prove the integrity and completeness of several test artefacts. The customer asked Northmere to show which work packages were affected, which obligations applied, what evidence supported the supplier decision, which actions were open, and whether the supplier remained suitable for the programme milestone.
The issue was not that Northmere had no supplier process. The issue was that supplier approval status had become disconnected from current evidence, open findings, supplier changes and decision-ready assurance.
What it cost
Operational impact
The programme team had to delay the milestone while affected test artefacts and work packages were revalidated. Engineering, quality, cyber, export-control, procurement and programme teams were diverted into an emergency supplier review and manual evidence reconstruction.
Governance impact
The programme board challenged whether previous supplier assurance reporting could be relied on. The organisation had to distinguish between suppliers that were approved, conditionally approved, evidenced, overdue or assurance-qualified.
Customer and audit impact
The customer challenged the evidence supporting the supplier decision. The organisation faced additional burden around supplier quality evidence, cyber supply-chain review, controlled-data handling and programme gate assurance.
Commercial impact
The delay created additional supplier oversight work, potential contractual exposure and renewed scrutiny over whether the supplier relationship could continue without qualification.
Remediation impact
Closed actions had to be reopened. Supplier change review, cyber remediation, evidence refresh and stronger closure criteria were introduced under pressure.
Where the assurance chain broke
| Broken link | What was missing | Why it mattered |
|---|---|---|
| Supplier criticality | Programme criticality was understood locally but not reflected in the central supplier assurance view. | Assurance effort was not focused on the supplier whose work package, controlled-data exposure and release evidence mattered most. |
| Supplier change | The hosted tooling change was noted in email but not captured as an assurance-relevant change. | The change should have triggered cyber, export-control, resilience and programme assurance review. |
| Obligation mapping | Flowed-down obligations were not connected to the current evidence needed to support them. | The team could not quickly show which quality, cyber, controlled-data and programme obligations were supported by current evidence. |
| Ownership | Cyber, quality, supplier assurance and programme teams each held part of the story. | No single chain showed who owned each open action or evidence gap. |
| Action closure | The release-evidence corrective action was closed based on supplier confirmation. | Closure became a status update, not proof that remediation had been evidenced and reviewed. |
| Evidence | Evidence was spread across supplier folders, email, QMS records, cyber tools and shared drives. | The organisation could not quickly prove what had been requested, received, reviewed, expired or used to support the decision. |
| Assurance decision | The continuation decision relied on approval status rather than a connected evidence trail. | Leadership could not confidently show what was known, owned, evidenced, reviewed or still unresolved. |
What should have been visible earlier
Known signals
- Critical programme dependency on a low-spend but high-impact supplier.
- Controlled technical data and supplier access exposure.
- Hosted tooling change affecting test evidence and supplier operations.
- Expired cyber evidence and access-control attestation.
- Open cyber finding related to MFA coverage and privileged access.
- Open supplier quality corrective action related to release-evidence packs.
- Programme gate approaching with unresolved supplier assurance dependencies.
Unowned actions
- Supplier change review for hosted tooling migration.
- Cyber remediation and evidence refresh.
- Supplier quality corrective action closure evidence.
- Export-control or controlled-data impact review.
- Programme decision-pack review for evidence sufficiency.
- Evidence review ownership separated from action ownership.
Stale or missing evidence
- Cyber questionnaire and access-control attestation not refreshed.
- Prior supplier audit pack still treated as decision-ready evidence.
- Controlled-data handling acknowledgement not reviewed after tooling change.
- Release-evidence process update asserted but not supported by sample evidence.
- Supplier approval status not updated to reflect assurance qualification.
Missing review points
- No evidence gate before corrective action closure.
- No supplier change assurance trigger.
- No distinction between approved, approved with open findings, evidence overdue and assurance-qualified.
- No programme gate check showing supplier evidence currency and open remediation.
- No formal review of whether action closure changed the underlying assurance position.
How STREAM® Cloud could help
Make the issue visible earlier
STREAM® Cloud could help create structured records for the supplier, programme scope, flowed-down obligations, evidence items, supplier findings, remediation actions, supplier changes, exceptions and assurance decisions.
Clarify ownership
STREAM® Cloud could help assign named owners across supplier assurance, supplier quality, cyber supply-chain, export-control, programme assurance, evidence review and leadership assurance.
Track remediation
STREAM® Cloud could help track due dates, action status, overdue items, dependencies, review status, exception status and escalation status for supplier findings and corrective actions.
Link evidence to decisions
STREAM® Cloud could help link evidence directly to obligations, findings, actions, supplier changes and assurance decisions, including audit reports, certification evidence, cyber questionnaires, attestations, review notes and exception approvals.
Show what is overdue or unevidenced
STREAM® Cloud could help review forums see which supplier actions are overdue, partially evidenced, expired, awaiting review or linked to upcoming programme decisions.
Support decision-ready assurance
STREAM® Cloud could help distinguish supplier approval from current, evidenced and assurance-ready supplier status.
Reduce manual reconstruction
STREAM® Cloud could help reduce the manual burden of reconstructing the story after a supplier issue by keeping linked records, status changes, evidence references, review notes and decision rationale in one structured chain.
Related use case
Supplier Assurance
Want to see how STREAM® Cloud supports evidence-backed assurance?
STREAM® Cloud helps teams connect records, actions, evidence, review status and assurance outputs in a configurable workspace.