Redundancy is not the same as resilience
Organisations often respond to supply risk by adding another manufacturer or another geography. That can help, but it can also add transfer cost, quality complexity, fragmented volume, and more interfaces without reducing the underlying exposure.
The first question is not how many suppliers exist. It is how failure travels through the portfolio. A single API, analytical method, packaging component, release dependency, forecast assumption, or market-specific specification can remain the true point of concentration even when two finished-dose sites are available.
Map fragility at product level
Resilience should be designed product by product. Examine technical substitutability, lead times, minimum batches, shelf life, demand volatility, regulatory change burden, margin headroom, partner responsiveness, inventory visibility, and the time required to qualify an alternative.
This produces a differentiated answer. Some products justify dual sourcing. Others are better protected through specification strategy, inventory policy, contractual controls, demand shaping, transfer-ready documentation, or a planned exit before risk becomes loss.
Govern the signals before the disruption
Resilient systems identify weakening signals early: delayed responses, repeated deviations, capacity changes, ownership transitions, raw-material concentration, quality drift, forecast error, and deteriorating economics.
The operating model must define who sees those signals, who interprets them, who can trigger action, and what evidence is required. A risk register that is reviewed after disruption is an archive, not a control system.
This perspective is general information and does not constitute formal regulatory, legal, investment, clinical, manufacturing, quality, or other specialist advice.