September 18, 2025
Kategorie
BPM & GRC software

Crisis-proof supply chains in times of geopolitical uncertainty

Christopher Schaffert
Managing Director of intellior GmbH
No items found.
Logo YoutubeLogo LinkedInLogo Xing
Crisis-proof supply chains in uncertain times with BPM and GRC software Aeneis
Inhaltsverzeichnis

Geopolitical tensions, wars and the resulting sanctions, export controls and volatility in commodity markets are the dominant disruptive factors in global supply chains today. At the same time, legal pressure is noticeably increasing, from LkSG/CSDDD (German Supply Chain Due Diligence Act/Corporate Sustainability Due Diligence Directive) to industry-specific requirements to cybersecurity requirements that have a direct impact on supply networks. Public utilities, energy, industrial and financial companies are thus confronted with a “wave of regulation” in which LkSG/CSDDD plays a central role alongside ISO standards, GDPR, HinSchG (German Whistleblower Protection Act) and CSRD (Corporate Sustainability Reporting Directive). An integrated management system (IMS) with robust GRC processes is thus becoming a mandatory program in order to demonstrably fulfill obligations and limit liability risks.

Cybersecurity is developing particularly dynamically: The NIS-2 Directive (Network and Information Security Directive 2) significantly expands obligations, from registration with the BSI (Federal Office for Information Security) to reporting requirements and the personal responsibility of management. Supply chain attacks are an explicitly identified risk factor. Pressure is also increasing in the financial sector: DORA (Digital Operational Recilience Act) requires digital resilience, robust recovery strategies and a certified BCMS (Business Continuity Management System) from 2025, including documentation of external dependencies such as supplier IT or cloud services.

The quintessence: Crisis-proof supply chains are created not through selective individual measures, but through transparent processes, systematic risk management and an active BCMS on one platform. This is exactly where Aeneis comes in, with process-oriented transparency, risk management including ICS, information security and business continuity in an integrated system.

Latest studies & trends

Digital resilience as a competitive factor. A current reference source is IMD World Digital Competitiveness Ranking 2024, which shows how digital performance enables economies and companies to react agilely to upheavals. Intellior places these results in the BPM context: Digital excellence correlates with adaptability and resilience, both core requirements of crisis-proof supply chains. For companies, this means that process and data expertise are not “secondary IT issues,” but the basis for identifying, evaluating and specifically mitigating supply network risks.

Regulatory trend: more obligation, shorter deadlines, higher liability. On an operational level, NIS-2 is tightening requirements, including due to the increase in supply chain attacks. The government draft on NIS2UmsuCG (German NIS 2 Implementation and Cybersecurity Strengthening Act) sets the legal framework; companies must demonstrably live risk management, incident response and continuity planning, often with registration within three months of entry into force and personal management responsibility. This affects significantly more companies than in the past. For supply chain managers, this means: Cyber, compliance and operational risks in the chain can no longer be thought of separately.

Sectoral consolidation: DORA & Co. Especially for financial companies, DORA requires certified reliability across the entire value chain, including external dependencies. This changes the importance of supplier and service provider management: Not only contracts, but process-related evidence (processes ↔ risks ↔ measures ↔ tests) become decisive. Aeneis supports by integrating BCMS, ISMS and GRC components and restarting and effectiveness tests are documented in a structured manner.

Supply chain with LkSG/CSDDD focus. Many industries, such as public utilities, energy, mechanical engineering or healthcare, increasingly see LkSG/CSDDD (German Supply Chain Due Diligence Act / Corporate Sustainability Due Diligence Directive) as a cross-cutting task. With Aeneis, companies have an integrated management system that reduces duplication of effort and consistently enshrines obligations across standards. For supply chains, this means that risks (e.g. raw material, compliance, cyber risks) are made visible along the process map and delivery stages and linked to controls, tasks and audits in a system, rather than in individual solutions.

Consequence for practice: Companies that combine process management, risk management (including ICS), ISMS and BCMS on a central platform measurably increase their supply chain resilience: processes become transparent (e.g. process map, views, roles), risks are assessed and monitored in a standardized manner (e.g. risk matrix, controls, tasks), information security is tackled in a structured manner and business continuity is planned, tested and proven in accordance with standards. Aeneis provides the components for this, from BPM to GRC and risk management to BCMS, from a single source.

Challenges for companies

Global supply chains are currently under tremendous pressure. Companies are confronted with a variety of risks that are mutually reinforcing:

  • Political and geopolitical risks
    Wars, tariffs, sanctions and trade restrictions change the availability of goods and intermediate products from one day to the next. Dependencies on individual regions or suppliers can result in total failure.
  • Commodity scarcity and price volatility
    The supply of rare earths, metals and energy is particularly critical. Supply bottlenecks drive up prices and threaten production continuity and competitiveness.
  • Statutory pressure from LkSG & CSDDD
    Companies must not only secure their supply chains economically, but also comply with human rights and ecological due diligence obligations. The German Supply Chain Due Diligence Act (LkSG) and the planned EU CSDDD commit to comprehensive transparency, risk analyses, prevention and remedial measures, including documentation and reporting.
  • Cyber and compliance risks in the supply chain
    With NIS-2 and industry-specific requirements such as DORA, responsibility for digital resilience is growing. Attacks via suppliers and IT service providers are one of the biggest threats, as they often have a deep impact on one's own company.
  • Lack of transparency and complexity
    Many organizations have only limited insight into the second and third supplier layers. Risks are considered in isolation rather than in a holistic system. As a result, the basis for predictive control is missing.

The central challenge is therefore: How can this growing complexity be made manageable and how can companies fulfill their reporting obligations without sinking into a jungle of bureaucracy?

Core solution with Aeneis — process management, risk management, ISMS & BCMS

The Aeneis BPM and GRC software addresses these challenges by providing an integrated platform that combines processes, risks, information security, and business continuity in one system.

1. Process management: Create transparency

  • With Aeneis, supply chain processes can be digitally modeled, including dependencies on suppliers, IT systems, roles and documents.
  • Process maps and interactive views make it possible to see where critical paths exist and which suppliers or materials are systemically relevant.
  • Features for exporting and interfaces (e.g. to LeanIX) enable integration into existing IT landscapes.

2. Risk management: Managing risks systematically

  • The ICS/risk management app makes it possible to centrally record, evaluate and link risks to processes.
  • Companies can create controls and tasks directly, define automatic test cycles and clearly assign responsibilities.
  • Diagrams, heat maps and dashboards provide an overview of the probability of occurrence, impact and the status of risk treatment at any time.
  • Advantage: Risks from compliance, IT security and raw material supply can be mapped in an integrated system.

3. ISMS: Information security in the supply chain

  • With Aeneis, companies can carry out a protection requirements analysis for their processes, IT systems and databases in order to assess their criticality.
  • On this basis, a systematic risk analysis is carried out for threats in the area of information security, which is particularly important for supply chains.
  • Security incidents can be recorded and evaluated directly in the system and linked to specific measures for remediation and prevention.
  • Aeneis is guided by the international standards of ISO 27001 and supports the implementation of legal requirements such as the NIS-2 Directive.

4. BCMS: Ensuring business continuity

  • Business continuity management in Aeneis makes it possible to identify critical processes and resources and secure them with clear recovery plans.
  • Emergency and crisis plans can be drawn up and responsibilities can be clearly assigned for various scenarios such as supplier failures, raw material shortages or energy bottlenecks.
  • All steps are documented in the system so that no time is lost with unclear responsibilities in an emergency.
  • Aeneis supports companies in implementing the requirements of ISO 22301 and ensures that the effectiveness of the BCMS can be proven at any time.

5. Integration as a success factor

  • Aeneis combines process management, risk management, BCMS and ISMS in a common platform and thus creates a central single point of truth.
  • By using the High Level Structure (HLS), the requirements of various standards such as ISO 9001, ISO 22301 and ISO 27001 can be met consistently and integrated.
  • Companies benefit from a single database that avoids duplication of work and ensures consistent traceability.

Ensuring continuous compliance

A key goal of modern companies is not only to fulfill compliance as a formal requirement, but also to actually integrate it into the daily work of employees. The supply chain in particular shows how important it is that laws, standards and processes are not only known, but also really understood and applied. Whether it concerns human rights due diligence requirements, cybersecurity requirements from NIS-2 or the requirements of ISO standards, without actual compliance, any process description remains ineffective.

With the upcoming version 7.5 of Aeneis, intellior provides the Compliance manager for this purpose. This feature makes it possible to check compliance directly in the processes. Involved employees go through AI-based tests that are specifically tailored to their role and the respective process. For example, they must specifically prove that they have understood the relevant processes, regulations and risks. For management, this provides audit-proof evidence that processes are not only documented but actually implemented. At the same time, the system provides valuable information when there are gaps in understanding or additional training measures are required.

Compliance managers develop their particular strengths, particularly in the context of supply chains. Because regulatory requirements can only be implemented sustainably if all parties involved, from purchasing to supplier management to IT security, know and internalize their responsibilities. Aeneis thus not only ensures transparency and risk control, but also ensures that compliance with laws and standards is actively anchored in the company. In this way, compliance becomes a continuous process that significantly strengthens the resilience and stability of the entire supply chain.

Conclusion

The current geopolitical uncertainties, raw material shortages and increasing legal pressure pose enormous challenges for companies. Supply chains today are exposed not only to economic fluctuations, but also to regulatory requirements and cyber risks. If you want to survive successfully in this environment, you need more than just short-term solutions. You need a consistent, integrated management system that creates transparency, makes risks manageable and ensures the ability to act even in crisis situations.

With Aeneis, intellior offers exactly this platform. The combination of process management, risk management, business continuity management and information security management creates a central “single point of truth” that gives companies the necessary overview and control capacity. Supplemented by the new Compliance Manager from version 7.5, which ensures that processes are not only documented but actually understood and implemented, compliance is becoming a continuous success factor.

For supply chains, this means that risks become visible, responsibilities become clear, and compliance with legal requirements is not left to chance, but is systematically proven. This creates real resilience and gives companies the security of being able to deliver reliably even in uncertain times.

Test Aeneis today or arrange a personal live demo and find out how your organization not only secures supply chains, but also makes them sustainably crisis-proof.

No items found.

FAQ

1. Why is an integrated management system with Aeneis important for supply chains?
Aeneis combines processes, risks, information security and business continuity in a central platform. It thus reduces double costs, creates transparency and enables the reliable fulfilment of regulatory obligations such as LkSG, CSDDD or NIS-2.

2. How does Aeneis help deal with geopolitical and regulatory risks?
With Aeneis, supply chain processes can be digitally modeled and risks systematically recorded. Dependencies, for example with suppliers or IT systems, become visible and can be controlled in a targeted manner via dashboards, controls and measures.

3. What is the role of Aeneis in the context of the NIS-2 Directive?
With Aeneis, protection requirements and risk analyses for processes and IT systems can be carried out, security incidents can be documented and preventive measures can be derived from this and assigned to those responsible. In this way, the requirements of the NIS-2 Directive can be implemented in a structured and verifiable way.

4. How does Aeneis help financial companies comply with DORA?
Aeneis integrates BCMS and ISMS functionalities, through which recovery plans and external dependencies can be documented and reliable evidence can be provided. This allows financial companies to meet DORA's resilience requirements efficiently and in an audit-proof manner.

5. What does Business Continuity Management do in Aeneis?
With the BCMS in Aeneis, critical processes and resources can be identified, recovery plans defined and tests can be documented in accordance with ISO 22301. As a result, companies are prepared in an emergency and can keep their supply chains operational.

6. How does the Compliance Manager in Aeneis ensure actual compliance?
Starting with version 7.5, the Compliance Manager checks the knowledge and understanding of employees directly in the process. AI-based tests provide audit-proof evidence that requirements from LkSG, NIS-2 or ISO standards are actually understood and applied.

7. Which companies is Aeneis particularly suitable for?
Aeneis is aimed at regulated industries such as energy, public utilities, industry, healthcare and the financial sector. Wherever supply chains need to be managed in a stable, transparent and compliant manner, Aeneis provides the right platform.

No items found.
Christopher Schaffert
Managing Director of intellior GmbH

Über den Experten

Thought leader for business process management (BPM), governance, risk & compliance (GRC), and digital transformation. For over 15 years, he has been helping companies identify regulatory requirements, technological developments and market developments at an early stage and use them as a driving force for sustainable development.

His work focuses on translating complex developments into future-oriented strategies and sustainable solutions. In doing so, he creates orientation in dynamic environments and supports organizations in actively and effectively shaping change.

He has been managing director of intellior GmbH since 2024 and is responsible for the strategic development of the company.

Logo LinkedIn

No items found.

Weitere spannende Blog-Posts

Erfolgskritische Prozesse verstehen, optimieren und absichern
Nutzen Sie das verbesserte Verständnis, um eine Grundlage für die Prozessoptimierung zu schaffen.

Risiken minimieren. Prozesse optimieren.
Kostenfreie Erstberatung anfordern