How to Map Sub-Tier Supply Chain Risk in Biotech

Most supply chain due diligence checks the company directly in front of you and stops there. According to someone who maps this exposure for a living, that is exactly where the real risk begins. Theresa Campobasso, Senior Vice President at Aardwolf Global Solutions and a former U.S. Marine Corps intelligence officer who provided counterintelligence support to the Defense Intelligence Agency, opened our series on China and the life sciences. Her argument is that the danger sits below the first tier, and that, for the first time, the tools to see it actually exist.
How do you map sub-tier supply chain risk?
You go past the partner in front of you. Most companies run a solid check on the third party they are about to work with, then stop, and the deeper layers of the supply chain go unexamined. Campobasso's point is that the exposure that matters tends to live several suppliers down:
"We do a great job around assessing the risk environment for the third party itself, but oftentimes we stop there because we're so excited to do this research."
The fix is to keep going. Map the suppliers of your suppliers, down through the tiers, until you can actually see who is connected to whom. That is the work most diligence skips, and it is where the surprises are.
Why third-party checks stop too early
A clean first-tier partner is not the same as a clean supply chain. The questionnaire gets filled out, the sanctions check comes back fine, the box gets ticked, and the deeper network never gets illuminated. Campobasso described what that misses:
"We need to illuminate the rest of that supply chain, because oftentimes tiers three to five are where you're going to find obfuscated state ownership or Chinese government presence, Chinese military technology presence, and maybe some hidden, what we call FOCI, or foreign ownership, control, and influence, that weren't apparent when you just did that third-party check on that first company that you're considering doing business with."
FOCI is foreign ownership, control, and influence. The reason it hides in tiers three through five is simple: nobody looks there, because the diligence stopped at tier one.
What changed: supply chain became a security problem
For most of its history, supply chain was treated as a procurement and optimization exercise, not a security one. Campobasso traced the shift to a specific moment:
"Before that point in time, supply chain was typically seen as really just an acquisition or procurement or an optimization exercise. It wasn't really seen as a security equity. […] So then COVID happens. We see global widespread supply chain challenges, disruptions, huge long lead times, huge shortages of medical equipment, critical supplies, microelectronics. All of a sudden the paradigm shifts. People can clearly see why supply chain is a national security issue."
That reframing matters because it changed where the investment went. Once supply chain was a security question, the data, the tooling, and the methods followed.
The tools that make deep mapping possible now
This is the part Campobasso is most direct about: the work that was effectively impossible five years ago is doable today. The reason is the data plus the analytics layer that now sits on top of it.
"With the rise of generative AI and all sorts of modeling and simulation, AI-driven, agentic AI-driven capabilities that we didn't have before, all of a sudden you can take these huge data sets and you can quickly apply some machine learning, some natural language, some generative AI, some agentic AI capabilities on top of that data. You can pull out these hidden trends. You can identify these connections at a scale and at a volume and at a speed that a human being previously wouldn't be able to do."
The result is a level of resolution that used to be out of reach. In her words, the better solutions can "track the raw material down to the hole in the ground that it came out of," with particular focus on critical minerals, critical mining, and rare earth elements.
What it means for operators
Campobasso's conclusion is the optimistic one. The blind spot is real, but it is not permanent.
"This problem is solvable. The question is answerable."
For an operator, the practical takeaway is that "we did our diligence" no longer means what it used to. If the check stopped at the first supplier, the exposure in tiers three through five is still sitting there unmapped. The capability to go deeper exists now, which means the harder question is no longer whether you can see your sub-tier network, but whether you have actually looked. The same blind spot is what makes a law like the BIOSECURE Act easier to satisfy on paper than in practice. Mapping the network also forces a prior question: whether there are alternatives to Chinese biotech suppliers in the first place.
Join the conversation
If you run sourcing, security, or diligence, you are making calls every week about partners whose deeper networks you have not mapped. The people on the other sides of that problem see parts of it you cannot, and the fastest way to close the gap is to get those views in the same room.
Open Door Salon convenes those conversations on the record. Watch the full conversation with Theresa Campobasso. And if your company needs to reach the people making these supply chain decisions, that is what sponsorship is for.
