Redefining Technology

Manufacturing (Automotive)Future of AI & Visionary Thinking

AI-driven supply network orchestration in automotive manufacturing: running a multi-tier supply base you cannot fully see

AI-driven supply network orchestration is the practice of planning, allocating and rebalancing an automotive supply base across every tier at once — not only the suppliers an OEM contracts with, but the sub-tier plants those suppliers depend on. It combines multi-tier visibility, sovereign data sharing and explicit allocation rules so scarcity is resolved by policy rather than by escalation.

Automotive supply-network control room overlooking an assembly plant, with a multi-tier flow map and capacity charts on the wall
Manufacturing (Automotive) · Future of AI & Visionary Thinking

Key takeaways

  1. Multi-tier visibility is a governance problem before it is a data problem. The tier-2 and tier-3 plants that constrain an automotive build are not hiding behind bad integration — they are behind a supplier who has a commercial reason not to name them, and no technology closes that gap without a reciprocal deal.
  2. An OEM can orchestrate what it buys, not what its supplier buys. Every orchestration ambition eventually hits the contract boundary: below tier-1 you have influence, specification power and goodwill, but no instruction rights unless you have bought them through a directed buy or a direct capacity reservation.
  3. The hard decision in a shortage is not detection, it is allocation — which plant, which model, which market goes short. That decision has a basis, an owner and a defensible record, or it has none of the three and gets made by whoever escalates hardest.
  4. Catena-X matters to orchestration for one reason: sovereignty. A supplier will emit a capacity signal when it can see, and revoke, what the receiver may do with it. The data space is the mechanism that makes a machine-readable answer cheaper for the supplier than a phone call.
  5. Disruption response is a rehearsed capability or a heroic scramble, and the difference is measured in how much of the analysis was pre-built. Operators who can go from headline to quantified build-plan impact in hours have a maintained part-to-site graph; the rest reconstruct it under pressure.

Abbreviations used on this page

OEM
Original equipment manufacturer — the vehicle maker
Tier-n
Any supplier below tier-1 — the tier-2, tier-3 and deeper plants an OEM has no contract with
BOM
Bill of materials — the part structure of a vehicle
MRP
Material requirements planning
APS
Advanced planning and scheduling system
EDI
Electronic data interchange — the call-off and despatch messages defined by Odette, VDA and AIAG
ASN
Advance shipping notice (the DESADV / 856 despatch message)
JIS
Just-in-sequence — parts delivered in build order, minutes ahead of the line
MMOG/LE
Materials Management Operations Guideline / Logistics Evaluation — the AIAG and Odette supply-chain capability standard
MCU
Microcontroller unit — the chip class the 2020–23 shortage bit hardest
DCM
Demand and capacity management — the Catena-X use case for cross-tier capacity signalling
BCP
Business continuity plan

Free · 8 questions · ~3 minutes

Score your supply network on the orchestration ladder

Eight questions, one at a time, about three minutes. Answer them and we build your personalised orchestration report — your rung on the Tier-1 visible → Self-rebalancing ladder, your score on each of the four dimensions, and the specific gap standing between you and the next rung — and send it to your inbox. Your result doubles as the baseline for your next disruption rehearsal.

0 of 8 answered

Question 1 of 8Multi-tier visibility

How far below tier-1 can you name the actual manufacturing site for a critical component — from systems, not from a phone call?

Depth of the part-to-site graph sets the ceiling on everything else. You cannot plan around a constraint you cannot locate.

How the score maps to a stage
  • 05 — Stage 1, Tier-1 visible. Tier-1 visible is the stage where the OEM knows, in systems, only the suppliers it holds contracts with — everything below tier-1 exists as correspondence rather than as data.
  • 611 — Stage 2, Tier-n mapped. Tier-n mapped is the stage where a maintained part-to-site graph reaches two or more tiers deep for the critical commodities — a real map, but one refreshed by survey rather than by signal.
  • 1216 — Stage 3, Signal-shared. Signal-shared is the stage where sub-tier partners emit scoped, machine-readable demand and capacity signals under agreed terms, so the network picture refreshes itself instead of being surveyed.
  • 1721 — Stage 4, Jointly orchestrated. Jointly orchestrated is the stage where the OEM and its critical suppliers plan against one shared model and rebalance together under a published allocation policy, with accountability for each call named in advance.
  • 2224 — Stage 5, Self-rebalancing. Self-rebalancing is the stage where bounded reallocation executes automatically inside the published policy — routine swaps happen without a meeting, and only out-of-policy moves reach a person.

What AI-driven supply network orchestration is in automotive

A definition, why the automotive supply base is a harder case than any other manufacturing network, and the path a capacity signal has to travel before it can change a build decision.

AI-driven supply network orchestration is the practice of planning, allocating and rebalancing an automotive supply base across every tier simultaneously, rather than one contractual hop at a time. Where classical supply-chain planning optimises what an OEM buys from its tier-1s, orchestration treats the network — the parts, the sites that make them, the capacity at each site and the commitments that bind them — as one object, and uses models to keep that object current and to test moves against it before they are made.

Automotive is the hardest place to attempt this, for three structural reasons. The supply base is unusually deep: a vehicle carries tens of thousands of parts, and the parts that stop a line are frequently four or five commercial hops from the OEM. Buffers are unusually thin, because just-in-time and just-in-sequence delivery (opens in a new tab) are the industry's operating discipline, so a sub-tier interruption reaches the line in days rather than months. And concentration hides at depth: two tier-1s that look independent in the supplier master routinely share a wafer fab, a resin grade, a connector plant or a rare-earth refinery, and nothing in the OEM's systems would say so. European and German industry bodies (opens in a new tab) and their German counterpart (opens in a new tab) have both spent the post-2020 period pushing member companies toward exactly this kind of cross-tier transparency, precisely because the 2020–23 semiconductor shortage demonstrated that no individual OEM could see the constraint that was stopping it.

Orchestration value released against the depth of network you can act on

Value stays close to flat while the network is only mapped, because a map changes no decision by itself. It inflects when a signal starts arriving without being asked for, and again when the parties plan against the same picture. This is why manufacturers who invested heavily in mapping after 2021 often report disappointing returns — they built the artefact and stopped one rung short of the mechanism.

Orchestration value released by stage

  • Stage 1 · Tier-1 visible — 24% of operators. Tier-1 visible is the stage where the OEM knows, in systems, only the suppliers it holds contracts with — everything below tier-1 exists as correspondence rather than as data.
  • Stage 2 · Tier-n mapped — 38% of operators. Tier-n mapped is the stage where a maintained part-to-site graph reaches two or more tiers deep for the critical commodities — a real map, but one refreshed by survey rather than by signal.
  • Stage 3 · Signal-shared — 24% of operators. Signal-shared is the stage where sub-tier partners emit scoped, machine-readable demand and capacity signals under agreed terms, so the network picture refreshes itself instead of being surveyed.
  • Stage 4 · Jointly orchestrated — 11% of operators. Jointly orchestrated is the stage where the OEM and its critical suppliers plan against one shared model and rebalance together under a published allocation policy, with accountability for each call named in advance.
  • Stage 5 · Self-rebalancing — 3% of operators. Self-rebalancing is the stage where bounded reallocation executes automatically inside the published policy — routine swaps happen without a meeting, and only out-of-policy moves reach a person.

Curve shape: logistic, plotted from the stage data above. Distribution: Consistent with Deloitte's automotive supply-chain research.

How a capacity signal travels from a sub-tier plant to an OEM build decision

The same constraint, three ways. In the top lane the OEM's information stops at the tier-1 order book, so the shortage is discovered as a missed ASN on the goods-in dock. In the middle lane a sovereign connector carries a scoped capacity assertion into a network model, and a planner re-sequences before the miss. In the bottom lane the parties rebalance together against a published allocation policy. Most OEMs are in the top lane.

  • Data & feeds
  • Where value leaks
  • AI / model
  • System-of-record action
  • Human in the loop

The process, in words

  • Today, the OEM's picture stops at the tier-1's order book. The OEM pushes forecast out as call-offs and receives despatch notices back, but the hop from tier-2 to tier-1 is commercially opaque by design, so a constraint forming at a wafer fab or a connector plant reaches the OEM only when a delivery fails. Just-in-sequence supply means the first symptom is a stopped line, and the first response is a phone call in which nobody has numbers.
  • In the signal-shared lane, the sub-tier partner emits a scoped, time-boxed capacity and cover assertion under a data contract, carried by a connector that enforces what the receiver may do with it. That assertion lands in a network model that already holds the part-to-site graph, so weeks of cover per part and per plant becomes a live figure and the planner re-sequences call-offs before the miss rather than after it.
  • In the jointly orchestrated lane, the same model feeds a rebalancing proposal that all parties see, and the allocation basis was fixed in writing before the shortage. Moves inside the policy execute; moves outside it escalate to a named accountable executive with a logged rationale. The speed gain is real but secondary — the durable gain is that the decision is defensible afterwards.
Step-by-step insights
The invisible hop — why tier-2 to tier-1 is opaque on purpose
A tier-1's supply base is a competitive asset. It reflects years of qualification work, negotiated pricing and capacity commitments, and disclosing it upward exposes the tier-1 to disintermediation and to margin pressure at its next price round. Automotive OEMs have historically reinforced this by using every disclosure as sourcing intelligence. The opacity is therefore rational behaviour by a rational party, which is why it does not yield to better integration. It yields to a bounded, verifiable, reciprocal arrangement — or it does not yield at all.
Call-offs go out, understanding does not come back
The EDI infrastructure automotive already runs — the Odette, VDA and AIAG message families for delivery forecasts, call-offs and despatch advice — is superb at moving commitments downward and status upward. What it was never designed to carry is capacity, cover or constraint. An ASN tells you what shipped; it cannot tell you that the plant which shipped it will be at 60% next month. Orchestration is not a new EDI message. It is a different class of assertion, exchanged under different terms, and it needs a channel that can carry the terms alongside the payload.
Why just-in-sequence turns a sub-tier problem into a same-week problem
Just-in-time removed inventory from the network deliberately, and just-in-sequence removed it from the plant. The economics are excellent and the fragility is structural: a network optimised for flow has, by construction, nothing to absorb a shock with. That is not an argument for abandoning JIT — the industry has tried buffers and rediscovered why it left them behind — but it is the reason automotive cannot treat sub-tier visibility as a nice-to-have. In a network with days of cover, information arriving after the event is not information.
The scoped assertion — what a good sub-tier signal actually contains
The instinct is to ask for everything: full order book, full capacity, full sub-supplier list. The signals that actually get agreed are narrow. A workable assertion names one part or part family, states committed capacity for a stated horizon, states the share allocated to this customer, gives weeks of cover at the supplier's own inbound, carries a validity window, and says nothing about other customers. It is deliberately less than the OEM wants and enough to plan on — and being less is precisely why the supplier signs.
The network model is a graph problem before it is a machine-learning problem
Most of the value in a network model comes from the graph: part numbers to sites, sites to capacity, capacity to programmes, programmes to commitments. Traversal answers the questions that matter — which programmes does this fire touch, which of my dual sources are secretly single, how many weeks until the first plant stops. Learned components earn their place at the edges: predicting lead-time drift from historical despatch variance, inferring undisclosed sub-tier relationships from customs and shipping records, classifying incoming supplier documents into the graph. Teams that start with the model and defer the graph build something that demonstrates well and answers nothing.
Policy before automation — the escalation branch is the important one
The bottom lane's value is concentrated in the branch that escalates, not the branch that executes. Automating an in-policy swap saves a meeting; routing an out-of-policy move to a named accountable person with a logged rationale is what keeps the whole arrangement legitimate when a plant loses two weeks of volume and asks why. Design the escalation path first — who is named, what the log records, how a supplier can query it — and the automation becomes a safe optimisation of a system that already works.

The word doing the work in all of this is orchestration rather than optimisation. An optimiser assumes it controls the variables it is solving over; an orchestrator does not, and its central problem is acting through parties with their own interests, their own customers and their own information. That distinction shapes every rung of the ladder below, and it is why the hardest problems on this page are commercial and governance problems that happen to have a technical component — not the other way round.

The five stages in detail

For each rung: what it looks like inside a real purchasing and planning organisation, the diagnostic signals a reviewer can check in an afternoon, the anti-pattern that traps manufacturers there, and what leaving costs.

Each rung below is written for a practitioner rather than a buyer. The hallmarks describe observable conditions in the supplier master, the planning system and the risk register; the diagnostic signals are checks you can run against your own estate this week; and the anti-pattern is the specific mistake most often made trying to leave that rung.

Select a rung

Every rung's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.

Stage 1

Tier-1 visible

24% of operators sit here

Tier-1 visible is the stage where the OEM knows, in systems, only the suppliers it holds contracts with — everything below tier-1 exists as correspondence rather than as data.

Stage 1 is not ignorance; it is a boundary drawn where the contract ends. Purchasing knows its tier-1s in genuine detail — capability, capacity agreements, quality history, MMOG/LE scores — and that knowledge stops precisely at the point where the tier-1 becomes a buyer rather than a seller. The organisation is not failing to look below tier-1. It has never been structured to.

The consequence is that the entire supply base is modelled as a list rather than as a graph. A list answers 'who supplies this part' and cannot answer 'what else does this part depend on', which is the only question that matters when a plant on the far side of the world stops. Two tier-1s can look like a healthy dual source in the supplier master and share one wafer fab, one resin grade or one connector plant in reality, and nothing in the system would say so.

This is a cheap stage to leave and an expensive one to sit in, because the cost only appears during disruption and then appears all at once. The 2020–23 semiconductor shortage was the industry's collective discovery of this: OEMs with excellent tier-1 relationships found they could not answer, in days, which of their programmes depended on which fab. The answer existed — it just lived in nobody's system.

In practice

The part everyone thought was second-sourced

A European OEM carried two approved suppliers for a body-control module and treated the commodity as de-risked in its risk register. When one supplier declared allocation, the second could not step up: both bought the same 40-nanometre microcontroller family from the same foundry, and the foundry's allocation was made to the chip vendor, not to either module maker. The dual source was real at tier-1 and imaginary at tier-3. Nobody had lied; nobody had ever explored the BOM past the module.

What it looks like

  • The supplier master doubles as the tier map; there is no part-to-site graph below tier-1
  • Sub-tier questions are answered by email chains during a crisis, not by a query
  • Capacity is assumed from the contract rather than observed from the supplier's plant
  • Nobody owns 'the network' — purchasing owns suppliers, plants own lines, and the space between is unassigned

Diagnostic signals you can check this week

  • Ask which plant manufactures the microcontroller in a named ECU. If the answer requires an email to the supplier, you are here
  • Open the risk register and count how many entries name a site rather than a company
  • Check whether any 'dual-sourced' commodity has ever been tested for shared sub-tier dependency
  • Ask who is accountable for the supply network as an object. If the answer is a committee, it is nobody

Anti-pattern · Buying a risk-monitoring subscription first

The instinctive fix is a third-party supply-risk feed: earthquakes, fires, port closures, insolvency signals, all pushed into an inbox. It is genuinely useful later and almost useless now, because an alert about a site you cannot connect to a part number is noise with a red icon on it. Teams at stage 1 typically mute the feed within two quarters. Build the part-to-site graph for your top commodities first; the same feed then becomes actionable, because every alert resolves to programmes and volumes.

What holds you here

The supply base is modelled as a list of contracted suppliers rather than as a graph of parts and sites, so sub-tier dependency is structurally invisible.

Highest-leverage next move

Pick the top twenty parts by line-stop consequence and explode each one to the tier where the real constraint sits. Not the whole BOM — twenty parts.

Cost of leaving

Effort
3–6 months
Team
One supply-chain data engineer, one commodity buyer, part-time engineering support
Risk
Low — the work is additive and no production decision depends on it yet
To next stage
3–6 months

If this is you, the next step is

A 3-week engagement: explode one part family to the constraining tier and price the gap.

Map one critical commodity

Stage 2

Tier-n mapped

38% of operators sit here

Tier-n mapped is the stage where a maintained part-to-site graph reaches two or more tiers deep for the critical commodities — a real map, but one refreshed by survey rather than by signal.

Stage 2 is where most automotive manufacturers sit after the shortage years, and it is a genuine achievement: someone did the BOM work, chased the declarations, and produced a map that answers real questions. The map is the single highest-return artefact in this whole domain, because it converts every subsequent signal — a fire, a flood, an export control, an insolvency — from a news item into a list of programmes and volumes.

The structural weakness is that the map has no metabolism. It was assembled by asking, and asking is expensive, so it gets asked roughly once a year — while the underlying network changes continuously. Suppliers requalify sub-suppliers, move production between their own plants, add capacity in a new region, and none of that reaches the map until the next survey cycle. A tier map with no refresh mechanism should be assumed materially wrong within a year, and the parts that move fastest are usually the ones under commercial pressure, which is to say the risky ones.

The second weakness is that the map describes structure but not state. It says a component comes from a named site; it does not say how much capacity that site has this quarter, what share of it you hold, or how many weeks of cover sit between that site and your line. Structure without state supports post-mortems and does not support planning. Moving to stage 3 is the move from asking to receiving.

In practice

The map that was true in March

A supplier-network team spent a quarter building a tier-2 and tier-3 map for forty electronic commodities, complete with named plants and geographies. Eleven months later a typhoon closed one of the mapped sites and the team ran the impact query with real confidence. Two of the three affected part numbers had been requalified to a different plant six months earlier as part of a supplier cost programme — nobody had told the OEM, because nobody was contractually required to. The query was fast, well-built and wrong.

What it looks like

  • A part-to-site dataset exists for critical commodities and names manufacturing sites, not just legal entities
  • Shared sub-tier dependencies between nominally dual-sourced parts have been identified at least once
  • The map is refreshed by annual supplier declaration or by a crisis-driven survey
  • Risk alerts can be resolved to affected part numbers and programmes within days

Diagnostic signals you can check this week

  • Ask when the tier map was last refreshed and by what mechanism. 'The last crisis' is a common and revealing answer
  • Pick three mapped parts at random and verify the site with the tier-1 this week — count how many have moved
  • Check whether the map records capacity or share of capacity, or only structure
  • Ask what the map costs to refresh in person-days. If the answer is large, it will not be refreshed

Anti-pattern · Mapping everything before using anything

Once the mapping method works, the temptation is to run it across the whole bill of materials. It is a two-year project that produces a dataset stale at both ends: the parts mapped first have moved by the time the last are done, and none of it has yet changed a planning decision. Depth beats breadth. Map to the constraining tier for the parts whose absence stops a line, get a live signal on those, and let the long tail stay at tier-1 until a signal is cheap enough to extend.

What holds you here

The map is refreshed by asking rather than by receiving, so it decays between surveys and describes structure without state.

Highest-leverage next move

Convert one tier-2 relationship from survey to signal: a scoped, machine-readable capacity and cover assertion, exchanged under terms the supplier can audit.

Cost of leaving

Effort
6–12 months
Team
A named supply-network owner, a data engineer, commodity buyers for the critical groups
Risk
Medium — the first supplier data-sharing conversations set the tone for every later one
To next stage
6–12 months

If this is you, the next step is

We design the disclosure terms and the data path, then run the first commodity end to end.

Put a refresh mechanism on your tier map

Stage 3

Signal-shared

24% of operators sit here

Signal-shared is the stage where sub-tier partners emit scoped, machine-readable demand and capacity signals under agreed terms, so the network picture refreshes itself instead of being surveyed.

Stage 3 is the first stage where the network picture stops being a project deliverable and starts being a feed. The engineering is modest; the negotiation is not. A tier-2 supplier's capacity and order book are among the most commercially sensitive things it owns, and the reason it does not share them with its customer's customer is not integration cost — it is that it cannot see what will happen to the data afterwards, and it has usually been burned by a customer who used a capacity disclosure as a price lever.

That is precisely the problem the automotive data-space work was built to solve. Sovereignty guarantees — usage policies that travel with the data, revocable access, verifiable identity, and an audit trail the supplier can read — turn a dangerous disclosure into a bounded one. The technical stack is real but secondary; the reason it matters is that it makes a machine-readable answer cheaper and safer for the supplier than a phone call, which is the only durable basis for a recurring signal.

The characteristic mistake here is treating the signal as free intelligence. Stage-3 relationships that last are reciprocal: the OEM gives the supplier something it wants — a longer frozen horizon, an earlier view of programme volumes, a commitment to a minimum take — in exchange for what it is asking. Where nothing flows back, the signal degrades into a compliance form filled in by an intern, and the numbers stop being true long before anyone notices.

In practice

The exchange that survived a price round

An OEM agreed a quarterly capacity-and-cover exchange with a tier-2 connector manufacturer, on explicit terms: the data could be used for build planning and constraint detection, not for sourcing or commercial negotiation, with retention capped and the supplier able to revoke. Six months later the OEM's purchasing team opened a cost round with the same supplier. Because the exchange terms were machine-enforced and separately auditable, the supplier could verify that its capacity data had not entered the negotiation. The signal survived the price round — which is the only test that matters.

What it looks like

  • At least one tier-2 relationship exchanges capacity or cover data on a schedule, not on request
  • Data sharing runs under an explicit contract naming purpose, retention and revocation
  • Weeks of cover per critical part is a live figure visible in the planning cadence
  • The OEM emits something back — a firmer forecast horizon, an earlier demand signal, or a reciprocal view

Diagnostic signals you can check this week

  • Count the sub-tier relationships where data arrives on a schedule without anyone asking. Zero is the usual honest answer at stage 2
  • Read one data-sharing agreement and look for purpose limitation, retention and revocation. If it only covers confidentiality, it is an NDA, not a data contract
  • Ask a supplier what they get back. If they cannot name it, the signal is on borrowed time
  • Check whether weeks of cover for critical parts appears in the planning cadence or only in incident reviews

Anti-pattern · Mandating disclosure in the terms and conditions

The fastest-looking route to sub-tier data is a clause: suppliers shall disclose their suppliers on request. It works on paper, produces a PDF once, and poisons the relationship for the thing you actually need, which is a recurring, accurate, voluntary signal. Suppliers comply minimally and defensively — legal entities rather than sites, aggregate rather than per-part, last year rather than this quarter. Buy the signal with something the supplier values instead, and keep the clause as a floor rather than a strategy.

What holds you here

Signals exist bilaterally but planning is still done alone: the OEM receives data and then decides in private, so suppliers cannot act on the same picture.

Highest-leverage next move

Publish an allocation policy and a joint rebalancing cadence, so the shared picture leads to a shared decision rather than a better-informed unilateral one.

Cost of leaving

Effort
9–18 months
Team
Supply-network owner, integration engineer, commercial and legal partners, a sponsor at purchasing-director level
Risk
Medium — the first agreement is a template for the next thirty, so it is worth over-designing
To next stage
9–18 months

If this is you, the next step is

The terms, the connector pattern and the reciprocal offer — drafted against one real commodity.

Design your first sub-tier data contract

Stage 4

Jointly orchestrated

11% of operators sit here

Jointly orchestrated is the stage where the OEM and its critical suppliers plan against one shared model and rebalance together under a published allocation policy, with accountability for each call named in advance.

At stage 4 the interesting artefact stops being the data and becomes the policy. Once several parties can see the same constraint, the question changes from 'what is happening' to 'who goes short, and on what basis' — and that question has no technical answer. It has a governance answer: a written allocation basis, a decision-rights table naming who proposes and who decides, and a record of the reasoning that survives the people who were in the room.

The manufacturers who do this well write the policy in calm weather. During a shortage, an allocation basis proposed for the first time is read as a manoeuvre by whoever it disadvantages — the plant that loses volume, the market that loses cars, the tier-1 whose other customers are being favoured. Written a year earlier and applied without exception, the same basis is read as a rule. The difference is entirely in the timing, and it is the single cheapest intervention available in this domain.

The remaining constraint at stage 4 is throughput of decision-making, not of information. Every rebalance still passes through a meeting, and meetings are weekly. That is often the right place to stop: an allocation decision touching plant employment, dealer commitments and homologated programmes deserves a human. What moves to stage 5 is the narrow, high-frequency subset where the consequences are bounded and the policy is unambiguous.

In practice

The rebalance that took a day instead of a fortnight

An OEM running a joint capacity cadence with two tier-1s and one tier-2 hit a packaging constraint on a microcontroller family. Because the shared model already carried per-plant cover and the allocation policy already said commitment-bearing fleet volume was protected ahead of retail trim mix, the parties agreed a build re-sequence in a single working day: one plant dropped a high-option trim for two weeks, the tier-1 re-phased its own call-offs, and the tier-2 confirmed the revised schedule. The equivalent decision the previous year had taken eleven days and three escalation calls to reach a worse answer.

What it looks like

  • A network model spans tiers and is trusted enough that suppliers argue with its numbers rather than dismissing it
  • An allocation policy exists in writing, is versioned, and was agreed before the current shortage
  • Rebalancing decisions are made in a standing joint cadence, not in an escalation call
  • Every allocation decision leaves a logged rationale a third party could reconstruct

Diagnostic signals you can check this week

  • Ask to see the allocation policy. If it is produced in under a minute and has a version number, you are at stage 4
  • Check whether the last allocation decision has a written rationale naming the basis applied
  • Look at whether suppliers challenge the network model's numbers — engagement is a maturity signal, silence is not
  • Ask whether the joint cadence runs when there is no crisis. Cadences that only convene under stress are escalation by another name

Anti-pattern · Letting the optimiser choose the allocation basis

With a working network model, it is technically easy to have the solver pick whichever allocation maximises a single objective — usually contribution margin. It is also the fastest way to lose the policy's legitimacy, because margin ranking silently overrides contractual commitments, regulatory programmes and the fair-share expectations that hold supplier relationships together. Fix the basis as a human policy decision, then let the model optimise inside it and cost the alternatives honestly.

What holds you here

Every rebalance still passes through a human cadence, so response speed is bounded by meeting frequency rather than by information.

Highest-leverage next move

Define the narrow band of reallocation decisions that may execute inside policy without a meeting, and the evidence trail that makes that defensible.

Cost of leaving

Effort
18+ months
Team
Supply-network platform team, S&OP owner, purchasing director, legal, plus supplier counterparts
Risk
Higher — the policy is a commercial and political artefact as much as an operational one
To next stage
18+ months

If this is you, the next step is

A two-day workshop with purchasing, S&OP and manufacturing; you keep the draft either way.

Draft your allocation policy before the next shortage

Stage 5

Self-rebalancing

3% of operators sit here

Self-rebalancing is the stage where bounded reallocation executes automatically inside the published policy — routine swaps happen without a meeting, and only out-of-policy moves reach a person.

Stage 5 is much narrower than the phrase suggests. It is not a self-driving supply chain; it is a specific, enumerated list of moves that may execute inside stated bounds — shifting a week of call-off between two plants of the same OEM, releasing buffer stock against a defined cover floor, re-sequencing option content within an agreed envelope. Anything that changes a supplier commitment, touches a homologated programme, or has employment consequences at a plant is correctly held at stage 4 permanently.

What makes this stage work is not model quality. It is that the bounds were derived from a real approval log: a year of stage-4 decisions, each with its basis and its outcome, is the dataset that tells you which moves humans always approved and therefore which moves are safe to delegate. Operators who skip stage 4 and set bounds by judgement discover the gaps the expensive way, usually in the first genuinely unusual week.

Sustaining stage 5 is a governance discipline. Networks change — a new plant, a new region, a supplier consolidation — and thresholds derived from last year's topology drift quietly out of validity. The escalation rate is the instrument to watch: a rising share of moves falling outside policy means the policy is describing a network that no longer exists, and it should trigger a review before it triggers an incident.

In practice

The bounded swap set

A large OEM permits automatic reallocation across a defined set: call-off volume may move between two of its own plants for the same part, up to a weekly ceiling, provided both plants stay above a stated cover floor and the part is not on the homologation-critical list. Roughly one move in twelve falls outside those bounds and routes to the regional manufacturing lead. The escalation rate is reviewed monthly; when it rose after a plant added a second shift, the policy — not the model — was revised.

What it looks like

  • An enumerated, bounded set of reallocation moves executes without human approval inside stated limits
  • The policy is versioned and reviewed like code, with a named owner and a change log
  • Escalation rate is monitored as a leading indicator that the world has moved outside the policy
  • Rollback to the manual cadence has been exercised deliberately, not just documented

Diagnostic signals you can check this week

  • Ask whether the allocation policy has a version history and who approved the last change
  • Check when the fallback to the manual cadence was last exercised deliberately
  • Confirm escalation rate is trended, not just counted
  • Ask whether a third party could reconstruct any single automated reallocation from the log alone

Anti-pattern · Extending the bounds to decisions the log never covered

Automation that works on intra-OEM plant swaps invites extension to supplier-facing moves, because the mechanism is identical. The evidence is not: no approval log exists for decisions that change a supplier's committed volume, and the first bad automated move typically results in every automated move being switched off. New decision classes re-earn autonomy from their own approval history. No threshold inheritance.

What holds you here

Sustaining autonomy is a governance problem: the constraint becomes policy currency and change control, not modelling.

Highest-leverage next move

Treat the allocation policy as a versioned, reviewed artefact with the same rigour as the model, and trend the escalation rate as its health metric.

Cost of leaving

Effort
Continuous
Team
Supply-network platform team plus a standing allocation governance forum
Risk
Concentrated — low frequency, high consequence, and commercially visible to suppliers

If this is you, the next step is

We run a real scenario against your policy, your bounds and your rollback.

Stress-test an automated reallocation path

Where automotive manufacturers sit on the ladder today

The distribution across the five rungs, and why the mapped-to-signalled transition is the largest single loss.

Most automotive manufacturers are at Tier-n mapped. The shortage years produced a genuine step change in mapping — the majority of OEMs and large tier-1s now hold a part-to-site dataset for their critical electronic commodities that did not exist in 2019 — and a much smaller minority converted that map into a recurring signal from the suppliers who own the data. The distribution below is heavily weighted toward that mapped-but-static middle.

Illustrative distribution of automotive manufacturers across the five rungs

Illustrative, not measured: a model-derived distribution synthesised from published automotive supply-chain research and from public data-space programme reporting. Tier-n mapped is the mode and the plateau — the drop from mapped to signal-shared is the largest single transition loss on the ladder, because it is the one that needs a supplier to agree rather than an OEM to build.

Share of manufacturers

  • 24% — 1 · Tier-1 visible
  • 38% — 2 · Tier-n mapped (the plateau)
  • 24% — 3 · Signal-shared
  • 11% — 4 · Jointly orchestrated
  • 3% — 5 · Self-rebalancing

Source: Illustrative distribution, synthesised from Deloitte automotive research and public Catena-X programme reporting

The scale of that number is the argument for this whole discipline, but the more useful figure is a smaller one. The U.S. Department of Commerce's Bureau of Industry and Security (opens in a new tab) surveyed semiconductor buyers and suppliers in 2021 and reported that the median inventory buyers held had fallen from around 40 days in 2019 to under five days — which is to say the industry had, collectively, removed almost all of the time in which a warning could have been useful. Public policy responded at the supply end: the European Chips Act (opens in a new tab) targets a doubling of Europe's share of global semiconductor production to 20% by 2030. Neither building fabs nor rebuilding buffers changes the fact that an OEM at rung one still cannot say which of its cars a given fab is inside.

The transition that loses the most manufacturers is rung two to rung three, and the reason is worth stating plainly: every previous rung could be reached unilaterally. Mapping is work an OEM can commission and complete on its own timetable. A signal cannot — it requires a supplier, two or three commercial hops away, to agree to send something it has spent thirty years learning not to send. That is why the ladder's steepest step is not a technology step, and why the rest of this page spends more time on disclosure terms, allocation policy and decision rights than on models.

Why multi-tier visibility is a governance problem before a data problem

Suppliers will not name their suppliers, and no integration project changes that. The mechanisms that do work, what each one actually yields, and how deep each one reaches.

Multi-tier visibility fails on consent rather than on connectivity. The data an OEM needs about tier-2 and tier-3 exists, is well structured, and sits in ERP systems that could emit it tomorrow — but it belongs to a company that has a rational commercial interest in not sending it, and that has usually watched a customer use an earlier disclosure as a sourcing or pricing lever. Every technical programme that treats this as an integration problem produces the same artefact: a beautiful pipeline with no upstream.

There are only four mechanisms that move sub-tier information, and they differ enormously in what they yield, what they cost the relationship, and how deep they reach. Most manufacturers use exactly one — the contractual demand — and get exactly what that mechanism is capable of producing, which is a legal-entity list, once, defensively completed.

MechanismWhat it yieldsTypical depthRelationship costWhere it breaks
Contractual disclosure obligationA named list of legal entities, produced once, at the level of granularity the clause forces and no moreTier-2, patchilyLow to give, high to enforceSuppliers comply minimally: entities not sites, aggregate not per-part, last year not this quarter
Reciprocal data exchangeA scoped, recurring assertion — capacity, allocated share, weeks of cover — for named parts under agreed termsTier-2 and tier-3 where the OEM is material to the supplierHigh to negotiate, low to sustainFalls over where the OEM has nothing the supplier wants, or where terms are not machine-enforced
Directed buy or nominationFull commercial visibility of the nominated component, because the OEM is on the contractExactly one tier deeper than the nominationModerate — the tier-1 loses margin and sourcing freedomDoes not scale past the handful of components worth the administrative load
Inference from open and traded dataProbabilistic sub-tier structure from customs records, shipping manifests, certification registers and shortage post-mortemsTier-3 and beyond, unevenlyNone — but no supplier consentedConfidence varies by trade lane and commodity; it informs where to ask, it does not replace an assertion
The four mechanisms that actually move sub-tier information, and the honest limits of each. 'Typical depth' is how far below tier-1 the mechanism reliably reaches in an automotive supply base; 'relationship cost' is what it spends with the supplier.
  • Disclosure is a trade, and most OEMs bring nothing to it

    The single most effective change available to a purchasing organisation is to decide what it will give in exchange for sub-tier data, and to give it first. A firmer frozen forecast horizon, an earlier view of programme volumes, a commitment to a minimum take, or reciprocal visibility of the OEM's own downstream demand are all things suppliers genuinely value and OEMs routinely withhold by default rather than by decision.

  • Purpose limitation is the concession that unlocks the rest

    Suppliers do not fear that the OEM will know their capacity. They fear the purchasing team will know it during the next price round. A data agreement that names the permitted purpose, excludes commercial negotiation explicitly, caps retention and is separately auditable removes the specific fear rather than asking the supplier to trust a general assurance. This is why the automotive data-space work matters operationally and not just architecturally — see the sovereignty section below.

  • Depth should follow consequence, not curiosity

    Mapping to the constraining tier is expensive per part, so it must be rationed by what happens if the part is missing. Classify by line-stop consequence and by substitutability: a fastener with four qualified sources needs no tier-3 map, and a microcontroller with a two-year requalification cycle needs one whatever it costs. Most manufacturers who feel their mapping programme stalled were mapping by commodity structure rather than by consequence.

  • Somebody has to own the network as an object

    Purchasing owns suppliers, plants own lines, S&OP owns the plan, and the network between them is frequently owned by nobody — which is why tier maps rot and why nobody is paged when a disclosure obligation goes unfulfilled. The cheapest structural fix on this page is naming a supply-network owner with a budget and an accountability for the map's freshness. It costs one job title and it changes the decay rate of every artefact below.

It is worth noting how much of the semantic groundwork already exists. The automotive industry has spent four decades agreeing what a delivery forecast, a call-off and a despatch advice mean, through Odette (opens in a new tab) in Europe and AIAG (opens in a new tab) in North America, whose joint MMOG/LE guideline is already the industry's shared vocabulary for supply-chain capability. What none of that infrastructure carries is state: capacity, allocated share and weeks of cover are a different class of assertion from a commitment, and they are the class the supplier side — represented by bodies such as MEMA (opens in a new tab) — has the strongest reasons to guard. The March 2021 fire at a Renesas (opens in a new tab) wafer plant is the cleanest illustration: a single site, several tiers down, simultaneously constraining OEMs who had no commercial relationship with it and, in most cases, no record that it existed in their systems.

Inference deserves a specific note, because it is the mechanism most often oversold. Customs and shipping records, certification registers, published environmental permits and the post-mortems suppliers file after disruptions genuinely do reveal a great deal of sub-tier structure, and a model trained to associate them with your own part numbers is a legitimate and useful thing to build. What it produces is a hypothesis with a confidence attached — good enough to decide where to spend a disclosure conversation, not good enough to underwrite a build plan. Treat inference as a targeting system for the other three mechanisms, and the effort pays back quickly; treat it as a substitute for consent and it produces confident errors at depth, which is the worst failure mode available in this domain.

The allocation decision: who decides which plant loses production

The centre of this discipline is not detection. It is the moment when there are not enough parts and someone must decide which plant, which model and which market goes short — on what basis, and answerable to whom.

The allocation decision is the point at which a supply network stops being an information problem and becomes a governance one: when the parts available are fewer than the parts committed, someone must decide who goes without, and that decision either has a written basis, a named decider and a logged rationale, or it has none of the three and is settled by whoever escalates hardest. Every manufacturer that went through the shortage years has a story about the second kind. Very few have written down the first.

There are five defensible bases for allocating scarce parts across a vehicle programme portfolio. None is right in general; each optimises something real and disadvantages someone real, and the choice is a commercial and strategic one that belongs to executives rather than to a solver. What a model can legitimately do is compute each basis honestly, expose what each costs, and enforce the one chosen — which is a far more useful role than choosing.

Allocation basisWhat it optimisesWho pays for itEvidence it requiresThe model's legitimate role
Contribution margin per unitShort-term profit — high-trim, high-option and premium programmes are built firstVolume programmes, entry trims, and price-sensitive markets whose dealers see empty forecourtsPer-variant contribution against actual build cost, not standard cost — standard-cost ranking is systematically wrong under disruptionCompute and rank the options; never decide, because margin ranking silently overrides contractual and regulatory duties
Contractual commitment firstLegal and financial exposure — fleet contracts, homologation commitments and take-or-pay obligations are honoured before anything elseThe retail order bank, which absorbs the shortfall quietly and shows up later as lost shareA machine-readable register of volume commitments, penalty clauses and their trigger datesDetect which commitments a given shortfall breaches, by when, and at what penalty — a genuinely hard query nobody can run by hand
Fair share by historical offtakeRelationship stability — every plant, region and market takes a proportional cut and nobody can claim favouritismAny programme with a genuine step change in demand, which gets frozen at last year's shapeClean twelve-month offtake baselines, adjusted for known one-offs such as launches, strikes and prior shortagesCompute the shares and flag where the baseline is no longer representative of real demand
Line-stop avoidanceFixed-cost absorption — the most expensive lines and the hardest restarts are protected firstSmaller or newer plants with lower stop cost, which absorb the cuts repeatedlyPer-plant stop cost including restart, labour agreements, and the knock-on cost imposed on tier-1s who must also stopSimulate knock-on stop cost across the network, including at suppliers — the number executives most often guess and most often get wrong
Strategic programme protectionLaunch integrity — new models, regulatory-critical variants and flagship programmes are ring-fenced regardless of near-term economicsMature programmes late in lifecycle, which are cut disproportionately and lose residual valueAn explicit, board-approved list of ring-fenced programmes agreed before the shortage, not during itEnforce the ring-fence as a hard constraint and cost the option, so the board sees what protection is costing
The five allocation bases, what each optimises and who pays for it. The right-hand column is the boundary this page argues for: models compute, rank and enforce; humans choose the basis and own the consequence.

Choosing a basis is only half of it. The other half is decision rights: which role proposes, which role decides, who remains accountable when the decision is reviewed six months later, and what condition forces the decision upward. The table below is the shape that survives contact with a real shortage. It is deliberately boring — the point of a decision-rights table is that it is agreed when nothing is at stake and applied without argument when everything is.

DecisionProposesDecidesAccountable afterwardsEscalation trigger
Which parts enter allocation at allSupply-network control tower, triggered when cover falls below the policy floorCommodity leadHead of purchasingAny safety-relevant or homologation-critical part enters allocation
The allocation basis applied to this shortageControl tower proposes the policy branch and costs the alternativesS&OP executive committeeChief operating officerAny change of basis part-way through a shortage
Which plant loses volume this weekNetwork model, as ranked options with knock-on costRegional manufacturing leadChief operating officerCross-region reallocation, or the same plant cut two weeks running
Which market loses allocationSales and operations planning, against the commitment registerRegional sales leadChief commercial officerAny contractual fleet commitment placed at risk
Whether to buy on the broker or spot marketPurchasing, with provenance risk assessed by qualityHead of purchasingHead of qualityAny part without unbroken traceability to an authorised distributor
Whether to engineer the constrained part outEngineering, with requalification lead time from the network modelProgramme directorChief engineerAny change touching a homologated function or a type-approved system
Allocation decision rights in an automotive network. 'Accountable' is the role that answers for the decision afterwards, which is frequently not the role that made it — and stating both in advance is what makes the arrangement hold under pressure.

Running an allocation cycle without losing the plot

  1. Convert the shortfall into units of build, not units of part

    A supplier's allocation notice arrives in pieces per week. It becomes decidable only when the network model translates it into vehicles per programme per plant, because that is the unit in which every downstream consequence — commitments, dealer orders, plant employment — is denominated. Teams that skip this step spend the first two days arguing about a number nobody can act on.

  2. Publish the basis before publishing the numbers

    State which allocation basis is being applied and why, to everyone affected, before anyone sees who wins and who loses. The identical decision reads as a rule when the basis came first and as a manoeuvre when it came second, and that perception determines whether the next cycle can run at all.

  3. Cost the alternatives you rejected

    Publish what the other bases would have produced. It looks like extra work and it is the mechanism that keeps the policy honest: an executive who can see that fair-share would have cost eleven hundred fewer units than the chosen protection of a launch programme is making a real decision rather than ratifying an output.

  4. Log the rationale in a form a third party could read

    Basis applied, options considered, decision taken, who took it, what evidence was in front of them, what the escalation triggers were. Six months later this record is the difference between a defensible commercial decision and an unexplainable one, and the parties asking will include suppliers, dealers, works councils and occasionally auditors.

  5. Close the loop with the suppliers who gave you the signal

    Tell the tier-2 that shared its capacity assertion what happened as a result. This is the step everybody drops and the one that determines whether the signal still arrives next quarter — suppliers sustain disclosure when they can see it changed something, and stop when it disappears into a customer's black box.

The reason this section sits at the centre of the page rather than at the end is that allocation is the decision the entire orchestration stack exists to serve. Every rung below it — the map, the signal, the shared model — is instrumentation for this moment, and instrumentation without a decision rule produces better-informed chaos. Manufacturers who write the allocation policy first frequently find that the visibility investments they were about to make change shape, because the policy names precisely which numbers the decision actually needs.

What multi-tier orchestration looks like in public

Three publicly documented programmes, read against the ladder: one OEM that mapped in depth a decade early, one that bought authority it did not have, and the consortium that made sovereign sharing possible.

The public record from the shortage years is unusually informative, because the responses were announced rather than inferred. Three of them map cleanly onto three different rungs of this ladder, and taken together they make the argument better than any single case can: depth of map, reach of authority and terms of sharing are separate capabilities, and a manufacturer can be strong in one and helpless in the others.

Three programmes read against the orchestration ladder

Outcomes as reported by the operators themselves or by their industry consortium; we have not independently audited them, and none is an Atomic Loops engagement. Card images are illustrative generated scenes from our automotive library, not photographs of the named organisations, and imply no endorsement or association.

Illustrative scene: planners at a supply-network wall showing global part flows inside a vehicle plantToyota Motor CorporationGlobal OEM · multi-tier parts database maintained since 201113
Challenge
The 2011 Tōhoku earthquake showed that even the industry's most disciplined production system could not answer quickly which of its vehicles depended on which sub-tier plant. The just-in-time model Toyota had pioneered removed the buffer that would have made a slow answer survivable.
Approach
Toyota invested in a maintained supplier and parts database reaching well below tier-1, and paired it with a business-continuity policy that asked semiconductor and other long-lead suppliers to hold buffer stock sized in months rather than days — an explicit, deliberate exception to just-in-time for parts whose replacement lead time made JIT unsafe.
Reported outcome
Toyota's own published material describes the production system and the continuity thinking behind it, and its newsroom carries the record of monthly production plans and their revisions through the 2021 shortage — a chain that absorbed the first wave of the shortage on buffer and was eventually forced to revise plans when the second wave closed South-East Asian plants.
What it shows about the curveDepth of map is a decade-scale asset and it is not sufficient on its own. Toyota reached rung three earlier than the industry because it had both the graph and a state signal from suppliers — and it still lost volume, because a map plus buffer does not confer authority over a fab you do not contract with.

Toyota Global Newsroom and Toyota Production System (opens in a new tab)

Illustrative scene: a global supply-flow map projected over a vehicle assembly line with tracked inbound containersGeneral MotorsGlobal OEM · North America-led semiconductor sourcing change24
Challenge
GM found in 2021 that its semiconductor exposure sat two and three tiers below its direct suppliers, at foundries with which it had no commercial relationship, buying a long tail of unique microcontroller part numbers specified programme by programme over decades.
Approach
GM publicly announced agreements to work directly with semiconductor manufacturers on co-development and dedicated capacity, alongside a design-side programme to consolidate the sprawl of unique chips into a small number of standard microcontroller families used across the portfolio.
Reported outcome
GM stated publicly that the strategy would see the great majority of its microcontrollers consolidated into three families sourced under direct agreements with named chip suppliers — a change to who GM contracts with, not merely to how well it forecasts.
What it shows about the curveThis is the orchestration-authority move in its purest form. GM did not improve its visibility of the constraining tier; it changed the contract boundary so that the constraining tier became a party it could actually direct. Visibility tells you where the constraint is. Only the contract lets you move it.

GM corporate newsroom (opens in a new tab)

Illustrative scene: supply-network specialists reviewing a cross-tier data flow overlay on an assembly floorCatena-X Automotive NetworkIndustry consortium · OEMs, tier-n suppliers, software and infrastructure providers24
Challenge
No OEM can compel its suppliers' suppliers to share operational data, and no supplier can afford to build a bespoke integration for each of its customers' customers. The result before Catena-X was a network in which the only scalable answer to a cross-tier question was a survey.
Approach
Catena-X built a federated automotive data space on data-sovereignty principles: participants keep their data in their own systems and answer defined questions through standardised connectors that carry usage policies with the payload, under a governance model the association publishes. Its Demand and Capacity Management use case is the orchestration-specific one — a standard way for a customer and a supplier to exchange demand forecasts and capacity commitments and to surface the mismatch between them.
Reported outcome
The association publishes its standards, its governance and its use-case catalogue openly, and Demand and Capacity Management operates alongside traceability and product-carbon-footprint as a live cross-tier use case — evidence that the sharing problem yields to sovereignty guarantees rather than to mandate.
What it shows about the curveThe mechanism that unlocks rung three is not a pipeline; it is a credible promise about what the receiver may do with what it receives. Once that promise is machine-enforced and auditable by the sender, a recurring capacity signal becomes cheaper for the supplier than the phone call it replaces.

Catena-X Automotive Network (opens in a new tab)

Read together, the three cases separate capabilities that are usually conflated. Toyota shows that a deep, maintained map plus supplier-held buffer buys time and does not buy control. GM shows that control is bought with contracts, and that the design organisation is as much a lever as the purchasing one — consolidating microcontroller families is an engineering decision with a supply-network purpose. Catena-X shows that the sharing problem has an institutional solution, and that it took an industry consortium rather than any single OEM to build it: the founding members include BMW Group (opens in a new tab) and Volkswagen Group (opens in a new tab), both of which publish their own accounts of the programme. No manufacturer reaches rung four on one of the three alone.

Orchestration authority: you can direct what you buy, not what your supplier buys

The boundary every orchestration programme eventually hits, tier by tier — what an OEM can command, what it can influence, what it cannot see, and the specific mechanism that moves each line.

Orchestration authority is the reach of an OEM's ability to actually change something, and it ends precisely where its contracts end. Below tier-1 an OEM has specification power, approved-vendor influence, quality gates and goodwill — all real, none of them instruction rights. This is the boundary that turns an excellent visibility programme into an exercise in watching a problem approach, and it is the dimension most often misdiagnosed, because 'we could not act' is easily mistaken for 'we did not know'.

Where the constraint sitsWhat the OEM can directWhat it can only influenceWhat it cannot see by defaultThe mechanism that changes this
Tier-1 — assembly, modules, systemsCall-off volume and timing, delivery windows, packaging, just-in-sequence build orderTheir capital plan, shift pattern and sub-supplier choicesTheir order book for other customers, and how they would allocate under stressA capacity agreement with take-or-pay and a published, firm forecast horizon in exchange
Tier-2 — components, sub-assemblies, semiconductorsNothing directly, unless a directed buy or nomination is in placeSpecification, approved-vendor list, quality gates and requalification requirementsHow the tier-2 allocates between your own tier-1s, which can silently undo a dual sourceDirected buy or nomination with the OEM on the contract, or a data-space capacity signal
Tier-3 and below — die, wafer, packaging, resins, connectorsNothing at allVery little; you are frequently not a named customer anywhere in their systemEverything, including whether two of your tier-1s depend on one plantDirect capacity reservation with the constraining supplier, or design-side consolidation to fewer part families
Inbound logistics and transportRouting, mode and expedite authority on freight you controlYour suppliers' own inbound freight decisionsPort, lane and border congestion affecting sub-tier inputsInbound-to-manufacturing control of supplier freight, or a shared logistics visibility feed
Raw materials and refined inputsNothingThrough specification, approved sources and long-term offtakeMine, refinery and smelter-level exposure behind your named suppliersOfftake agreement, or participation in a traceability scheme that reaches the material
What an OEM can actually direct, by where the constraint sits. The right-hand column is the only thing that moves a row leftward — every one of these mechanisms is a commercial decision with a cost, not a systems project.

Plotting your position on the two axes that matter — how deep you can see, and how far your contracts reach — produces four postures with genuinely different remedies. The uncomfortable one is the top-left: manufacturers who invested seriously in mapping after 2021 and can now watch a constraint form in high resolution without holding a single lever that moves it.

Diagnosing your real constraint: authority against visibility

Plot multi-tier visibility against orchestration authority. Three of the four quadrants have remedies that are commercial rather than technical, which is the central practical finding of this page.

Informed spectator

  • You see the constraint forming and hold nothing that moves it
  • The common landing place for post-2021 mapping programmes
  • Fix: convert visibility into a commitment — directed buy or capacity reservation on your top three constrained parts

Orchestrator

  • You can see it and you hold a lever on it
  • The only quadrant where joint rebalancing is genuinely available
  • Fix: publish the allocation policy before the next shortage rather than during it

Exposed

  • The industry's default position in 2020
  • Every disruption is discovered on the goods-in dock
  • Fix: map the twenty parts with the highest line-stop consequence to the constraining tier

Blind leverage

  • Commitments at a depth you cannot verify
  • Take-or-pay on capacity you cannot see being consumed
  • Fix: attach a reporting obligation to every capacity agreement you already hold
Multi-tier visibility — top: Part-to-site graph, refreshed, bottom: Tier-1 only
Orchestration authority — left: You can only ask, right: You hold the commitment

One further authority lever is routinely overlooked because it does not live in purchasing at all. Design decides how many distinct part numbers the network has to carry, and a portfolio that specifies a different microcontroller per programme has made itself unorchestratable by engineering choice. Consolidating to fewer, larger, longer-lived part families increases substitutability, raises the OEM's volume with each supplier — which is the only thing that makes a supplier care about your capacity request — and shortens requalification when a source is lost. It is the slowest lever on this page and frequently the largest.

Data sovereignty and the orchestration stack

Why Catena-X matters operationally rather than architecturally, and what has to exist beneath a network model before it can be trusted with a build decision.

Data sovereignty is the guarantee that a supplier keeps control of its data after sending it — and in supply-network orchestration it is the enabling condition rather than a compliance nicety. A tier-2 that can see, in machine-enforced terms, that its capacity assertion may be used for build planning and not for sourcing, that it expires after ninety days, and that access can be revoked, is being asked a bounded question. The same tier-2 asked to email a spreadsheet is being asked to trust an organisation whose purchasing team it will negotiate with next quarter.

That is the specific problem the automotive data space addresses. Catena-X (opens in a new tab) builds on the sovereignty architecture developed by the International Data Spaces Association (opens in a new tab) and the federated-infrastructure principles of Gaia-X (opens in a new tab): verifiable participant identity, connectors that carry usage policies alongside the payload, and a published association governance model (opens in a new tab) that makes the rules a shared artefact rather than a bilateral negotiation repeated three hundred times. Its Demand and Capacity Management use case is the one this page cares about — a standard way to exchange demand forecasts and capacity commitments across a tier boundary and to make the mismatch between them visible to both sides. The traceability and compliance use cases matter too and are covered on the compliance and supply-chain security page; here the relevant point is narrower and more practical: sovereignty is what makes a recurring operational signal commercially survivable.

  • Purpose limitation that a machine enforces

    The usage policy travels with the data and the connector applies it, so 'planning use only, not sourcing' is a control rather than a promise. This single guarantee resolves the most common and most legitimate supplier objection, and it cannot be replicated by a clause in a master agreement that nobody can verify was honoured.

  • Revocability with a real effect

    A supplier that can withdraw access, and see that withdrawal take effect, is exposed to a bounded risk rather than an open-ended one. Counter-intuitively, revocability increases the volume of data shared: parties disclose more when leaving is cheap, which is the same dynamic that makes short-notice contracts easier to sign than long ones.

  • Symmetry, so the OEM is also a sender

    The arrangements that last are two-way. An OEM that emits a firm forecast horizon, an early programme-volume view or a reciprocal cover position through the same channel is a participant rather than a collector, and suppliers treat the signal accordingly. Asymmetric data spaces decay into compliance portals within a year.

  • Standard semantics, so the answer means the same thing everywhere

    The unglamorous half of the work is agreeing what 'capacity', 'committed', 'weeks of cover' and 'allocated share' mean, in one model, across hundreds of companies. This is what industry bodies do well and what no individual OEM can do at all — and it is why the automotive EDI standards from Odette, VDA and AIAG remain the closest analogue to what a data space is attempting for a harder class of assertion.

The orchestration stack, layer by layer

Each layer is annotated with the rung that first requires it. A manufacturer building a network model without the tier map beneath it has a beautiful simulation of a supply base it cannot describe.

  1. Systems of record

    Stage 1+

    • ERP / MRPPart master, BOM structure, requirements
    • APS and S&OPWhere the build plan and call-offs are actually decided
    • Purchasing and supplier masterContracts, nominations, capacity agreements
    • Plant and inbound logisticsCall-off, ASN and JIS sequencing execution
  2. Tier map and product graph

    Stage 2+

    • Part-to-site graphNamed manufacturing sites, not just legal entities
    • Criticality classificationLine-stop consequence × requalification lead time
    • Shared-dependency detectionFinds the dual sources that are secretly single
  3. Sovereign exchange layer

    Stage 3+

    • Data-space connectorUsage policy travels with the payload
    • Verifiable participant identityWho is asking, and on whose behalf
    • Data contract registryPurpose, retention, revocation, audit trail
  4. Network model layer

    Stage 3+

    • Digital twin of the networkParts, sites, capacity, commitments as one graph
    • Scenario engineFire, flood, closure, allocation notice — run in minutes
    • Cover and constraint monitoringWeeks of cover per part, per plant, live
  5. Allocation and response layer

    Stage 4+

    • Allocation policy engineVersioned basis, applied as a constraint
    • Joint rebalancing workflowShared options across OEM, tier-1 and tier-2
    • Decision logBasis, options, decider, evidence — reconstructable

Pipeline described

  1. Systems of record (stage 1+) — ERP / MRP: Part master, BOM structure, requirements; APS and S&OP: Where the build plan and call-offs are actually decided; Purchasing and supplier master: Contracts, nominations, capacity agreements; Plant and inbound logistics: Call-off, ASN and JIS sequencing execution
  2. Tier map and product graph (stage 2+) — Part-to-site graph: Named manufacturing sites, not just legal entities; Criticality classification: Line-stop consequence × requalification lead time; Shared-dependency detection: Finds the dual sources that are secretly single
  3. Sovereign exchange layer (stage 3+) — Data-space connector: Usage policy travels with the payload; Verifiable participant identity: Who is asking, and on whose behalf; Data contract registry: Purpose, retention, revocation, audit trail
  4. Network model layer (stage 3+) — Digital twin of the network: Parts, sites, capacity, commitments as one graph; Scenario engine: Fire, flood, closure, allocation notice — run in minutes; Cover and constraint monitoring: Weeks of cover per part, per plant, live
  5. Allocation and response layer (stage 4+) — Allocation policy engine: Versioned basis, applied as a constraint; Joint rebalancing workflow: Shared options across OEM, tier-1 and tier-2; Decision log: Basis, options, decider, evidence — reconstructable
Step-by-step insights
Systems of record — the build plan is the only decision that counts
Orchestration outputs are worthless unless they reach the APS and the call-off. This is the automotive-specific version of the write-back discipline: a constraint alert that appears in a control-tower dashboard changes nothing, while the same alert expressed as a revised call-off in the planning system changes what a supplier ships next week. Sequence the integration work toward the planning system early, even when the model is crude, because a crude number in the right place beats a precise number in the wrong one.
Tier map — sites, not companies, and consequence, not coverage
Two design decisions determine whether a tier map is useful. First, record manufacturing sites rather than legal entities: a supplier group with eleven plants is eleven different risk positions, and a fire affects one of them. Second, ration depth by consequence rather than pursuing coverage: mapping every commodity to tier-3 is a two-year project that ages at both ends, while mapping the twenty parts that stop a line is a quarter's work that pays back on the first incident.
Sovereign exchange — the registry is the part people skip
Connectors are the visible half; the data contract registry is the half that determines whether the arrangement survives an audit or a dispute. It records, per exchange, what was shared, for what purpose, under what retention, and who may query it — and it is what lets an OEM prove to a supplier that a capacity disclosure did not reach a purchasing negotiation. Build it as an operational system with an owner, not as a compliance artefact assembled on request.
Network model — traverse first, learn later
The highest-value queries against a network model are graph traversals, not predictions: which programmes does this site touch, which of my dual sources share a sub-tier plant, how many weeks until the first line stops. Learned components belong at the edges — lead-time drift from despatch variance, sub-tier inference from customs and shipping records, document classification into the graph. A model-first build demonstrates impressively and cannot answer the question an executive will ask in the first hour of a real disruption.
Allocation and response — the log is the deliverable
At rung four the decision log looks like administrative overhead and at rung five it is the artefact that makes automation defensible. It also has an unexpected second use: a year of logged allocation decisions, each with its basis and outcome, is the dataset that tells you which moves humans always approved and therefore which are safe to delegate. Manufacturers who automate without that log are setting bounds from judgement, which works until the first genuinely unusual week.

One caution about the stack: the layers are ordered by dependency, not by budget. The sovereign exchange layer is the cheapest layer to build and the most expensive to negotiate, and manufacturers routinely under-resource the negotiation because it appears on no engineering plan. Staff the commercial side of layer three as seriously as the technical side, or the connectors will be sitting idle with nothing flowing through them.

The four dimensions that set your rung

Orchestration maturity is not one number. Four dimensions gate each other, and the lowest is your real rung — because each one caps what the others can be used for.

Orchestration maturity is scored on four dimensions — multi-tier visibility, data sovereignty and sharing, orchestration authority, and disruption response readiness — and the lowest of the four is the real rung, because each gates the others. A superb network model fed by an annual survey answers last year's question; a live signal into an organisation with no allocation policy produces a faster argument; and authority over a tier you cannot see is a take-or-pay contract you cannot audit.

  • Multi-tier visibility

    How deep the part-to-site graph reaches, how it is refreshed, and whether it records sites or companies. The binding question is whether a named disruption resolves to part numbers and programmes without anybody sending an email. This dimension is the one most manufacturers have invested in since 2021, and it is frequently no longer the constraint by the time they finish.

  • Data sovereignty and sharing

    Whether sub-tier information arrives because someone sends it or because someone asked. The mechanism is a data contract with purpose limitation, retention and revocation, ideally machine-enforced through a connector rather than asserted in a master agreement — which is where the automotive data-space work (opens in a new tab) earns its place in an operational discussion rather than an architectural one.

  • Orchestration authority

    How far your contracts reach relative to where your constraints sit. This is the dimension most often misdiagnosed as a visibility problem, because both present as an inability to act. It is also the only dimension whose remedies are entirely commercial — nomination, directed buy, capacity reservation, offtake, and design-side part consolidation — and therefore the one an engineering roadmap will never fix.

  • Disruption response readiness

    Whether the response is rehearsed or improvised, measured as elapsed time from a public event to a quantified impact on the build plan. The strongest predictor is not team quality; it is how much of the analysis was pre-built. Manufacturers that rehearse disruptions which never happened are, by the time a real one arrives, doing it for the second time.

DimensionWhat it gatesThe question that reveals it in one minuteThe rung it caps you at when weak
Multi-tier visibilityWhether you can name a constraint before it arrives at the dockWhich plant manufactures the microcontroller in your body control module?Rung 1 — you can react well, and only after the fact
Data sovereignty & sharingWhether the map stays true without a survey campaignWhat can a supplier see about how you used the data they sent you?Rung 2 — mapped, static, and quietly decaying
Orchestration authorityWhether visibility converts into a change anyone has to honourWho can change a tier-2 commitment this week, and under which contract?Rung 3 — well informed, planning with parties who cannot commit
Disruption response readinessWhether the response is a capability or a heroic scrambleHow long from headline to quantified build-plan impact, last time?Rung 4 — nothing is safe to automate without a drilled fallback
How each dimension caps the rest. Read your weakest row: the right-hand column is the rung you are held at until it is fixed, regardless of how strong the other three are.

The practical use of the four dimensions is sequencing. A manufacturer whose lowest score is authority should not fund another mapping phase, however comfortable that would be; it should be negotiating a nomination or a capacity reservation on its three most constrained parts. A manufacturer whose lowest score is sharing should not build a network model yet — the model will be fed by the same annual survey and will report last year's network with great precision. Fix the floor, not the ceiling.

A 90-day plan: a live capacity signal behind one ECU family

The mapped-to-signalled transition made concrete on one automotive problem — the microcontroller behind a single safety-relevant ECU family, from BOM explosion to a rehearsed disruption. Contains no platform build.

Moving one rung takes about 90 days when it is scoped to a single part family, and several years when it is scoped to a supply base. To make that concrete, the plan below runs the rung two to rung three transition on the problem most automotive manufacturers actually have: one safety-relevant ECU family whose microcontroller supply is opaque below the module maker. There is no platform in this quarter and no data-space membership required to start — the deliverable is one working signal and one rehearsed response, both of which are reusable patterns rather than one-offs.

Rung 2 → rung 3 on one ECU family, in one quarter

One part family, one tier-1, one tier-2, one named owner. If a phase needs longer than its window, narrow the scope — fewer part numbers, one plant — rather than extending the plan.

  1. Days 1–15

    Explode the BOM to the constraining tier

    Take one safety-relevant ECU family and trace it from your part number through the module maker to the microcontroller, the packaging step and the substrate. Record manufacturing sites, not legal entities. Establish requalification lead time for each element with engineering, and compute line-stop consequence per day across every plant that builds a vehicle containing it. Name a supply-network owner accountable for this dataset.

    A part-to-site graph for one family, with consequence and lead time attached

  2. Days 16–45

    Negotiate one reciprocal data contract

    Agree with the tier-1, and through it the tier-2, a scoped quarterly assertion: committed capacity for the named part, your allocated share, weeks of cover at their inbound, and a validity window. Write the purpose limitation explicitly — planning use, excluded from commercial negotiation — with retention capped and revocation available. Offer something back in the same document: a firmer frozen horizon or an earlier programme-volume view. Legal and purchasing lead; engineering is not on the critical path here.

    One signed data contract and the first assertion received

  3. Days 46–70

    Put weeks of cover on the S&OP screen and write the policy

    Land the assertion in the planning cadence as a live weeks-of-cover figure per plant, in the screen the S&OP team already uses, with a stated floor that triggers review. In parallel, draft the allocation policy for this commodity: which basis applies, who proposes, who decides, who is accountable afterwards, and what escalates. Get it signed while there is no shortage.

    Live cover in the planning cadence; a signed allocation policy

  4. Days 71–90

    Rehearse a disruption that did not happen

    Invent a plausible event — a two-week closure at the packaging site — and run it end to end with the real people. Time how long from the scenario being read out to a quantified impact on the build plan, apply the allocation policy for real, and log the decision as though it counted. Capture what was missing and fix it. Then tell the tier-2 what the exercise found, which is what earns the next quarter's assertion.

    A measured response time, a tested policy, and a supplier who saw the loop close

The order matters

  1. Map before you monitor

    A risk feed without a part-to-site graph produces alerts that resolve to nothing, and teams mute it. With the graph in place, the same feed becomes the cheapest layer on this page. Fifteen days of BOM work changes what every later tool is worth.

  2. One signal before any platform

    The temptation after the first successful exchange is to build the general case — a supplier portal, a connector fleet, an onboarding programme. Do the second and third commodity by hand first. The shape of the general case is visible after exchange three and is guesswork before exchange one, and the negotiation pattern matters far more than the pipeline.

  3. Policy before the shortage, always

    An allocation policy written during a shortage is read as a manoeuvre by whoever it disadvantages and is renegotiated in every subsequent cycle. The same policy written in a quiet quarter is read as a rule. This is the highest-return hour on the whole plan and it consumes no engineering capacity at all.

The reason this plan starts with an ECU family rather than with a commodity group is substitutability. Electronics carry the longest requalification lead times in the vehicle, which means they are the parts where advance warning is worth the most and where a two-week head start genuinely changes the outcome. A fastener shortage is solved with a phone call and a courier; a microcontroller shortage is solved eighteen months earlier or not at all.

Disruption response as a rehearsed capability, not a heroic scramble

The playbook by event type, a readiness checklist you can tick today, and the four failure modes that quietly send manufacturers back down the ladder.

Disruption response is a rehearsed capability when the analysis is pre-built and a heroic scramble when it is not — and the distinction is visible within the first four hours of any real event. Manufacturers who can convert a headline into affected part numbers, programmes and volumes before lunch are not staffed better; they are running a query against a graph that already existed. Everybody else spends those four hours deciding who should be in the room. This is the operational content behind the resilience language that has dominated World Economic Forum (opens in a new tab) supply-chain discussion since 2020: resilience is not a posture or a buffer policy, it is a measured elapsed time from event to decision, and it can be rehearsed the way a plant rehearses an evacuation.

TriggerFirst 4 hoursFirst 48 hoursFirst 2 weeksNamed owner
Sub-tier site event — fire, flood, earthquakeRun the affected site through the part-to-site graph; produce affected part numbers, programmes and daily build exposureConfirm weeks of cover per plant; open a joint call with the tier-1 and, where a signal exists, the tier-2Qualify an alternate source or re-sequence build; update the allocation policy trigger if cover floors were wrongCommodity lead, escalating to head of purchasing
Semiconductor allocation noticeConvert pieces-per-week into vehicles per programme per plant; identify which commitments the shortfall breachesDecide and publish the allocation basis; brief every affected plant and market before the numbers circulateNegotiate directed capacity or a nomination; re-sequence trim and option content within the agreed envelopeS&OP executive committee
Tier-1 insolvency or capacity withdrawalIdentify every part, tool and fixture held at that supplier, including tooling ownership and locationSecure tooling and finished stock physically; run resourcing lead time through the network modelExecute resourcing or bridge with buffer; renegotiate the sub-tier relationships that came with the toolingHead of purchasing, with legal
Logistics closure — port, canal, border, strikeIdentify inbound in transit and which parts it covers; compute days of cover on the affected lanesRe-mode the critical subset and recost; confirm the change does not break JIS sequencing at the plantRebuild the inbound plan; renegotiate freight and reassess lane concentration in the tier mapInbound logistics lead
Export control or sanctions changeScreen the tier map for affected origins, entities and material classesHalt affected flows; assess re-sourcing options and the requalification clock for eachRequalify components and document the change through the engineering change processTrade compliance lead, with purchasing
The response playbook by event type. The first-four-hours column is the one that distinguishes rehearsed from improvised: in every row it is a query against pre-built structure, not a meeting.

Rung 3 readiness checklist

If you cannot tick all seven, you are still at rung two however good your tier map is. Tick as you go — this list is server-rendered and works without JavaScript.

0 of 7 ticked

Tick honestly — the blank list is data too

Most manufacturers can genuinely tick one or two, not zero. If none apply yet, do not start with tooling: take one safety-relevant ECU family and run the 90-day plan above. Every item on this list falls out of doing that once, and the second family costs a fraction of the first.

Likelihood: highImpact: high

The tier map decays and nobody notices

Suppliers requalify sub-suppliers and move production between their own plants continuously, and none of it is reportable unless someone made it so. A map that answered correctly last March answers confidently and wrongly this March, which is worse than having no map, because the confident wrong answer gets acted on.

PreventionA staleness SLA per criticality class, an owner who is paged when it lapses, and a refresh obligation attached to the commercial relationship rather than to goodwill.

Likelihood: mediumImpact: high

The signal is used for sourcing and the supplier stops sending it

A capacity disclosure reaches a purchasing negotiation — usually innocently, through a shared report — and the supplier concludes the arrangement was never bounded. Recovery is close to impossible: the next request is answered with an aggregate figure, and the tier-2 tells its peers.

PreventionMachine-enforced purpose limitation through the connector, with an audit trail the supplier can query themselves rather than a promise they must take on trust.

Likelihood: mediumImpact: high

Allocation policy is rewritten mid-shortage to fit the answer somebody wanted

A basis is agreed, produces an unpopular result for a powerful plant or market, and is amended. The policy then has no authority in any subsequent cycle, and every allocation reverts to escalation — which is the state the policy existed to replace.

PreventionVersion the policy, require an executive-committee decision to change the basis mid-shortage, and log every change with its rationale alongside the decisions it affected.

Likelihood: mediumImpact: medium

The network model outlives the assumptions it was built on

New plants, supplier consolidations and design changes alter the graph, while the model keeps answering against the old topology. Because it still returns plausible numbers, the drift is invisible until a scenario returns an answer that is confidently wrong at exactly the moment it matters.

PreventionRe-run last year's rehearsal scenarios each quarter and compare answers; a changed answer with no changed input is the alarm that the graph moved beneath the model.

Glossary

Hover a term for its definition — or expand the map full screen. The full definitions are written out below.

Tier-n
Any supplier below tier-1 — the tier-2, tier-3 and deeper plants an OEM has no contract with and, by default, no visibility of. Automotive supply bases routinely run five or more commercial hops deep on electronic components.
Part-to-site graph
The dataset mapping each part number to the actual manufacturing sites that produce it and its inputs, tier by tier. Records sites rather than legal entities, because a supplier group with eleven plants is eleven separate risk positions.
Sub-tier concentration
The condition in which two or more nominally independent suppliers depend on a single deeper plant — a shared wafer fab, resin grade or connector line — so that a dual source at tier-1 is a single source in reality.
Directed buy
An arrangement in which the OEM negotiates a component's commercial terms directly with a sub-tier supplier while the tier-1 continues to buy and integrate it. The principal mechanism by which an OEM acquires authority one tier deeper than its own contracts reach.
Allocation policy
The versioned, written basis on which scarce parts are distributed across plants, programmes and markets, together with the decision rights that name who proposes, who decides and who remains accountable afterwards.
Weeks of cover
Available stock of a part expressed as weeks of forward build at current rate, computed per part and per plant. The single most useful state figure in a supply network, and the one most often available only in aggregate.
Data sovereignty
The guarantee that the sender of data retains control over how it is used after transmission — enforced through usage policies that travel with the payload, verifiable identity and revocable access, rather than asserted in contract text.
Data-space connector
The software component through which participants in a federated data space exchange information, applying the sender's usage policy at the point of transfer and recording the exchange for later audit by either party.
Demand and capacity management (DCM)
The Catena-X use case in which a customer and a supplier exchange demand forecasts and capacity commitments across a tier boundary in a standard form, so that the mismatch between them is visible to both sides before it becomes a shortage.
Digital twin of the network
A maintained model of the supply network as a graph of parts, sites, capacities and commitments, against which disruption scenarios can be run. Its value comes primarily from traversal rather than from prediction.
Just-in-sequence (JIS)
Delivery of parts in the exact order in which vehicles will be built, typically minutes ahead of the line. It removes the last buffer between a supply interruption and a stopped line, which is why automotive cannot treat sub-tier warning time as optional.
Rehearsed response
A disruption playbook that has been exercised against the live network model with the real decision-makers, timed, and updated from what the exercise found — as distinct from a business-continuity document that has never been opened under pressure.

Frequently asked questions

The questions purchasing, planning and manufacturing leaders ask most often when they start treating the supply base as a network rather than as a list.

What is AI-driven supply network orchestration in automotive?

It is the practice of planning, allocating and rebalancing an automotive supply base across every tier at once, rather than one contractual hop at a time. It combines a maintained part-to-site graph, scoped signals from sub-tier suppliers, a network model that can run disruption scenarios, and a written allocation policy for deciding who goes short. AI contributes at the edges — inferring undisclosed relationships, predicting lead-time drift, ranking allocation options — while the core is a graph problem and a governance problem.

Why could automotive OEMs not see the semiconductor shortage coming?

Because their systems modelled the supply base as a list of contracted tier-1 suppliers rather than as a graph of parts and sites. The constraint sat three or four commercial hops away at foundries and packaging plants with which no OEM had a relationship, and nothing in a supplier master records that two independent module makers buy from one fab. The information existed inside the suppliers who held it; the structure to receive it did not exist anywhere. Just-in-time then removed the buffer that would have made a slow answer survivable.

How do you map suppliers below tier-1 when they will not disclose?

Combine four mechanisms in order of durability. A contractual disclosure obligation gives you a legal-entity list once and is a floor rather than a strategy. A reciprocal data exchange — you give a firmer forecast horizon, they give capacity and cover under purpose-limited terms — produces a recurring signal and is the only mechanism that scales. A directed buy or nomination gives full visibility exactly one tier deeper, for the handful of parts worth the administrative load. Inference from customs and shipping records tells you where to spend the other three.

Is Catena-X a supply-chain visibility tool?

No. Catena-X is a federated data space with sovereignty controls — it defines how participants exchange defined information while the sender keeps control of what the receiver may do with it. It is not a database an OEM can query for its supply base. Its relevance to orchestration is that it removes the specific reason suppliers withhold operational data: usage policies travel with the payload, access is revocable, and the exchange is auditable by the sender. Its Demand and Capacity Management use case is the orchestration-specific one.

Who should decide which plant loses production when parts are short?

A named role, against a written basis agreed before the shortage. In practice the regional manufacturing lead decides the weekly plant-level call, the S&OP executive committee decides which allocation basis applies, and the chief operating officer remains accountable afterwards. What matters more than the specific assignment is that all three are written down in advance, that the basis is published before the numbers are, and that every decision leaves a logged rationale a third party could read six months later.

Can AI make the allocation decision itself?

It can compute, rank and enforce; it should not choose the basis. Selecting between margin, contractual commitment, fair share, line-stop avoidance and strategic protection is a commercial and strategic judgement with consequences for employment, dealer relationships and regulatory programmes — and a solver optimising one objective will silently override the others. The legitimate and valuable role is to translate a shortfall into vehicles per programme per plant, cost every basis honestly so executives see the trade-off, and then enforce the basis chosen as a hard constraint.

What is a digital twin of the supply network, and what does it actually need?

It is a maintained graph of parts, sites, capacities and commitments against which you can run scenarios. It needs three things most programmes underestimate: a part-to-site graph that records manufacturing sites rather than legal entities, a state signal so capacity and cover are current rather than annual, and an integration into the planning system so its output becomes a revised call-off rather than a dashboard. Most of its value comes from graph traversal — which programmes does this fire touch — not from machine learning.

How is this different from buying a supply-chain risk monitoring service?

Risk monitoring tells you that something happened somewhere; orchestration tells you what it means for your build plan and what to do about it. A monitoring feed is genuinely valuable once you hold a part-to-site graph, because every alert then resolves to part numbers, programmes and volumes. Bought first, it produces alerts about sites you cannot connect to anything you make, and teams reliably mute it within two quarters. Sequence the graph first and the same subscription becomes one of the cheapest layers in the stack.

Do we need a directed-buy strategy to orchestrate at tier-2?

Not to see tier-2, but usually to change anything there. Visibility can be obtained through reciprocal data exchange without touching the commercial structure. Authority cannot: below tier-1 an OEM has specification power and influence but no instruction rights, so a constraint it can see remains a constraint it cannot move. Directed buys and direct capacity reservations are how that changes, and because both carry real administrative and relationship cost they should be reserved for the handful of parts where line-stop consequence and requalification lead time are both high.

How long does it take to move one rung on this ladder?

About 90 days scoped to one part family, and several years scoped to a supply base. The rung-two-to-three transition is the one worth timeboxing, because it is dominated by a commercial negotiation rather than by engineering: a part-to-site graph for one ECU family takes a fortnight, and agreeing the reciprocal data contract behind it takes a month. Moving to joint orchestration takes longer, typically eighteen months or more, because it requires suppliers to change their own planning cadence, not just to send you data.

What does a rehearsed disruption response actually look like?

You invent a plausible event — a two-week closure at a mapped packaging site — and run it end to end with the people who would really be in the room. You time three stages: headline to affected part numbers, affected parts to quantified build impact, build impact to a decision with a logged rationale. You apply the allocation policy for real rather than discussing it. Then you fix what was missing and tell the suppliers who supplied the data what the exercise found, which is what earns next quarter's signal.

Does any of this apply to a tier-1 supplier, or only to OEMs?

It applies more sharply to a tier-1, because a tier-1 faces both directions at once. Upward it must answer increasingly specific OEM questions about its own sub-tier exposure; downward it has exactly the same blindness the OEM has, one tier further along. The ladder is identical and the economics are better: a tier-1 that can emit a credible capacity assertion cheaply becomes materially easier to buy from, and the same maintained graph serves both the customer answers and its own allocation decisions.

About the author

Atomic Loops Engineering

Industrial AI practice

Atomic Loops builds production AI systems for manufacturing, logistics and energy operators — forecasting, planning, vision inspection and decision support running against live operational data, integrated into the ERP, APS and plant layer rather than delivered as dashboards.

  • · Production deployments across automotive manufacturing and supplier networks
  • · Supply-network modelling built on real BOM, call-off and logistics data
  • · Integration-first delivery: planning-system write-back, monitoring, rollback
  • · 20 cited sources on this page

Sources

  1. Catena-X Automotive Network e.V.Catena-X Automotive Network (opens in a new tab)
  2. Catena-X Automotive Network e.V.Catena-X association and governance model (opens in a new tab)
  3. Gaia-X European Association for Data and Cloud AISBLGaia-X — federated, sovereign data infrastructure (opens in a new tab)
  4. International Data Spaces AssociationInternational Data Spaces — data sovereignty architecture (opens in a new tab)
  5. ACEA — European Automobile Manufacturers' AssociationEuropean automotive industry data and positions (opens in a new tab)
  6. VDA — Verband der AutomobilindustrieGerman automotive industry association (opens in a new tab)
  7. Odette InternationalAutomotive supply-chain standards and publications (opens in a new tab)
  8. AIAG — Automotive Industry Action GroupMMOG/LE and automotive supply-chain standards (opens in a new tab)
  9. MEMA — Motor and Equipment Manufacturers AssociationVehicle supplier industry association (opens in a new tab)
  10. AlixPartnersAutomotive insights — semiconductor shortage impact forecasts (opens in a new tab)
  11. Bureau of Industry and Security, U.S. Department of CommerceSemiconductor supply-chain request for information results (opens in a new tab)
  12. European CommissionEuropean Chips Act (opens in a new tab)
  13. DeloitteAutomotive industry insights (opens in a new tab)
  14. World Economic ForumSupply-chain resilience research (opens in a new tab)
  15. Toyota Motor CorporationToyota Global Newsroom (opens in a new tab)
  16. Toyota Motor CorporationToyota Production System (opens in a new tab)
  17. General MotorsGM corporate newsroom (opens in a new tab)
  18. BMW GroupBMW Group PressClub (opens in a new tab)
  19. Volkswagen AGVolkswagen Group (opens in a new tab)
  20. Renesas Electronics CorporationRenesas Electronics (opens in a new tab)

Find out where your network really stops — then what it would take to extend it

We run the assessment with your purchasing, S&OP and manufacturing leads, test it against two of your genuinely critical commodities, and leave you with a costed 90-day plan for the weakest dimension — whether that turns out to be the map, the signal, the contract boundary or the rehearsal. You keep the plan whether or not we build it.

Published · Last updated

Benchmark request

Tell us where to send it

Benchmark for this page

Used once, to send this benchmark and follow it up personally. No newsletter, no automated sequences.