Risk Center

OSINT for Supply Chain Risk Management

By Laurits Aae Mouritsen, Founder · July 2026 · 928-word read

Key takeaways

  • OSINT (open-source intelligence) is the practice of turning publicly available data — news, registries, filings, sanctions lists, satellite and trade data — into structured risk signals.
  • It is the answer to the core weakness of supplier due diligence: questionnaires capture what a supplier says about itself, while OSINT captures what the world reports about it.
  • Done well, OSINT is continuous and entity-resolved: every signal is tied to a specific, real supplier, not to a country or a keyword.
  • Intellens is built on OSINT — the founder's Copenhagen Business School thesis, Open Source Intelligence (OSINT) in Supply Chain Risk Management, is the research it productised.

Open-source intelligence, or OSINT, is the discipline of collecting and analysing publicly available information to answer a question that matters. It is an old idea from the intelligence world — most of what you need to know is already public, if you can gather it at scale and make sense of it — and it turns out to be exactly the right tool for supply chain risk. Applied to procurement, OSINT means turning the vast, messy stream of public data about companies into a structured, continuously-updated picture of which of your suppliers is exposed to a developing risk.

This matters because supplier due diligence has a structural blind spot. The questionnaire, the audit, and the self-attestation all capture the same thing: what a supplier chooses to say about itself, on a schedule it can prepare for. OSINT captures the opposite — what the world independently reports about that supplier, as it happens. The two are complementary, but only one of them surfaces the sanctioned owner, the local-language labour dispute, or the quietly-failing audit before it reaches you.

What counts as an open source

"Open source" is broader than most people assume. It includes news media in every language, company and beneficial-ownership registries, court and insolvency filings, sanctions and watchlists, customs and trade records, regulatory enforcement actions, NGO and civil-society reporting, job postings, satellite and geospatial imagery, and the digital footprint of the companies themselves. None of it is secret; the difficulty is that it is fragmented across thousands of sources, in dozens of languages, and almost none of it arrives pre-connected to your supplier list.

That is the real work of supply chain OSINT, and where the founder's research focused: not finding the data, but resolving it — matching a story about "a factory fire in Bursa" or "a sanctioned director at an obscure holding company" to the specific supplier in your network it actually concerns, at the scale of hundreds of millions of companies and their physical locations.

Internal vs external signals

A useful way to frame supplier risk is internal versus external. Internal signals come from data you already hold — your ERP, your spend, your supplier master: who you buy from, how much, on what terms, from which sites. External signals come from the open sources above: what is happening to those suppliers out in the world. Neither is enough alone. Internal data tells you what you depend on; external data tells you what is threatening it.

OSINT done properly joins the two. By connecting to your existing supplier and ERP data and enriching it with open-source intelligence, a monitoring system can weight a public risk signal by how much you actually depend on the supplier it concerns — so a minor story about a critical single-source supplier outranks a dramatic one about a supplier you could replace tomorrow. This internal-plus-external join is the difference between a news feed and a risk system.

Why OSINT beats the questionnaire

The annual questionnaire has three weaknesses OSINT directly addresses. It is periodic, so it misses everything that happens between cycles; it is self-reported, so it misses everything a supplier would rather not disclose; and it is shallow past tier 1, because you can only send a questionnaire to a company you have a relationship with. OSINT is continuous by nature, independent by definition, and — because it works from public data about any company — it can reach the sub-tier suppliers you have never contracted with.

None of this makes questionnaires worthless; attestations still have a role, especially where a supplier's own commitment is the point. But as the primary instrument for seeing risk, a once-a-year self-report has been overtaken by continuous open-source monitoring, in the same way annual accounts were overtaken by real-time dashboards.

OSINT is the foundation of Intellens

Intellens is, at its core, an applied-OSINT platform. It began as academic research: its founder's master's thesis at Copenhagen Business School, Open Source Intelligence (OSINT) in Supply Chain Risk Management, built software able to gather intelligence on hundreds of millions of companies, identify the real-world locations of their offices and factories, and run automated internal and external risk analysis on any supplier in a company's network by connecting to its existing ERP data.

That is the same engine, productised: read the open sources at scale, resolve every signal to a named supplier, join it to what the buyer actually depends on, and turn the result into a score and an alert someone can act on. To see what open-source intelligence surfaces for your own supplier network, request a demo, or read more in the Risk Center.

Frequently asked questions

What does OSINT mean in supply chain risk management?

OSINT — open-source intelligence — is the practice of collecting and analysing publicly available data (news, registries, filings, sanctions lists, trade and geospatial data) to assess the risk attached to specific suppliers, continuously and independently of what those suppliers self-report.

How is OSINT different from a supplier questionnaire?

A questionnaire captures what a supplier says about itself, periodically. OSINT captures what the world independently reports about that supplier, continuously — so it surfaces risks between audit cycles and risks a supplier would not volunteer.

Can OSINT reach sub-tier (tier-2 and beyond) suppliers?

Yes. Because OSINT works from public data about any company, it can monitor suppliers you have no contract with — exactly where forced-labour, insolvency, and concentration risks tend to hide.

Is OSINT reliable enough to act on?

On its own, a single source can be noisy. Reliability comes from scale and resolution: cross-referencing many independent sources, resolving each to a specific supplier, and scoring the result — which is what turns raw open data into a signal worth acting on.

About the author

Laurits Aae Mouritsen is the founder of Intellens. His master's thesis at Copenhagen Business SchoolOpen Source Intelligence (OSINT) in Supply Chain Risk Management (Cand.merc.it., 2024) — built software to gather intelligence on hundreds of millions of companies and automatically analyse supplier risk across a supply network. Intellens is that research put into practice. More on the about page · LinkedIn.

Published 2026-07-08 · Back to the Risk Center