Risk Center

Sub-Tier Supplier Discovery: Finding Hidden Suppliers

By Laurits Aae Mouritsen, Founder · July 2026 · 714-word read

Key takeaways

  • Monitoring, scoring, and due diligence all assume you know who your suppliers are — but below tier 1, most companies don't.
  • Sub-tier discovery is the step of identifying the suppliers behind your suppliers, including the ones no one told you about.
  • It cannot rely on suppliers self-disclosing: they often treat their sources as confidential, or don't fully know their own sub-tiers.
  • Open-source intelligence infers the hidden network from public data — trade records, filings, corporate relationships — which is why discovery is an OSINT problem.

Every technique in supply chain risk management — monitoring, scoring, sanctions screening, ESG reporting — quietly assumes a prior step: that you know who your suppliers are. Above tier 1, you usually do. Below it, most organisations do not. And you cannot monitor, score, or screen a company whose existence you are unaware of. Sub-tier supplier discovery is the unglamorous but foundational work of finding those hidden companies, so the rest of the program has something to act on.

It is the difference between a supply chain you can describe and one you can actually manage. Discovery turns "we buy from these fifty tier-1 suppliers" into "and here is the network of tier-2 and tier-3 companies behind them, including the shared dependency we didn't know we had."

Why you can't just ask

The obvious approach — ask your tier-1 suppliers who their suppliers are — helps, but only partly. Suppliers frequently regard their sources as commercially sensitive and are reluctant to disclose them; some genuinely do not have a complete picture of their own sub-tiers; and none of them can tell you about a shared dependency that only becomes visible when you look across several suppliers at once. Self-disclosure produces a partial, self-serving, and quickly-stale map.

As multi-tier visibility makes clear, the risks that matter most — hidden concentration, a fragile common sub-supplier, a forced-labour link deep in the chain — are precisely the ones self-disclosure is least likely to reveal. Discovery has to be able to work independently of the suppliers themselves.

The cost of the blind spot

The consequences of not discovering the sub-tiers are concrete, not theoretical. Every downstream capability quietly inherits the gap: you monitor only the companies you already know, so a forced-labour finding, an insolvency, or a sanctioned owner three tiers down never reaches your alerts. Regulatory due diligence under the CSDDD and national laws expects a risk-based view of the whole value chain, but a program that stops at tier 1 is assessing a fraction of it and calling the job done.

The most expensive version of the blind spot is concentration. Procurement teams work hard to diversify their tier-1 base, then discover — usually during a disruption — that several of those 'independent' suppliers depend on one shared sub-tier plant, foundry, or logistics node. The diversification was real on paper and illusory in practice, and it was invisible precisely because no one had mapped below the first layer. Discovery is what turns that unknown into a managed risk.

Discovering the network from public data

That independent map comes from open-source intelligence. Trade and shipping records connect buyers and sellers. Corporate registries and filings reveal ownership and relationships. Company websites, job postings, certifications, and customs data leave a trail of who works with whom. Individually these are fragments; assembled and resolved at scale, they reconstruct a large part of the hidden network — and surface the sub-tier companies no one put on a list.

This is directly the capability at the heart of the OSINT research Intellens is built on: gathering intelligence on hundreds of millions of companies and the relationships between them, so a buyer can move from a tier-1 list to a real, multi-tier supplier network. Once the hidden suppliers are discovered, everything else — monitoring, scoring, screening — finally has the complete map it always assumed. To see how sub-tier discovery and mapping work for your network, request a demo, or read more in the Risk Center.

Frequently asked questions

What is sub-tier supplier discovery?

The process of identifying the suppliers behind your direct (tier-1) suppliers — tier 2, tier 3, and beyond — including companies that were never disclosed to you. It is the prerequisite for monitoring and due diligence below tier 1.

Why isn't asking suppliers for their sources enough?

Suppliers often treat their sources as confidential, may not fully know their own sub-tiers, and cannot reveal shared dependencies visible only across multiple suppliers. Self-disclosure yields a partial, stale map.

How can hidden suppliers be discovered?

Through open-source intelligence — trade and shipping records, corporate registries and filings, certifications, and customs data — assembled and resolved at scale to reconstruct the multi-tier network independently of the suppliers.

Why does discovery matter for compliance?

Because regulations like the CSDDD expect risk-based due diligence across the value chain, and forced-labour, conflict-minerals, and concentration risks concentrate in the sub-tiers you must first discover to assess.

About the author

Laurits Aae Mouritsen is the founder of Intellens. His master's thesis at Copenhagen Business SchoolOpen Source Intelligence (OSINT) in Supply Chain Risk Management (Cand.merc.it., 2024) — built software to gather intelligence on hundreds of millions of companies and automatically analyse supplier risk across a supply network. Intellens is that research put into practice. More on the about page · LinkedIn.

Published 2026-07-08 · Back to the Risk Center