Risk Center

Supplier Location Intelligence: Where Suppliers Operate

By Laurits Aae Mouritsen, Founder · July 2026 · 934-word read

Key takeaways

  • The address on a supplier's contract is usually a headquarters or billing office — not the factory, port, or mine where the actual risk sits.
  • Location intelligence means resolving a supplier to its real physical sites, because geographic risk (climate, conflict, deforestation, sanctions) is site-specific.
  • Regulation is forcing the issue: the EUDR requires plot-level geolocation, and CSRD climate disclosures depend on knowing where suppliers actually operate.
  • Open-source intelligence can map supplier offices and factories at scale from public data — the capability at the heart of the research Intellens is built on.

Ask most procurement systems where a supplier is, and they will give you the address on the contract. That address is almost always a headquarters, a sales office, or a billing entity — and it is almost never where the risk actually lives. The flood risk is at the factory. The forced-labour risk is at the sub-contracted plant. The port-closure risk is at the harbour their goods ship through. The sanctions risk is at the parent company two ownership layers up. A single billing address hides all of it.

Supplier location intelligence is the practice of resolving a supplier to its real physical footprint — the specific sites where it operates — so that geographic risk can be assessed against the places that actually matter. It is one of the least glamorous and most consequential capabilities in supply chain risk, because almost every environmental, geopolitical, and climate risk is fundamentally a question of "where."

Why the invoice address is not enough

A country-level or headquarters-level view fails in a specific, predictable way: it averages away exactly the detail you need. Two suppliers with the same registered address in Frankfurt might operate factories in entirely different, differently-exposed regions. A supplier registered in a low-risk country might do all its manufacturing in a high-risk one. Country risk tells you the weather system; site location tells you whether your building is in the flood plain.

This is also why supplier-provided data is insufficient on its own. Even a cooperative supplier may not disclose every sub-site, every sub-contractor, or every tier-2 dependency — and an uncooperative one certainly will not. The real map has to be assembled independently, from public evidence, and kept current as sites open, close, and change hands.

Regulation is making location non-negotiable

What used to be a nice-to-have is becoming a legal requirement. The EU Deforestation Regulation (EUDR) requires operators to provide the geographic coordinates of the plots of land where commodities were produced — geolocation is the core of the compliance test. CSRD climate disclosures (CSRD) depend on knowing where in the value chain physical-climate risk and emissions actually sit. In both cases, "we know our supplier's head office" is not an answer; "we know where our supplier produces" is.

The direction is clear: regulators increasingly expect companies to demonstrate site-level knowledge of their value chain, not company-level. That raises the bar from a supplier list to a supplier map.

Location is the join key for geographic risk

The reason location intelligence is foundational rather than a nice-to-have is that almost every geographic risk is joined to your supply chain through a place, not a name. A flood model, a conflict map, a drought index, a sanctions-affected region, a deforestation alert — none of them know your suppliers. They know coordinates. Without resolving your suppliers to their real sites, you have no way to ask the one question that matters: is any of my supply exposed to this event?

Once suppliers are on the map, that question becomes answerable automatically. A wildfire footprint, a port closure, a new export-control zone, or a deforestation event can be intersected with your suppliers' actual locations to produce a precise, supplier-level answer — these three sites are inside the affected area, everyone else is clear — instead of a vague, anxiety-inducing 'we have suppliers in that country somewhere.' Location turns ambient world events into specific, actionable supply-chain exposures.

This is also what makes location intelligence compound in value. The same resolved-site map serves climate risk, conflict risk, sanctions exposure, EUDR geolocation, and CSRD physical-risk disclosure at once. Built once and kept current, it becomes the spatial backbone that every other risk capability queries.

Mapping locations from public data

Building that map by hand is impractical at any real scale. The open-source approach is to infer physical sites from the trail companies leave in public data — registries, permits, filings, trade and shipping records, job postings tied to locations, and geospatial imagery — and to resolve those signals to specific entities and coordinates. Done at scale, it turns a list of supplier names into a map of where those suppliers, and the suppliers behind them, actually operate.

This is precisely the capability at the heart of the research Intellens is built on: its founder's Copenhagen Business School thesis, Open Source Intelligence (OSINT) in Supply Chain Risk Management, built software able to identify the office and factory locations of hundreds of millions of companies in order to run automated, site-aware risk analysis. Once a supplier is resolved to its real places, geographic risk — climate, conflict, energy, deforestation, sanctions exposure — can be assessed against the ground truth rather than a billing address.

To see how site-level supplier mapping and monitoring work for your own network, request a demo, or continue in the Risk Center.

Frequently asked questions

What is supplier location intelligence?

The practice of resolving a supplier to its real physical sites — factories, ports, mines, offices — rather than relying on the billing or headquarters address, so that site-specific geographic risk can be assessed accurately.

Why isn't a supplier's registered address good enough?

The registered or billing address is usually a headquarters, not where production happens. Climate, conflict, deforestation, and sanctions risks are site-specific, so a single address hides the exposures that matter.

How does location intelligence relate to the EUDR?

The EU Deforestation Regulation requires the geographic coordinates of the plots where commodities were produced. That is location intelligence as a legal requirement — proof of where, not just who.

Can supplier locations be mapped without the supplier's help?

Largely, yes. Open-source intelligence infers physical sites from public data — registries, permits, trade records, job postings, and geospatial imagery — which is essential for the sub-tier suppliers that will not, or cannot, self-report.

About the author

Laurits Aae Mouritsen is the founder of Intellens. His master's thesis at Copenhagen Business SchoolOpen Source Intelligence (OSINT) in Supply Chain Risk Management (Cand.merc.it., 2024) — built software to gather intelligence on hundreds of millions of companies and automatically analyse supplier risk across a supply network. Intellens is that research put into practice. More on the about page · LinkedIn.

Published 2026-07-08 · Back to the Risk Center