
Supply Chain Risk Management Flagship practice
We investigate the suppliers, components and ownership relationships that can introduce risk into federal supply chains.
Harbour crane · Gothenburg harbour, 2017
Deliverables
What you receive
Depending on the assignment, our support includes:
Risk assessments
A clear assessment of the risks associated with a vendor, component, company or supply tier and their implications for your organization.Supporting analysis
The evidence, reasoning and confidence behind the assessment, including gaps and information that could change the conclusion.Mitigation options
Practical options for addressing the risks, with the benefits and tradeoffs explained so you can decide how to proceed.
Context
What drives the requirement
The following regulations and federal guidance inform supply chain risk requirements. These are general summaries.
Regulatory drivers
| NIST SP 800-161 | Cybersecurity supply chain risk management practices for systems and organizations. The reference framework federal C-SCRM programs are built against. |
|---|---|
| NIST SP 800-171 | Protection of controlled unclassified information in nonfederal systems. The control set defense suppliers are measured against. |
| DFARS 252.204-7012 | Safeguarding covered defense information and cyber incident reporting. Obligates defense contractors to implement NIST SP 800-171 and to report incidents. |
| CMMC | The Department of Defense program for assessing contractor cybersecurity, with requirements that flow down through subcontract tiers to suppliers who rarely deal with the government directly. |
| Section 889 | The FY2019 NDAA prohibition on procuring or using certain covered telecommunications and video surveillance equipment and services, which requires a supplier to know what is inside what it sells. |
| DoD SCRM Integration Center | A Department of Defense focal point for supply chain risk analysis supporting acquisition decisions. |
Evidence
Our experience
The experience and credentials behind our work.
- Analyst-owned and analyst-led
- Founded in 2006 by career intelligence analysts. President Carl McDonald has worked in intelligence since 1984, served as a US Navy intelligence analyst and holds PMP and ISSO certifications.
- Supply chain expertise since 2016
- The president has been a supply chain risk management subject matter expert since March 2016. This experience provides continuity and depth in supplier risk assessment.
- Supporting federal customers since 2006
- Continuous all-source analytic support to the Department of Defense, the Department of Homeland Security, national-level agencies, combatant commands, and federal, state, and local law enforcement.
- Recognized analytic work
- Employees have received individual and team Director of National Intelligence awards.
- Experienced in analytic standards
- Analysts are experienced in ICD 203 and adhere to those and other standards when requested by customers.
- Contracting eligibility
- SBA-certified Service-Disabled Veteran-Owned Small Business — eligible for sole-source and set-aside award under FAR Subpart 19.14. UEI LK5CFHLMKLK1, CAGE 4CDF0.
Procurement
How to work with us
IAI is an SBA-certified Service-Disabled Veteran-Owned Small Business (SDVOSB), eligible for sole-source and set-aside awards under FAR Subpart 19.14. We also work with prime contractors through subcontracting arrangements.
Find our business identifiers, industry codes, verification sources and contracting information on our contracting page.
Next step
Discuss your requirements
Government
Tell us about your goals and the support your team needs.Prime contractors and technology providers
We work with prime contractors and technology providers that need cleared analytic expertise.
Last reviewed 26 August 2026.