Supply Chain Resilience: Francisco Gaffney Highlights New Business Control Imperatives

F

Francisco Gaffney

LinkedIn Author

Board Advisor | Chairman| ex-SAP & Teradata | PLC, SME & Mid Market Firms

In a recent LinkedIn post, Francisco Gaffney discusses the evolving landscape of business controls and supply chain risk, emphasizing new regulatory requirements that extend beyond traditional cybersecurity concerns. Gaffney’s insights highlight the critical need for businesses to understand and test the resilience of their core services.

Mandatory Business Service Mapping and Testing

Francisco Gaffney points out that new regulations are compelling organizations to thoroughly map their business services and assess their impact tolerances. This goes beyond just focusing on cyber-attacks, suggesting a broader view of operational resilience is now essential.

“New regulations require firms to map and test business services for impact tolerances, going beyond just cyber attacks.”

As Gaffney notes, this proactive approach is crucial for identifying potential vulnerabilities within critical business functions. The emphasis on impact tolerances means understanding how disruptions to specific services could affect the overall business, requiring a deeper level of analysis than previously mandated.

Board Oversight and Responsibility

The post further elaborates on the role of corporate boards in this new regulatory environment. Francisco Gaffney highlights the necessity for boards to actively review self-assessments related to these controls and responsibilities.

“Boards must review self-assessments, addressing unclear engagement and responsibilities.”

According to Gaffney, this oversight is critical for ensuring that the organization is adequately prepared and that accountability is clearly defined. Ambiguity in engagement and responsibility can lead to significant gaps in preparedness, leaving businesses exposed to unforeseen risks.

Supply Chain Implications

A significant aspect of Gaffney’s analysis concerns the extension of these control requirements into the supply chain. He argues that the impact of these regulations is not limited to directly regulated entities but has broader implications for all businesses interacting within a supply chain.

“This extends to the supply chain, impacting tenders and contracts even if you’re not directly regulated.”

In Francisco Gaffney’s view, this means that even companies not subject to direct regulation must now consider these enhanced business control and supply chain risk requirements when engaging in tenders and contractual agreements. Failure to do so could result in a competitive disadvantage or non-compliance with partner requirements. Gaffney’s insights underscore a significant shift towards a more holistic and interconnected approach to business risk management, where the resilience of the entire value chain is paramount.

📝 About This Content

This article is based on insights shared by Francisco Gaffney on LinkedIn.

📅 Originally posted on April 30, 2026 | View original post on LinkedIn →