Two supply routes, one hidden factory floor. That is the reality behind most dual-sourcing arrangements, and it is discovered almost always after a defect, never before. I once spent three weeks chasing a dimensional drift on a machined housing that appeared at two supposedly independent suppliers, on different continents, within the same fortnight. Both held current approvals, both ran capable processes, and both insisted nothing had changed. Nothing had — at their level. The castings both came from the same tier-2 foundry, which had quietly reworked a core box after a maintenance event.
Dual sourcing is a genuine risk-control measure at tier one. But if you have never mapped what sits behind your two suppliers, you do not have two sources — you have two invoices for the same source. When the shared sub-tier degrades, both suppliers fail in the same direction, at the same time, often with the same defect signature. That symmetry makes root cause analysis harder, because the evidence looks like a systemic design issue rather than a single upstream process change.
The good news is that the fix is procedural, not exotic. Sub-tier mapping, layered requirements checks, selective tier-2 audits and a maintained common-source register will expose the overlap for a modest investment of supplier-quality engineering time. Here is the method as I have applied it across automotive and aerospace supply chains under IATF 16949 and AS9100.
The Illusion of Redundancy
Redundancy exists on paper only until you can name the node behind it. A second tier-1 that buys its castings, forgings or heat treatment from the same sub-tier as the first inherits every failure mode of that node while contributing nothing in the way of independence. The mathematical language is wrong too: two suppliers sharing one upstream source is a series system, not a parallel one, and its reliability is that of the common node.
The illusion persists because supplier approval audits stop at the boundary of the audited organisation. IATF 16949 and AS9100 both push flow-down of requirements to sub-tiers, but verification of that flow-down is typically assessed by document review at the tier-1, not by tracing a requirement to the shop floor that executes it. The gap between those two positions is where common-source risk lives.
The consequence is a specific and recognisable failure pattern: simultaneous onset at multiple tier-1s, each investigating itself in isolation, neither knowing the other shares the node. I have seen 8D teams at two suppliers run parallel root cause analyses for six weeks on a defect that originated in a single plating line. The fix was one phone call — once somebody finally made it.
Flow-Down That Actually Reaches the Shop Floor
Contractual flow-down is where most companies stop, and it is not enough. The purchase order carries the drawing, the specification, the special characteristic symbols and perhaps a customer-specific requirements annex. Whether the tier-1 pushes those requirements down to the foundry, forge, plater or heat-treater in language that shop can act on is a different matter. I have reviewed tier-1 quality manuals that forbid sub-tier changes without notification, then found tier-2 heat-treatment certificates arriving under a generic hardness specification with no reference to the flow-down clause at all.

What works is a layered requirements check. Ask the tier-1 to show you, for two or three named sub-tier processes, the actual document the sub-tier works to — not the tier-1's summary of it. Trace one special characteristic from your drawing through the tier-1 control documentation into the tier-2 work instruction. If the trace breaks, and it breaks more often than anyone admits, you have found the gap before the defect finds it.
Four items fail quietly and expensively, so check them first: key characteristics traced to sub-tier work instructions, change-notification obligations on sub-tier process and site changes, record retention that matches your traceability needs, and right-of-access clauses that extend to critical sub-tiers. A tier-1 that resists any of these is telling you something about how it manages the rest.
Tracing one requirement through the sub-tier chain
- 01Identify the characteristicPick a special characteristic from your drawing: a hardness, a torque, a cleanliness limit.
- 02Read the tier-1 control planConfirm the characteristic appears in the tier-1's process documentation, not just the PO.
- 03Find the tier-2 work instructionDemand the actual document the sub-tier shop works to, not a summary.
- 04Verify the linkageDoes the tier-2 document name the requirement, the limit and the reaction plan?
- 05Log the resultBroken traces go into the common-source register as findings, with corrective actions.
Auditing Below Tier One Without Auditing Everything
You cannot audit every sub-tier, and you should not try. What you can do is tier sub-tiers by criticality and audit selectively, with the tier-1 in the room. The tier-2 foundry feeding both of your machining suppliers qualifies for audit. So does any single-source heat treatment, passivation, plating or forging operation, and any sub-tier holding a process special characteristic you cannot verify on the finished part.
A tier-2 audit looks different from a tier-1 audit. You are not scoring a full quality system; you are verifying three or four specific things: does the process exist as described, is the control the tier-1 claims actually implemented, and is there a change-notification path that reaches someone who acts on it. Scope it as a process verification, aligned with the VDA 6.3 thinking of focused process audits rather than full-system certification audits.
Look for the maintenance-driven change — the repaired fixture, the swapped thermocouple, the replacement die insert — because that is where undocumented variation is born. Ask the furnace operator, not the quality manager, what happens when a thermocouple fails mid-cycle. The answer tells you whether the flow-down is real. Operators describe what is done; quality managers describe what is written.
Two suppliers sharing one upstream source is a series system, not a parallel one — its reliability is exactly that of the common node.
Where Hidden Common Sources Concentrate
Certain categories generate shared sub-tiers disproportionately, and knowing them lets you target the mapping effort. Heat treatment and plating concentrate because capital equipment and environmental permitting are heavy, so regionally there may be only two or three realistic players regardless of how many tier-1s you use. Foundries and forges concentrate for the same reason. Raw material mills concentrate absolutely: a single steel mill may stand behind a dozen apparent sources once you trace bar stock, forgings and castings back to the melt.
Beyond materials, watch for shared calibration and test laboratories, shared special-process houses for hydrogen embrittlement relief or dry-film lubricant application, and shared third-party logistics or rework operations. Software and firmware sub-tiers count too: two suppliers building "different" electronic modules may both licence the same communication stack or the same sensor from the same design house.
The failure mode in every case is identical — a change at the common node propagates simultaneously through both channels, and each tier-1 investigates itself in isolation because neither knows the other shares the node. Your job as the customer is to hold the map that shows the connection neither supplier can see.
Building the Common-Source Register
Start with the bills of material and process routings of your top-volume or critical-safety part numbers at each tier-1. For each, list every external process the tier-1 buys in: casting, forging, machining subcontract, heat treat, surface treatment, forming, testing. Then ask for the sub-tier name and site for each. Expect resistance on commercial grounds; offer an NDA. Where the tier-1 refuses, treat that refusal itself as a risk finding and escalate contractually rather than dropping the exercise.
Once you have the lists for two suppliers, overlay them. The overlap is your hidden common-source register. I keep it as a simple table: part family, shared sub-tier, shared site, shared process, failure mode if that node degrades, and the detection method currently in place. Review it whenever the tier-1 declares a change, and re-verify annually — sub-tiers get switched for price more often than anyone notifies you.
The register is also your escalation map. When both suppliers show the same anomaly, it tells you in minutes which single phone call to make. That is the entire return on investment: containment in an hour instead of a week, and root cause analysis aimed at the true node from day one instead of week six.
Detection, Metrics and the Honest Conversation
A shared-source problem has a signature worth training your people to recognise. Simultaneous onset at multiple tier-1s is the obvious clue, but subtler ones include identical defect morphology — the same pore cluster pattern, the same intergranular fracture face, the same plating thickness distribution — appearing in parts from suppliers who have never exchanged process knowledge. Certificate review is your earliest instrument: compare mill certificates, heat-treat certificates and plating batch records across suppliers periodically, and look for shared lot numbers, shared heat numbers, shared dates. A shared heat number on supposedly independent supply routes is a finding every time.
What the supplier-quality dashboard should carry
Metrics that belong on the dashboard include sub-tier change notifications received per quarter, the percentage of critical part families with a completed common-source register, and the age of register entries. On the physical side, incoming material verification — hardness, chemistry via optical emission spectroscopy or XRF, microstructure on a cut section for safety-critical items — catches the shared foundry's process drift before assembly does. One disciplined metallographic check per quarter on a shared-source casting has caught more drift for me than any stack of certificates.
The final piece is commercial and internal. Tier-1 contracts need a clause giving visibility of nominated critical sub-tiers and a notification obligation covering sub-tier process, site or ownership changes — not just drawing changes. Right of access should extend explicitly to critical sub-tiers for audit. Internally, be honest with management about what dual sourcing does and does not buy, and present the register as the evidence. Where overlap is unavoidable, as with mills and foundries, the mitigation is not a second source but detection and a documented escalation path that names the shared node.
Redundancy you have verified is protection. Redundancy you have assumed is a comfortable story we tell ourselves until the shared furnace trips — and on that day, the organisation holding the map contains the problem in an hour while everyone else spends a week finding out that their two suppliers were always one.
