Purpose – The purpose of this paper is to provide the organization with a process for assessing risk associated with their supply chain and a framework from which they can build their strategy to manage risk. Design/methodology/approach – The proposed process is based on a compilation of research and interactions with supply chain managers in various industries, and these sources provide a specific process to identify how critical the risk is, when to act upon it, and how to manage it. An adapted risk mitigation framework organizes strategies according to the likelihood of disruption and consequences. Included is an industry example used to demonstrate the framework. Findings – The variability and uncertainty associated with supply chain risks make disruption difficult to predict. Furthermore, getting information from suppliers about the amount of risk associated with their operation in an attempt to scope one's own risk can be a challenge. Management must consider the amount of risk the organization is going to accept and how much to invest to mitigate it. Originality/value – To manage the risk associated with supply chain disruption, an organization must deploy a strategy for assessing it. Once risk areas have been identified, the organization must design strategies which will mitigate the risk. The depth and degree to which risk is mitigated depends upon how risk-averse a company is and what they are willing to invest in this activity.