
The Strait of Hormuz situation has shown oil and gas companies exactly what regional conflict does to a supply chain: prices spike, tankers reroute, and buyers scramble for alternatives overnight. Shipping through the Strait has partially resumed since the June ceasefire, but volumes are still running a fraction of pre-war levels. For a lot of procurement teams, the sense of urgency faded with it.
That's a mistake because the exposure never went away, only the headlines did. Vessels are still being targeted in the Strait even with a ceasefire in place. Concentration risk in Middle East sourcing, dependence on oil-linked third parties, and blind spots in vessel tracking are structural problems, and they don’t magically resolve when a ceasefire holds. The next disruption will hit the same gaps, whether it's another regional flare-up, a labor action, or a weather event.
Exposure runs deeper than the vendor list
Most procurement teams can tell who their direct suppliers are, but far fewer can tell where those suppliers source their own materials, or whether a sub-supplier 2-3 tiers down is sitting in a conflict zone. That's the layer where the real risk hides.
During the Hormuz disruption, companies with heavy Middle East supplier dependence were exposed through direct contract, as well as through downstream relationships tied to oil and its derivatives - relationships that don't show up on a standard vendor list because nobody mapped that far down the chain.
Tracking Tier 4 suppliers has historically been slow, manual work. Tier 1 vendors don't automatically disclose who their own suppliers are, so getting that visibility means requesting it directly, tier by tier, through questionnaires and follow-up outreach that most companies don't have the bandwidth to run continuously. Most organizations have prioritized speed and cost over that kind of visibility. When a chokepoint like the Strait closes, the companies without that visibility are the ones finding out about their exposure in real time.
Vessels are third parties too
That same blind spot extends past the vendor list, into how a company's own product actually gets to market. For exploration and production (E&P) companies specifically, there's a category of exposure that rarely gets treated with the same rigor as suppliers: the vessels moving product to market. Ownership, flag, route, and current location all matter when a shipping lane becomes unstable, but many companies don't track this information as part of their third-party risk program. It sits somewhere else, owned by logistics or trading desks, disconnected from the broader risk picture.
That gap became obvious when dozens of tankers rerouted or held position waiting for the Strait to reopen. Companies that had visibility into where their product was and who was moving it could make faster calls on rerouting, insurance, and customer communication. Companies that didn't were reacting to secondhand reports.
What resilient teams are doing differently
The procurement organizations that emerged in better shape had already built a centralized system of record for their third-party relationships before the crisis hit. Not a spreadsheet updated every quarter, but a live view that shows ownership structures, geographic concentration, and dependency chains across every tier they can reach.
That structure let them answer basic questions fast, like which suppliers had operations in the affected region and which contracts carried force majeure exposure. It also gave them a starting point for identifying alternative sources before they were forced into emergency sourcing under pressure.
Centralization also matters because concentration risk isn't always obvious until you can see it laid out. A company might believe its supplier base is diversified across a dozen vendors, only to find that eight of them depend on the same regional refinery or the same shipping lane. That pattern is invisible in a vendor list, but wholly visible in a mapped network.
3 priorities for the next two quarters
Regardless of how the current geopolitical picture evolves, oil and gas procurement teams should be treating the next six months as preparation time.
● Build the centralized register now, while there's room to do it deliberately. Start with the suppliers already flagged as high-risk or high-spend and expand from there, rather than trying to map the entire vendor base at once. Waiting until the next disruption means building it under pressure, with incomplete information and no time to validate it.
● Extend visibility past tier one. Require direct suppliers to disclose their own critical vendors as part of onboarding and renewal and prioritize that outreach for suppliers tied to the highest-risk regions first. Direct suppliers are the easy part. The risk that catches companies off guard sits in the tiers below, and that's where mapping needs to go next.
● Bring vessel and logistics data into the same risk framework as supplier data. That means giving procurement or risk teams standing access to shipping and ownership data, not routing it through a separate logistics function that only gets looped in after a route is already disrupted. For E&P companies especially, treating transport as a function separate from third-party risk creates a blind spot that shows up exactly when it's least convenient.
Conflicts, sanctions, and chokepoint closures aren't going away, and no procurement organization can control when the next one happens. What's controllable is how much exposure is visible before it turns into a crisis, and how quickly a team can act once it does.
The companies that treated the Strait of Hormuz disruption as a wake-up call are the ones building that visibility now. The ones that didn't will be having the same scramble the next time a shipping lane closes, a region destabilizes, or a supplier's operations go dark without warning. Mapping that exposure now is the only real advantage a procurement team can build before the next disruption becomes a crisis.

















