Supply chain assurance · Governance, risk and compliance

A record is not the reality it describes.

I have spent seventeen years operating controls in Defence logistics. Nobody ever called them controls.

I work on the seam between physical supply chains and the governance functions that are supposed to assure them: asset accountability, supplier due diligence, trade compliance and the growing problem of AI-enabled decisions nobody can trace. I write about where that seam fails, and I build the tools I wish I had been handed.

Current
Petty Officer (Supply Chain), Royal Navy
Focus
Assurance, third-party risk, AI governance
Reading for
MSc Supply Chain and Logistics Management
Available
From 2028, on resettlement

Work

Open method, not case files

Reference material I have built and put in the open. Both are generalised from my own academic and professional work, and neither contains client, supplier or organisational detail.

Accreditation is not assurance.

A certificate establishes evidence within a defined scope. It does not establish that the control worked, that the record matches the asset, or that the supplier can do the thing it has promised. Most of my work sits in the distance between those two positions.

Physical custody

Asset accountability, reconciliation, custody transfer and the discipline of testing the ledger rather than reproducing it.

Third-party risk

Intelligence-led supplier due diligence, sub-tier visibility and the limits of what a completed questionnaire can tell you.

Regulated movement

Trade compliance and export control, where the evidence is created by logistics people who do not think of themselves as running controls.

Writing

In preparation

Three arguments, all of them versions of the same one. Links go live as each piece publishes.

In preparation

Recognition Before Retraining

Just over half of UK veterans have taken a job below the level of their last military role, and one of the two most cited reasons is employers failing to recognise transferable skills. Defence has now built the instrument that could fix that, and is using it only for internal workforce planning.

Skills · 1 of 2
In preparation

Talent Should Flow Both Ways

The Defence Industrial Strategy commits to a Skills Passport. The MOD is already running a pilot that hires on industry experience rather than previous rank. The strategy does not mention the pilot, and the pilot does not mention the strategy.

Skills · 2 of 2
In preparation

The Convergence of Cyber-GRC and Physical Logistics

A regulator recently found that a defence prime's export control exposure ran through the gap between a supply chain team that did not hold the regulatory knowledge and a file transfer system that did not carry the warning. Each function could have reported itself compliant.

Assurance

Background

Evidence before credentials

I started as a meter reader for the national electricity utility in St Vincent and spent twelve years there, finishing in planning and GIS. I led the GPS geo-tagging of the island's grid infrastructure, and that dataset went on to underpin an enterprise mapping system that won an Esri Special Achievement in GIS award.

I joined the Royal Navy and have spent more than seventeen years in Defence logistics: supply accounts, stocktaking, supersession and handover, fleet logistics inspection, transport safety and remedial action. It was presented to me as logistics. It took a postgraduate degree and a set of audit qualifications before I recognised it as governance, risk and compliance, which is a large part of why I now write about the translation problem.

I also founded a development programme for junior rates that was adopted as a standing programme by Engineering Support Group 1 and recognised with a Royal Navy Inclusivity Award.

Study

  • MSc Supply Chain and Logistics ManagementUniversity of Lincoln · in progress, dissertation 2027
  • MITx MicroMasters, Supply Chain ManagementSC0x–SC4x complete · final exam 2026
  • Open-Source Intelligence; Penetration TestingUniversity of Abertay, via SaluteMyJob

Certification

  • ISO/IEC 27001, 42001 and 27701 Lead AuditorInformation security, AI management, privacy
  • FellowMSAFellow of Management Systems Auditing
  • CompTIA PenTest+Valid to 2027

Programmes

  • 1SL Richmond Fellowship2025–26
  • Percy Hobart Fellowship2022
  • AWS Community BuilderFourth consecutive year

Get in touch

I am interested in defence supply chain assurance, supplier risk and resilience, trade compliance and export control, operational GRC and third-party risk. If that is your world, I would rather learn from you than pitch at you.