Every company depends on suppliers it does not control. That is not a problem until one of them fails — a factory fire, a bankruptcy, a cyberattack, a new tariff — and you discover you had no idea how exposed you were.
Supplier risk management is the work of finding that out in advance. In one sentence: know which suppliers matter most, know what could go wrong with each, and have a plan for when it does.
Why this matters more than it used to
Disruption is no longer occasional. The Business Continuity Institute's 2024 Supply Chain Resilience Report found almost 80% of organisations had their supply chains disrupted in the previous twelve months. The single biggest cause was not war, weather or cyberattack. It was suppliers themselves.
Other data points the same way. RapidRatings surveyed more than 200 suppliers and procurement and risk professionals in late 2025: 82% of enterprises had suffered a material supplier disruption in the previous year. Resilinc, which monitors supply chain events around the clock, recorded a 38% increase in disruptions in 2024, issuing 22,522 alerts.
And yet commitment is patchy. In the same BCI report, 20% of respondents said their management's commitment to supply chain risk was low or non-existent.
The seven types of supplier risk
Supplier risk is not one thing. It is at least seven, and they need different responses.
- 1. Financial risk
- The supplier runs out of money. Warning signs include slower deliveries, requests for faster payment, and staff leaving. This is often the one that arrives with least notice.
- 2. Operational risk
- The supplier cannot deliver: a fire, a quality failure, a strike, a machine breakdown. Resilinc recorded 2,299 factory fire alerts in 2024 — its most common disruption type.
- 3. Concentration risk
- Too much depends on too few suppliers, or on one. A single-source supplier for a critical part is a risk even if that supplier is excellent.
- 4. Geographic and trade risk
- Where things are made matters. Tariffs, sanctions, conflict and natural disasters all hit by location. McKinsey's 2025 survey found 82% of companies said their supply chains were affected by new tariffs.
- 5. Cyber risk
- A supplier with access to your systems or data can become the way in for an attacker. This one has grown fastest.
- 6. Compliance and legal risk
- Your supplier breaks the law — on labour, sanctions, environment or data — and you carry some of the consequences. Regulation increasingly makes this your responsibility.
- 7. Reputational risk
- Your supplier does something that ends up in the news with your name attached.
Cyber deserves a closer look because the numbers moved sharply. Verizon's 2025 Data Breach Investigations Report, which analysed more than 22,000 security incidents including 12,195 confirmed breaches, found that third-party involvement in breaches doubled in a single year.
Resilinc's 2024 data also shows how the mix is shifting. Factory fires fell 20% from the previous year, but flood-related alerts rose 214%, geopolitical risk alerts rose 123%, and labour violations rose 146%. The risks you planned for five years ago are not the ones growing fastest now.
The visibility problem: you can only see one step
Most companies know their direct suppliers — called tier-one suppliers. Far fewer know who supplies their suppliers. That matters because a lot of disruption starts one or two steps back.
It gets thinner the closer you look. In the same survey, 58% had mapped their tier-two suppliers, but fewer than half of those had any regular direct contact with them. A map is not a relationship.
There is some progress. The BCI found 17.1% of organisations now analyse critical suppliers down to tier four and beyond, up from just 3.7% the year before. That is a big jump from a very low base.
An eight-step process you can actually run
Enterprise risk programmes come with software, dashboards and dedicated teams. Most mid-sized companies have none of those. Here is a version that works with what you have.
Step 1: List your suppliers properly
You cannot assess risk on a supplier list that has the same company four times under different spellings. Clean the list first so each supplier appears once, with its total spend.
Step 2: Find the suppliers that matter
Spend is not the same as importance. A small supplier of a part nobody else makes can stop production. Sort suppliers on two questions: how much would losing them hurt, and how easily could we replace them? The ones that score high on both are your critical suppliers. For most companies that is a short list.
Step 3: Check your concentration
How much of your spend sits with a handful of suppliers? Procurify's data across more than 250 mid-market organisations found the top five suppliers typically take 57% to 59% of spend, and Procurify suggests 55% to 65% as a healthy range. Well above that, you are dependent. Well below, you may be spread too thin to get good terms.
Step 4: Check financial health
For critical suppliers, look at financial health at least once a year — more often for anyone showing warning signs. RapidRatings found only 15% of enterprises fully use supplier financial health data when setting payment terms, and 30% do not use it at all.
That matters because payment terms are a risk lever. Squeezing a financially fragile supplier on payment terms to improve your own cash position is a quick way to cause the failure you are trying to avoid.
Step 5: Find out where things are really made
Not where the supplier is registered. Where the item is actually made and shipped from. Tariffs and disasters hit by geography, and a supplier headquartered in one country may manufacture in another.
Step 6: Check cyber exposure
For every supplier that can access your systems or holds your data, ask the basic questions: what can they reach, how is access controlled, and how would they tell you about a breach? Given Verizon's doubling figure, this list deserves more attention than it usually gets.
Step 7: Have a plan B for critical items
This is where most of the value is. Deloitte asked more than 250 chief procurement officers which risk mitigation actually works best.
| Mitigation strategy | CPOs rating it most effective |
|---|---|
| Maintaining active alternative sources | 74% |
| Better visibility into the supply chain | 64% |
| More information sharing with suppliers | 61% |
| Near-shoring or reshoring | 33% |
| Rationalising the product portfolio | 31% |
| Holding more inventory | 31% |
Active alternative sources came top by a distance. Note the word active. A backup supplier you have never ordered from is a phone number, not a plan. Qualifying a second source means placing real orders with them, even small ones, so they can actually step in.
McKinsey's 2025 survey shows companies acting on this: of those facing tariff impacts, 45% were increasing inventory, 39% were pursuing dual sourcing, and 33% were developing nearshoring or onshoring plans.
Step 8: Write it into the contract, then review
Risk management that lives only in a spreadsheet disappears when the person who built it leaves. Put the important parts in the contract: notice obligations if the supplier's situation changes, continuity plans for critical services, and what happens if they fail.
The UK Government's Sourcing Playbook is a useful model here. It asks for a joint risk register with suppliers, contingency planning, and resolution planning for critical contracts — agreeing in advance how the service would continue if the supplier collapsed.
The regulation you may already be subject to
Supplier risk is increasingly a legal duty, not just good practice. Three examples relevant to this site's readers:
- Financial services in the EU: the Digital Operational Resilience Act (DORA) has applied since 17 January 2025. Covered firms must keep a register of their contracts with technology suppliers and manage the risks those suppliers create.
- UK organisations above a turnover threshold must publish an annual modern slavery statement under section 54 of the Modern Slavery Act 2015, setting out the steps taken to keep modern slavery out of their business and supply chains.
- EU sustainability due diligence rules were narrowed significantly in 2026 but not removed. Our procurement trends guide covers the new thresholds.
Even where a law does not name you directly, your larger customers often pass its requirements down to you by contract. Assume a large customer will eventually ask how you manage supplier risk.
Why relationships beat questionnaires
The standard approach is an annual supplier questionnaire. It has a place, but it tends to tell you what the supplier wants you to hear, once a year.
Relationships tell you things earlier. Olivier Berrouiguet, chief executive of Synertrade, put it simply on the Art of Procurement podcast:
You need to know your suppliers, what they can and what they can't do, and what they're ready to do on top of the relationship you have every day.
Olivier Berrouiguet, President and CEO, Synertrade
There is also a perception gap to be aware of. In RapidRatings' survey, 66% of buyers reported disruption but only 35% of suppliers did. The same event can look like a crisis from your side and a minor hiccup from theirs. Regular conversation is how you find out which it is before it matters.
Five mistakes to avoid
- Treating risk as a once-a-year questionnaire rather than something you watch.
- Looking only at your biggest suppliers by spend, and missing the small single-source supplier that can stop everything.
- Stopping at tier one. The risk often sits one step further back.
- Keeping a backup supplier you have never actually used.
- Squeezing fragile suppliers on price or payment terms, and causing the failure you feared.
Where to start this month
Do not try to build a full programme at once. In the next thirty days: clean your supplier list, identify your ten most critical suppliers, and for each one answer three questions — could we replace them within a month, where is the item actually made, and when did we last check their finances?
Those three answers will show you where your real exposure is, and it is rarely where people expect.
Common questions
What is supplier risk management?
Knowing which suppliers could hurt your business, how, and what you will do about it before it happens. In practice that means identifying critical suppliers, assessing their financial, operational, geographic, cyber and compliance risks, having alternatives for the most important items, and reviewing regularly rather than once a year.
What are the main types of supplier risk?
Seven cover most of it: financial risk (the supplier fails), operational risk (fire, quality failure, strike), concentration risk (too much depends on too few suppliers), geographic and trade risk (tariffs, sanctions, disasters by location), cyber risk (a supplier becomes the route for an attack), compliance and legal risk, and reputational risk.
What is the most common cause of supply chain disruption?
Suppliers themselves. The Business Continuity Institute's 2024 Supply Chain Resilience Report found third-party supplier failure was the leading cause of disruption at 43.6%, ahead of cyberattacks and natural disasters. Almost 80% of organisations had been disrupted in the previous twelve months.
What is tier-two supplier visibility?
Knowing who supplies your suppliers. McKinsey's 2025 survey found 95% of companies can see risks in their direct, tier-one suppliers, but only 42% can see into tier two or beyond. Of the 58% who had mapped tier two, fewer than half had regular contact with those companies. Much disruption starts one or two steps back.
How are cyber risks linked to suppliers?
Suppliers with access to your systems or data can become the route an attacker uses. Verizon's 2025 Data Breach Investigations Report found third-party involvement in confirmed breaches doubled from 15% to 30% in a year, across more than 22,000 incidents analysed. Ask every supplier with access what they can reach, how access is controlled, and how they would notify you of a breach.
What is the most effective way to reduce supplier risk?
Maintaining active alternative sources. In Deloitte's 2025 survey of more than 250 CPOs, 74% rated it the most effective mitigation, ahead of supply chain visibility (64%) and supplier information sharing (61%). Active is the key word: a backup supplier you have never ordered from cannot step in quickly. Place real orders with them, even small ones.
How often should supplier risk be reviewed?
Critical suppliers should be checked at least annually for financial health and more often if warning signs appear, such as slower deliveries or requests for faster payment. Risk should be monitored continuously rather than captured once a year in a questionnaire, and categories should be re-sorted at least annually because markets and supplier situations change.
Does regulation require supplier risk management?
Increasingly, yes. EU financial firms have been subject to DORA since 17 January 2025, which requires a register of technology supplier contracts and management of the risks those suppliers create. UK organisations above a turnover threshold must publish an annual modern slavery statement covering their supply chains. Larger customers also commonly pass these requirements down to their suppliers by contract.
How concentrated should my supplier base be?
Procurify's data across more than 250 mid-market organisations found the top five suppliers typically account for 57% to 59% of spend, and Procurify suggests 55% to 65% as a healthy range. Well above that means heavy dependence on a few suppliers. Well below may mean spend is spread too thinly to secure good terms. Single-source critical items matter more than the overall percentage.
Where should a mid-sized company start with supplier risk?
Clean the supplier list so each company appears once, identify the ten most critical suppliers, and for each answer three questions: could we replace them within a month, where is the item actually made, and when did we last check their finances? That takes about a month and shows where real exposure sits.
Sources
- Business Continuity Institute, Supply Chain Resilience Report 2024, 2 October 2024, sponsored by Zurich Resilience Solutions. Almost 80% disrupted; third-party failure 43.6% as leading cause; 17.1% analysing to tier 4 (from 3.7%); 20% report low or non-existent management commitment.
- RapidRatings, Annual Risk Report 2026, Published 2 March 2026; 200+ respondents, fielded late 2025. 82% material disruption; 15% fully integrating financial health into payment terms, 30% not at all; 66% of buyers vs 35% of suppliers reporting disruption.
- Resilinc, Global Supply Chains See Nearly 40% Annual Increase in Disruptions, 21 January 2025, covering 2024. 38% increase; 22,522 alerts; factory fires 2,299 (down 20%); floods +214%; geopolitical +123%; labour violations +146%.
- Verizon, 2025 Data Breach Investigations Report, 23 April 2025. Third-party involvement doubled to 30% from 15%; 22,000+ incidents, 12,195 confirmed breaches.
- McKinsey & Company, Supply chain risk pulse 2025: Tariffs reshuffle global trade priorities, 2 December 2025, 100 companies. 82% affected by tariffs; 95% tier-one vs 42% tier-two visibility; 58% mapped tier two, fewer than half in regular contact; 45% increasing inventory, 39% dual sourcing, 33% nearshoring plans.
- Deloitte, 2025 Global Chief Procurement Officer Survey, 250+ CPOs, 40 countries. Risk mitigation strategies (p.24): active alternative sources 74%, visibility 64%, information sharing 61%, near/reshoring 33%, portfolio rationalisation 31%, inventory 31%.
- Procurify, 2026 Mid-Market Procurement Benchmark Report, 250+ organisations, 2023–2025 data. Top-five vendor concentration 57.1–58.8% by segment; 55–65% suggested as healthy.
- UK Cabinet Office, The Sourcing Playbook (June 2023), Full document read. Joint risk registers, contingency planning, resolution planning, and guidance on assessing suppliers' economic and financial standing.
- CSSF (Luxembourg financial regulator), Entry into application of DORA regulation on 17 January 2025, Application date and register of information submission arrangements.
- UK Home Office, Transparency in supply chains: a practical guide, Section 54 of the Modern Slavery Act 2015 requires certain organisations to publish an annual modern slavery statement. The turnover threshold is set out in the full guide rather than this summary page.
- Art of Procurement, Relationship Building: The Key to Effective Risk Management in Procurement, Olivier Berrouiguet, President and CEO, Synertrade.
Want this run for you?
We take on the transactional half of procurement — invoices, purchase orders, supplier data and indirect spend — inside your own systems and under your approval rules. Start with a free spend audit: we measure your volumes, cycle times and exception rates, and the report is yours whether or not you go further.
Book a free spend audit


