Blog
Supplier risk management has become more visible in recent years. Procurement, supplier risk, and supply chain teams now have access to an incredible range of data, including financial performance and compliance signals, geopolitical indicators, ownership structures, ESG risk, and much more.
Yet for many organizations, greater visibility has not translated into better outcomes.
A Forrester Consulting study* commissioned by Dun & Bradstreet highlights a broader challenge facing organizations today. While companies are collecting more risk data and increasing investments in analytics and AI, many have difficulty translating risk insights into effective action. In fact, 71% of organizations reported challenges in moving from risk identification to successful risk treatment.
For procurement and supplier risk leaders, this can create a persistent gap: supplier risk may be visible, but not always fully understood, prioritized, or addressed in time to prevent disruption.
Organizations collect more risk data than ever, yet many continue to face obstacles when turning risk insights into effective treatment strategies.
Data silos and fragmented risk information can continue to limit collaboration, visibility, and timely risk response across the enterprise.
Multi-tier supplier networks, third-party dependencies, and regulatory pressures can make supplier risk harder to monitor and mitigate proactively.
AI and predictive analytics can strengthen supplier risk management, but success often depends on connected, trusted, decision-ready data.
The Forrester Consulting research provides a snapshot of the challenges, business impacts, and strategic investments shaping supplier risk management today. The data reveals where organizations are focusing their efforts to improve visibility, strengthen resilience, and support more informed risk decisions.
Supplier risk management is the practice of identifying, assessing, monitoring, and mitigating risks that could disrupt supplier performance, supply continuity, regulatory compliance, or business operations. Supplier risk is not confined to procurement or periodic supplier due diligence. It can touch business continuity, regulatory exposure, financial performance, operational resilience, and customer commitments.
That shift has helped raise expectations for procurement and supplier risk teams. Leaders may be expected to identify supplier issues earlier, understand how those issues could affect the business, and coordinate action across functions before disruption occurs.
This is occurring as supply chains grow more complex and globally distributed — increasing both visibility and exposure at the same time.
Forrester Consulting research found that more than a third of organizations cite challenges such as mitigating sub-tier supplier risk across the supply chain, predicting and preparing for external risks, and monitoring third-party compliance to avoid violations.
For procurement and supplier risk leaders, those challenges can be connected. A supplier issue may begin as a compliance concern, a financial health signal, a logistics disruption, a geopolitical exposure, or a hidden dependency several tiers deep. If the data behind those signals is disconnected, the organization may not recognize the full risk until the impact is already underway.
The scale and structure of modern supply chains can be key drivers of supplier risk.
According to the Dun & Bradstreet Manufacturing Pulse Survey, supply chains are increasingly multi-tiered: 29.2% of manufacturers report an average of three tiers in their supply chains, 16.7% manage four or more tiers, and 19.4% report a full multi-tier supply chain that includes raw material sources.
Visibility can drop sharply beyond direct suppliers. The Manufacturing Pulse Survey found that 23.2% of manufacturers monitor only Tier 1 suppliers for compliance, while only 18.1% monitor Tier 4 or full multi-tier supply chains.
The consequences are significant:
97% of manufacturers report negative impacts from complex supply chains.
29.1% report increased operational costs.
28.9% report delays in product delivery.
Supplier risk rarely originates neatly at Tier 1. Disruptions often emerge deeper in the supply chain — from sub-suppliers, raw material sources, unknown ownership structures, or hidden dependencies. Without integrated supplier data and shared visibility across tiers, these signals can remain isolated until the impact is already visible in operations.
This may create a familiar dynamic: organizations may understand their direct suppliers relatively well, but lack the insight needed to anticipate cascading risk across the broader supplier network.
The Manufacturing Pulse Survey also found that the most commonly reported reason for not monitoring deeper supplier tiers is lack of data and information, cited by 39% of manufacturers.
That finding suggests a critical limitation in traditional supplier risk management. Monitoring Tier 1 suppliers may not be sufficient when disruption can originate deeper in the ecosystem. Without a multi-tier view supported by reliable supplier data, organizations may remain exposed to risks they cannot see clearly — and therefore cannot act on in time.
Even when supplier risk is visible, fragmented data can limit action.
Forrester Consulting research found that 55% of businesses say data silos prevent cross-functional collaboration. The same research found that while many organizations can share data across departments in some form, only 11% can do so effectively to identify and manage risk.
The consequences extend beyond reporting inefficiencies. Among surveyed procurement and supply chain leaders, a significant majority reported lost revenue tied to risk management challenges, while many others reported operational breakdowns and ineffective supplier relationship management when risk information is not shared effectively across the organization.
This disconnect may be especially damaging in supplier risk management because the relevant data often sits across multiple systems and teams, including procurement, compliance, finance, and external data sources.
Without integration, supplier risk signals may lack the context needed for prioritization and escalation. Procurement may see supplier performance issues, compliance may track sanctions or regulatory exposure, and finance may monitor payment or credit risk. But without a unified supplier view, the organization can miss how those signals connect.
The cost is not just poor reporting. It can be slower responses. When supplier data is fragmented:
Early warning signals stay isolated.
Escalation requires manual coordination.
Mitigation becomes reactive.
This can reinforce a cycle where visibility may improve incrementally, but response timing may not.
Notably, many organizations are responding by strengthening data foundations for AI-enabled risk management. Investments in modern data infrastructure, interoperability, and internal AI expertise suggest that leaders increasingly recognize that better risk outcomes depend on connected, decision-ready supplier data.
Confidence in AI and predictive analytics is high. Forrester Consulting research found that 72% of organizations agree AI tools would significantly improve their ability to predict and treat risk, while 73% agree predictive analytics have already helped their organization proactively mitigate risk.
For procurement and supplier risk teams, these technologies can be especially valuable for:
Monitoring third-party exposure
Identifying emerging supplier disruptions
Detecting patterns across large supplier networks
Prioritizing risk signals by severity and likely business impact
Monitoring regulatory and policy changes that may affect suppliers
However, insight alone often is not enough.
The Manufacturing Pulse Survey highlights an underlying data challenge. Only 36% of manufacturers say they can make informed decisions with their current data, and 44% have experienced failed AI projects due to poor data quality.
AI can amplify the value of supplier risk data. But it can also expose the limitations of fragmented, incomplete, or poorly governed data.
Supplier risk is also being reshaped by external pressures.
The Manufacturing Pulse Survey found that 33.4% of manufacturers cite regulatory changes, including tariffs and sanctions, as a major supply chain challenge. It also found that 25.3% cite dependency on critical suppliers.
These risks are structural, not temporary. Procurement and supplier risk teams typically are operating in an environment where regulatory change, geopolitical disruption, supplier concentration, and third-party compliance exposure increasingly intersect — often across multiple tiers.
At the same time, many manufacturers are attempting to reduce exposure by shifting supply chains closer to home. According to the Manufacturing Pulse Survey, 61% of manufacturers are looking to move more than half of their supply chains closer to home. However, only 8% say nearshoring or localization is a priority in the next year, suggesting this is a longer-term strategy rather than an immediate fix.
New supplier networks introduce different dependencies, regulatory considerations, cost structures, and operational complexities. Without the data and visibility needed to understand these new ecosystems, organizations risk recreating the same supplier risk challenges in a different form.
Closing the gap between visibility and action takes more than better reporting. It requires a supplier risk management approach that connects data, analytics, workflows, and accountability.
First, organizations need to integrate internal and third-party data to create a unified view of supplier risk. This means connecting procurement, onboarding, compliance, finance, and external data into consistent supplier profiles that provide insight into ownership, financial health, regulatory exposure, and dependencies.
Second, supplier risk insight needs to be embedded directly into procurement and supplier management workflows — informing sourcing decisions, onboarding, supplier evaluations, contract reviews, and ongoing relationship management.
Third, procurement and supplier risk teams need shared definitions of risk. Procurement may focus on continuity, compliance on regulatory exposure, and finance on financial viability, but these perspectives need to align. A shared framework helps teams interpret signals consistently and act faster.
Finally, organizations need to prioritize decision-ready data. The challenge is not just collecting more data, but ensuring it is trusted, connected, current, and available at the point of decision.
Organizations that adopt these approaches can move from reactive to proactive supplier risk management — identifying issues earlier, prioritizing mitigation more effectively, and reducing downstream impact.
Supplier risk management is entering a new phase. Visibility is improving, but the complexity of supply chains and the speed of disruption have outpaced traditional approaches.
The findings from Forrester Consulting and Dun & Bradstreet point to a strong conclusion: seeing supplier risk is necessary, but may no longer be sufficient.
For procurement and supplier risk leaders, the challenge may not be to simply identify risk. They are increasingly expected to manage risk across multi-tier supplier ecosystems, integrate fragmented data, apply AI responsibly, and act early enough to protect business outcomes.
Success can depend on the ability to connect supplier risk insight to decision-making across the broader supplier network — before disruption becomes unavoidable.
*“Centralizing Risk, Unlocking Value: Modernizing Risk Management In The Age Of AI,” a commissioned study conducted by Forrester Consulting on behalf of Dun & Bradstreet [June 2026].
There are multiple Contact Forms popups in the page. Only one Contact Form popup could be present on single page. Please reconfigure Contact Forms and refresh the page.