KPMG Surveys Find Third-Party & Supply Chain Risk Converging
Key Takeaways
- Risk Moves to the Center: Regulatory compliance and cyber risk are the leading drivers of third-party risk strategy, while U.S. supply chain leaders rank managing risk and geopolitical uncertainty as their top transformation objective.
- Integration Remains Incomplete: Just 18% of organizations report full integration between third-party risk management and enterprise risk management, despite 71% planning further integration over the next three years.
- AI Adoption Outpaces Effectiveness: Between 50% and 58% of respondents report using AI across TPRM activities, but only 22% describe it as “very effective,” with fragmented systems and uneven data quality limiting its value.
- Partner Networks Are Expanding: Eighty-three percent of executives expect their partner networks to grow over the next one to three years, increasing the importance of deeper supplier visibility and risk-based oversight.
- Supply Chains Are Being Rebuilt Around Resilience: Seventy-three percent of U.S. supply chain leaders plan comprehensive operating-model transformation within three years, while 94% are innovating in risk management and resilience or plan to do so.
Deep Dive
Regulatory compliance and cyber risk are driving third-party risk management strategies. Supply chain leaders, meanwhile, rank cybersecurity as their top perceived risk and managing risk and geopolitical uncertainty as their leading transformation objective. Companies are preparing to expand their partner networks and automate more of the work that holds those networks together. Their risk functions are not always keeping pace.
The findings come from two KPMG studies published this year. The 2026 Global Third-Party Risk Management Survey covers 851 organizations globally. KPMG’s 2026 U.S. Supply Chain Survey polled 462 supply chain leaders at companies with at least $1 billion in annual revenue.
The surveys approach the problem from different directions, but there is considerable overlap in what respondents are worried about. In the global third-party risk survey, regulatory compliance was the leading driver of TPRM strategy, cited by 48% of respondents, followed by cyber risk at 37%. Spending reflects those priorities. Risk assessment and due diligence drew investment from 52% of organizations, followed by TPRM technology and tools at 51%, cybersecurity and data protection at 49%, and regulatory audits at 45%.
The U.S. supply chain findings widen the lens. Cybersecurity ranks as the top perceived supply chain risk, followed by exposure to multi-tier supplier networks, with shortages and regulatory pressure also among the concerns facing respondents. Managing and mitigating risks and geopolitical uncertainties ranks first among transformation objectives and is also the top near-term investment priority.
This is happening as companies prepare to rely on more outside partners, not fewer. Eighty-three percent of executives in the global TPRM survey expect their partner networks to expand over the next one to three years. Nearly half, 48%, see room to improve collaboration with those partners on risk management.
The difficulty is found in what sits between those ambitions and the systems companies have built to support them. Only 18% of organizations told KPMG that third-party risk management is fully integrated with enterprise risk management. Another 53% described the two as mostly integrated. Seventy-one percent plan further integration over the next three years.
The distinction between “mostly” and “fully” integrated can sound administrative until a third-party problem stops being merely a third-party problem. TPRM teams tend to work with the immediate facts of vendors and individual relationships. Enterprise risk teams are looking across the organization at strategic threats. Separate teams, priorities and methods can leave companies with plenty of information about individual suppliers and a less certain understanding of what those suppliers mean for the business as a whole.
KPMG’s supply chain findings make that separation harder to ignore. Ninety-four percent of respondents are innovating in risk management and resilience now or plan to do so within three years. Seventy-three percent expect to undertake a comprehensive transformation of their supply chain operating model over the same period.
The supplier network itself is becoming part of the risk equation. KPMG recommends developing greater “Nth-party” visibility so organizations can understand dependencies deeper in their supply chains and identify concentration risks that may not be apparent from looking only at direct suppliers.
AI Runs Into the Plumbing
Artificial intelligence occupies a prominent place in both studies, although KPMG’s third-party risk findings offer a useful corrective to the idea that adoption and effectiveness are the same thing. Depending on the TPRM activity, between 50% and 58% of respondents reported using AI. Only 22% described it as “very effective.” Another 40% said it was “somewhat effective.”
The problem is not necessarily the AI. Most organizations use between one and five systems to support TPRM, according to KPMG, and integration with other platforms is their leading technology pain point. That leaves many organizations trying to introduce AI into processes already divided among disconnected systems.
Then there is the data. Only 17% of organizations reported the highest level of TPRM data quality. Fifty-nine percent said their data was mostly complete, accurate and consistent. The difference shows up sharply in how much respondents trust the decisions they make: among organizations with high-quality data, 52% were very confident in their TPRM decisions. Among those with poor-quality data, 40% were not confident.
AI cannot make those distinctions disappear. If anything, greater automation makes the quality of the underlying information harder to dismiss. KPMG found that the more effective applications of AI connect disparate processes and have clear ownership across an end-to-end workflow. Siloed agents handling individual steps have proved less effective.
Supply chain leaders nevertheless expect considerably more automation. Seventy-eight percent of respondents to the U.S. survey plan to reach at least a moderate level of supply chain autonomy by 2027. Seven in 10 expect AI and generative AI to significantly transform the supply chain workforce.
That workforce already has holes in it. Seventy-seven percent of respondents reported a talent gap in their organizations’ procurement and supply chain functions. The attraction of automation is therefore not difficult to understand. Companies are being asked to oversee more suppliers, collect more information and respond to more kinds of risk while struggling to find enough people to do the work.
More Outsourcing, but Rarely All of It
Organizations have already found another way to absorb some of that workload. More than 80% of respondents to KPMG’s global TPRM survey use managed services, outsourcing or some combination of the two for core activities. Yet only 5% have adopted an end-to-end managed service model.
Most are handing off pieces of the process instead. High-volume work such as risk assessments and due-diligence questionnaires can be outsourced while the larger TPRM lifecycle remains inside the organization.
There are practical reasons for the reluctance to go further. KPMG identified concerns about losing control and sharing proprietary data as barriers to broader adoption. At the same time, the firm expects AI to push managed services toward more technology-enabled models, including high-volume automated screening and chatbots that can resolve lower-risk queries more quickly.
Outsourcing the work does not outsource responsibility for it. KPMG argues that organizations using managed services still need strong governance, effective oversight and clear alignment with their own risk appetites.
That point becomes more important as the two surveys are read together. Companies are expanding their networks of external partners. Their supply chains are becoming more automated. They are using outside providers to perform more risk-management work. And they are experimenting with AI inside systems whose data and integration remain uneven.
None of those developments is inherently at odds with resilience. They do make fragmentation increasingly expensive.
KPMG’s global survey ultimately recommends concentrating resources on vendors that present meaningful risk rather than screening broadly, integrating TPRM more closely with ERM, improving data governance, extending visibility into deeper tiers of the supply chain and using AI across coherent workflows instead of isolated tasks. Managed services can provide additional scale, provided organizations retain control of governance and strategy.
The U.S. supply chain survey suggests companies have already decided that substantial change is coming. Risk management and resilience lead their investment plans, and nearly three-quarters expect comprehensive operating-model transformation within three years.
What remains less settled is whether the information, governance and organizational structures underneath that transformation are ready for everything companies intend to put on top of them.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

