Global businesses increasingly depend on complex third-party ecosystems while facing heightened cyber threats, regulatory scrutiny, supply chain disruption, and rapid technological change. KPMG International’s 2026 Global Third-Party Risk Management Survey[1] (TPRM), which gathered insights from 851 professionals across industries and geographies, shows that one-third of organizations suffered monetary loss or reputational damage due to third parties in the previous three years, while 28% experienced supply chain disruption. Cyber risk and regulatory compliance have consequently become the leading drivers of TPRM strategy, cited by 48% and 45% of respondents respectively. However, significant maturity gaps remain: only 18% of TPRM programs are fully integrated with enterprise risk management (ERM), and just 15% of leaders express high confidence in the data supporting their programs. These findings reinforce the need for boards to oversee TPRM as a strategic resilience priority rather than solely as a compliance exercise.
Multinational firms must assess their operational resilience to ensure the third and fourth parties they deal with remain assets rather than liabilities. Potential risks incurred by dealing with third parties include the following: