Skip to main content

      Global businesses increasingly depend on complex third-party ecosystems while facing heightened cyber threats, regulatory scrutiny, supply chain disruption, and rapid technological change. KPMG International’s 2026 Global Third-Party Risk Management Survey[1] (TPRM), which gathered insights from 851 professionals across industries and geographies, shows that one-third of organizations suffered monetary loss or reputational damage due to third parties in the previous three years, while 28% experienced supply chain disruption. Cyber risk and regulatory compliance have consequently become the leading drivers of TPRM strategy, cited by 48% and 45% of respondents respectively. However, significant maturity gaps remain: only 18% of TPRM programs are fully integrated with enterprise risk management (ERM), and just 15% of leaders express high confidence in the data supporting their programs. These findings reinforce the need for boards to oversee TPRM as a strategic resilience priority rather than solely as a compliance exercise.

      Multinational firms must assess their operational resilience to ensure the third and fourth parties they deal with remain assets rather than liabilities. Potential risks incurred by dealing with third parties include the following:

      An increasing focus point of a sound TPRM framework and an area in which the board must be involved in setting out a corporate strategy and encouraging management to implement mitigating controls.

      An incident at a key third party can lead to regulatory scrutiny, with hefty fines for violating anti-fraud and anti-bribery regulations.

      Inadequate preparedness by either the third party or your organization to anticipate, withstand, respond to, and recover from severe but plausible disruptions can jeopardize timely restoration of critical services.

      Including business continuity, information security incidents (including data breaches), disaster recovery, physical security, misalignment with ESG, and performance management risks.

      From credit events to unnoticed insolvency issues at critical vendors.

      Spotting adverse media, litigation, and compliance issues at third parties is a key concern.

      Failure to recognize misalignment between a vendor's strategic goals and that of your organization may lead to service disruption. Potential incidents include full-service stoppage, as vendors reconsider their key accounts and business strategy.

      As outsourcing continues to increase, few firms have a clear view on their vendor's subcontractors and the risks these "fourth parties" pose. An outage at a cloud service provider of your vendor could have a direct impact on your day-to-day operations.

      A combination of services provided by a vendor could go unnoticed in a disjointed vendor management program. Alternatively, the geographic concentration of vendors in certain countries could rapidly pose risks to your organization if these countries become subject to sanctions.

      There is increasing regulatory pressure for firms to (a) integrate sustainability into corporate governance and management systems, (b) frame business decisions in terms of human rights, climate and environmental impact, and (c) have in place comprehensive mitigation processes related to adverse human rights and environmental impacts in their value chains.

      A robust TPRM framework is essential for navigating today’s increasingly complex third-party ecosystem. However, the findings of KPMG’s 2026 Global TPRM Survey demonstrate that many organizations continue to face significant challenges in translating awareness into effective execution. While third-party risk is widely recognized as a strategic priority, many firms struggle with fragmented operating models, limited integration between TPRM and enterprise risk management, and insufficient visibility across their third-party landscape. Additionally, confidence in the data underpinning TPRM programs remains low, with only 17% of organizations considering their data fully reliable and, as stated in the introduction, only 18% reporting full integration of TPRM into their ERM framework. As third-party networks continue to expand and risks become increasingly interconnected, organizations must evolve beyond compliance-driven approaches and invest in scalable operating models, high-quality data, integrated governance, and technology-enabled resilience.

      From a legislative perspective, TPRM has become increasingly complex as organizations must navigate a rapidly evolving regulatory landscape. Regulatory expectations continue to expand beyond traditional outsourcing oversight and now encompass cybersecurity, operational resilience, supply chain security, sustainability, and corporate accountability.

      • Financial institutions face some of the most mature and prescriptive TPRM requirements. While the European Banking Authority (EBA) Guidelines on Outsourcing Arrangements and the UK Prudential Regulation Authority (PRA) expectations remain relevant, the regulatory landscape has been fundamentally reshaped by the Digital Operational Resilience Act (DORA), which became applicable across the European Union in January 2025. DORA introduces comprehensive requirements for ICT third-party risk management, including enhanced due diligence, contractual standards, concentration risk assessments, ongoing monitoring, incident reporting, resilience testing, and exit planning. The regulation also establishes direct regulatory oversight of critical ICT service providers supporting the financial sector.
      • Outside the financial sector, regulatory expectations around third-party and supply chain risk have also intensified. The NIS2 Directive places greater emphasis on supply chain security and requires organizations operating in essential and important sectors to assess and manage cybersecurity risks arising from suppliers and service providers. In parallel, the Cyber Resilience Act (CRA) introduces cybersecurity obligations for products with digital elements, further increasing scrutiny of software vendors and technology suppliers throughout the value chain.
      • Organizations must also continue to manage third-party risks arising from compliance and integrity obligations. Regulations such as the Belgian Anti-Corruption Framework, the UK Bribery Act, and the US Foreign Corrupt Practices Act (FCPA) continue to hold companies accountable for the actions of intermediaries, agents, distributors, and other third parties acting on their behalf. As a result, third-party due diligence remains a critical component of effective compliance and risk management programs.
        This focus is further reinforced by the EU’s new Directive (EU) 2026/1021 on combating corruption [2], which strengthens the EU anti-corruption framework and places greater emphasis on the prevention and detection of corruption, including where offences are committed through intermediaries. The Directive also highlights the importance of effective internal controls and compliance programs and provides for corporate liability where a lack of supervision or control contributes to the commission of an offence. For organizations, this reinforces the need for a risk-based approach to third-party management, including appropriate due diligence, approval, contractual safeguards, ongoing monitoring, and escalation of corruption-related red flags. TPRM programs should therefore not only assess a third party's commercial and operational risks, but also provide demonstrable controls to identify and mitigate corruption and integrity risks throughout the third-party lifecycle.

      • Sustainability-related obligations are also increasingly influencing third-party risk management. The EU Corporate Sustainability Due Diligence Directive (CSDDD) [3], as amended by the 2026 Omnibus I simplification package [4], requires the largest companies within its scope to identify and address adverse human rights and environmental impacts across their operations and relevant chains of activities. While the 2026 amendments have significantly narrowed the scope of the Directive and postponed its application until July 2029, its underlying approach reinforces the importance of understanding sustainability risks within the value chain. For TPRM programs, this means that environmental and human rights considerations may need to be incorporated into third-party risk assessments, due diligence, contractual requirements, and ongoing monitoring. Moreover, companies outside the direct scope of the CSDDD may still face indirect requirements from customers, business partners, or other stakeholders seeking greater transparency and sustainability assurance across their supply chains.
      • Do we have an integrated TPRM framework covering the entire third-party lifecycle, and what is the maturity level of its key components?
      • Have we clearly defined the objectives, risk taxonomy, and risk appetite of our TPRM framework, and are these aligned with our broader Enterprise Risk Management principles?
      • Have we identified the regulatory requirements and scrutiny applicable to our third-party relationships?
      • Do we maintain a complete and up-to-date inventory of third-party relationships, including their corresponding risk classifications?
      • Can we obtain a current overview of each third party’s compliance with applicable organizational, contractual, and regulatory requirements?
      • Do we consolidate third-party risk information and TPRM activities to support portfolio-level oversight, escalation, and management reporting?
      • Have we identified and assessed emerging third-party risks, including fourth-party dependencies and concentrations involving individual providers, geographic regions, technologies, or subcontractors?
      • Have we identified the third parties supporting our critical or important business services and assessed the current and future impact of their disruption or unavailability?
      • Do we have adequate and tested business continuity, disaster recovery, and contingency arrangements to maintain critical business services following a major disruption at a key third party?

      In addition to the questions above for boards, management teams can consider asking the following questions:

      • Do we maintain an end-to-end view of third-party risks and dependencies throughout the lifecycle, from acceptance and onboarding to monitoring, reassessment, and offboarding?
      • Have we identified our critical third parties, fourth parties, and other dependencies, and assessed their importance and potential impact on critical business services?
      • Do we understand concentration risks arising from reliance on individual providers, cloud service providers, geographic locations, or other common dependencies?
      • Do we have a formal, risk-based process for third-party acceptance and onboarding, including documented approval decisions and appropriate risk ratings?
      • Can we consolidate and analyze relevant internal and external information to identify material third-party risks and support timely, risk-informed decision-making?
      • Do we have appropriate governance, organizational responsibilities, processes, and tools to monitor public and private third parties across jurisdictions?
      • Is our TPRM framework supported by appropriate technology, and should the selected tooling be integrated with the broader Governance, Risk, and Compliance environment?
      • Is TPRM effectively integrated with the contracting process, with clear requirements covering roles and responsibilities, resilience, service levels, incident reporting, audit rights, and exit arrangements?
      • Do we periodically reassess the risk profile, resilience, performance, and financial viability of third parties, particularly those supporting critical business services?
      • Do we have sufficient early-warning indicators and escalation mechanisms to anticipate and respond to potential third-party disruptions?
      • Do relevant corporate functions use consistent risk terminology, assessment criteria, reporting practices, and escalation procedures when managing third-party risks and disruptions?
      • Is sufficient cross-functional transparency available across the value chain to support continuous and coordinated third-party risk management?
      • Are any third-party risks operating outside the organization’s risk appetite, and are appropriate remediation or risk-acceptance actions being taken?
      • Do we have adequate and tested business continuity and contingency plans to maintain critical business services following the failure or disruption of a key third party?
      • Have significant third-party disruption scenarios been tested, with identified lessons translated into improvements to response and recovery arrangements?

      1. Ensure the management team has evaluated and addressed the gaps in your organization’s third-party governance process.

      2. Explore ways to enhance effectiveness in governing third parties by ensuring the company’s: 

      • Ability to anticipate supplier disruptions;
      • Consistent and ongoing access to data for all third parties;
      • Consistent cross-functional operating model to identify and mitigate risks in a timely manner;
      • Efficient data acquisition model;
      • Ability to define risk metrics and thresholds;
      • Robust data analytics;
      • Risk monitoring and alerts; and
      • Workflow processes to facilitate timely risk reviews.

      3. Consider technology solutions to uncover insights about the company’s suppliers and evaluate options for mitigating current and future risks.

      4. Ensure frequent testing of crisis management takes place, including business continuity plan testing. 

      About the Board Leadership Center

      KPMG’s Board Leadership Center (BLC) offers non-executive and executive board members – and those working closely with them – a place within a community of board-level peers. Through an array of insights, perspectives, and events – including topical seminars and more technical Board Academy sessions – the BLC promotes continuous education around the critical issues driving board agendas. 

      Authors: Jens Moerman, Director, Forensic and Jacob Masschelein, Senior Advisor, Forensic  

      Contact us

      Olivier Macq

      Partner, Chairman Board Leadership Center | Audit

      KPMG in Belgium

      Bart Meyer

      Partner, Technology | Advisory

      KPMG in Belgium

      Axel Jorion

      Partner | Audit

      KPMG in Belgium

      Stay informed

      Be the first to know about top business trends that can drive success for your company.

      stay informed