Skip to content.
A woman with red hair wearing a high-visibility vest holds a tablet and gestures while speaking to colleagues in a warehouse. Stacks of lumber are visible in the background. Another person in a high-visibility vest listens attentively.

Key takeaways

  • As manufacturers come to rely on more third-party suppliers as integral partners for their operations, today’s threats to production uptime often originate outside of the plant. 
  • Resilient manufacturers are shifting from reactive crisis management to proactive risk intelligence to better navigate a vast web of interconnected supplier risks. 
  • For compliance, ensuring resilience across the supply chain means more uptime, predictability and better business outcomes.

The source of disruption has evolved

Production shutdowns are far from a new challenge for manufacturers. Disruptions like equipment failure or worker injury are as old as manufacturing itself. External factors like raw material shortages and geopolitical tensions are well known. Through it all, the potential of enforcement action for noncompliance looms.  

Yet with the rise of increasingly complex, multi-layered supply chains across the industry, the nature of that challenge has evolved. Now, it is not enough for a manufacturer to ensure its own operations are resilient and compliant. Today, the risk posture extends deeper into third-party relationships, putting great value into visibility across sometimes vast networks of critical external entities.

Why manufacturers struggle to see risk beyond tier 1 suppliers

Modern organizations rely on a huge constellation of third parties for a wide range of needs varying from back-office software systems to physical supply chains. The exact numbers can vary, but they can be substantial – United States retail giant Walmart says it counts over 100,000 suppliers worldwide. 

As it’s unrealistic for most organizations to apply the same amount of vigilance to each of their suppliers, those with many third-party relationships often reserve the most acute vetting and monitoring for their most important “tier 1” partners. This ensures resources are focused on the parts of the supply chain where disruption would create the biggest negative impact. A less integral supplier may be subject to a more standardized and scalable level of scrutiny. 

Yet that does not mean a significant risk can’t emerge beyond tier 1 suppliers. Those most important suppliers rely on their own supply chains, for example, and a sudden crisis - weather, war, cyberattack – can send shockwaves through numerous downstream manufacturers. It’s easy to see how visibility into the risks beyond the tier 1 is a significant modern challenge.  

Facing this complex landscape, manufacturing risk and compliance leaders seem to recognize the value of their programs in addressing related concerns. The vast majority said they either “strongly” or “somewhat” agreed their third-party due diligence program significantly reduces legal, financial and reputational risks in a 2025 NAVEX survey.  Still, in a similar 2026 NAVEX survey, 15% of manufacturing leaders said their organization had experienced a third-party ethics or compliance failure in the past two years. 

As risks across the supply chain continue to grow, 29% of surveyed industry respondents said in 2026 their third-party due diligence program would see increased investment during the year. 

Cyber risk, third-party risk and operational risk are converging 

At times, third-party suppliers can be such an integral partner that they seem indistinguishable from a manufacturer’s own operations. Like cyber risk and broader operational risk, third-party risk thus joins a list of ever-present concerns for those tasked with keeping the production lines moving. 

These realms are now converging to support risk-based decision-making, encouraging a holistic and connected view of risk management. This may be the trend for the industry – when asked to select from a list of internal challenges that have increased for Compliance over the past 12 months, only one-quarter of surveyed manufacturing risk and compliance leaders selected " lack of alignment in how functions understand, discuss, and act on risk." 

However, there may be room to improve with closer partnerships across business units. In a 2025 NAVEX survey, manufacturing risk and compliance leaders were less likely than industries as a whole to indicate a strong relationship with most other business units like Data Privacy, Finance, Audit and Human Resources. 

The visibility gap that’s exposing manufacturers 

Ultimately, a supplier is not a business unit of the manufacturer. Visibility into risk is limited. This requires a highly collaborative and connected approach, one that includes ongoing monitoring of third-party risk at an appropriate intensity and interval executed through various touch points across the business. 

About three-quarters of manufacturing survey respondents told NAVEX in 2025 that their organization was at least “good” in this area. The question then becomes whether senior management has enough visibility into this continuing monitoring in order to make strategic decisions – that same year, only 32% of industry respondents said their organization has a centralized integrated risk management program run by senior management.  

Resilience is becoming a competitive advantage 

When buyers are looking to do business with a manufacturer, they will ask the same kinds of questions that the manufacturer might ask its third parties. Important among those findings is – how much do these factors all contribute to resilience and uptime, and whether I receive the product when I need it? 

For manufacturing, senior leaders are said to strongly see the value of compliance programs. A combined 82% of industry respondents said they either “strongly” or “somewhat” agree that senior leaders view those programs as a strategic advantage for the business. This suggests an opportunity for manufacturing risk managers to acquire the tools and resources they need to achieve greater resilience and address the many factors that could threaten a production shutdown.

A straight-on view of multiple rows of large, empty metal shelving units in a brightly lit warehouse or storage facility, creating a symmetrical corridor between the racks.

3 steps Compliance can take to build a more resilient manufacturing supply chain

Manufacturers of all sizes can consider some concrete efforts to address risks across the supply chain and build a more resilient operation: 

  1. AI may be the frontier for third-party risk assessment: In 2026, 14% of manufacturing risk and compliance leaders told NAVEX their organization was currently using AI for third-party risk screening and due diligence. These new technologies, when carefully implemented in partnership with the compliance program, may help the industry to manage their uniquely complex webs of supplier relationships and risks.  
     
  2. Adopt a proactive approach to third-party risk management: The reality of operations for many of today’s manufacturers means substantial disruptions can occur deeper in the supply chain. Ongoing monitoring across a wider swath of the network may now be necessary, and made possible with existing resources through purpose-built software and deeper relationships across business units. 
     
  3. View and communicate risk holistically: A risk-based approach to decision making may help senior leaders and other decision makers to act decisively when faced with a combination of third party, cyber, operational and other risks. Compliance and risk can enable these conversations – and many feel that senior leaders are ready to have them.

Build a stronger supply chain and more resilient organization

Risk and Compliance have the opportunity to strengthen the supply chains that support their organizations, making for more resilient manufacturing. 

Discover how a unified approach to third-party risk management can help your organization strengthen oversight, reduce risk, and build more resilient operations across every facility, supplier and geography.