Operational Risk | Insights, Resources & Best Practices

Detection Isn’t Enough: The Case for Supplier Engagement in Risk Management

Written by Pierre-François Thaler | July 24, 2026

Forty-four percent of companies In a recent survey said they experienced four to 10 supply-chain disruptions from third-party failures, trade disputes, labor issues, or environmental events.

The risk management stack most companies have built – continuous monitoring platforms, AI risk intelligence tools, or supplier scorecards – work like smoke detectors. They are a much needed foundation to alert companies to their risks, but they aren’t equipped to actually reduce exposure.

AI has made that detection far faster and broader, but AI only spots more fires rather than putting them out.

That gap is getting more expensive by the day. Supply-chain disruptions cost the global economy $86 billion in 2025, and pressure is mounting on every front, from geopolitical shocks to trade restrictions to tightening scrutiny on supplier practices.

Supplier engagement is the mechanism needed to turn detection into measurable risk reduction. The companies that build it into their risk management programs now will define what resilient supply-chain management looks like over the next decade.

The Risk of Stopping at the Alert

The Middle East conflict that disrupted shipping through the Strait of Hormuz is a useful test case for what detection alone actually buys you. The IEA called it the “largest supply disruption in the history of the global oil market,” and every company with a monitoring tool saw it coming.

EcoVadis Co-CEO Pierre-François Thaler

The companies that struggled could see the region was exposed but couldn't answer what came next: Which suppliers actually route materials through that corridor? Which had qualified a second source outside it that could take volume in days? And how far down did the exposure run – a tier-1 supplier looking fine while quietly dependent on a single tier-3 supplier from inside the affected area?

The companies best equipped to navigate the disruption had already mapped which suppliers touched the corridor, had a pre-qualified alternate outside the region, and knew from a conversation months earlier which tier-1s were exposed at the tier-3 level. When the news hit, those companies were rerouting while competitors were still emailing suppliers to ask whether they were affected.

A monitoring tool will flag the region, but it won’t tell you which of your suppliers have an actual plan.

More Data, Same Blind Spot

The problem isn’t only that monitoring tools can’t answer those questions. It’s also that most companies don’t have the internal infrastructure to answer them.

Companies already collect large amounts of supplier information through procurement, sustainability, and due diligence programs. But this intelligence rarely makes it into risk management processes in a form that risk and compliance leaders can use. The result is a structural disconnect where the teams generating supplier insight operate separately from the teams accountable for managing risk. Neither can do the full job alone.

AI is supercharging this disconnect. When AI operates on scattered, half-verified data, it produces fast, confident signals built on shaky inputs. AI can help synthesize risk data across the supply chain, but only when inputs are reliable. And even then, someone on the risk team needs to own the supplier engagement process – e.g., picking up the phone, understanding what’s happening, and driving the response. These are still human-centric responsibilities.

Companies that engage their suppliers continuously reduce the share of suppliers in the high-risk zone. Fewer suppliers in the risk zone means fewer incidents, cleaner audit results, and a supply base materially harder to disrupt.

From Monitoring to Prevention

Detection is becoming a commodity. Your competitors will see the same risks you do, at the same moment. What separates the companies that can successfully navigate a disruption – or a regulator’s inquiry – from those who don’t is the work that happens before a crisis hits, such as:

1. Prioritize suppliers by risk and criticality. Not every supplier needs the same level of engagement. Focus first on the ones that combine operational importance with elevated risk exposure, e.g., the suppliers whose failure would actually stop you, and the ones already showing signs of trouble. That prioritization is only as good as the data behind it. Without verified, scored assessments, you're working from tier classifications and self-reported information, which tells you where a supplier sits in your network but not how they're actually performing.

2. Turn findings into action plans. Treat each risk alert as the start of a conversation, but one grounded in verified data, not just the alert itself. When you go to a supplier with an assessment result, there’s less room for dispute about what the problem is or what needs to change. Work directly with the supplier on corrective action plans with clear milestones and defined accountability on both sides, and follow through on each one.

3. Supplier capability-building. Many suppliers, especially smaller ones, don’t have the systems or resources to drive engagement and improvement on their own. Equip them with the tools, training, and support they need to share verified data and make measurable improvement over time. A supplier who can’t do that remains a blind spot regardless of how often you engage them. Capability-building is how you convert an unverifiable supplier into one you can actually manage.

4. Create continuous engagement cycles. Episodic engagement, or one-time audits, create false confidence because conditions change faster than the review cycle. Resilience is built by keeping the supplier dialogue open year-round and reassessing on a regular cadence, so teams already know where they stand when a disruption hits.

The companies that will navigate the next decade of supply-chain pressure aren’t necessarily the ones with the most sophisticated monitoring tools. They’re the ones that treat supplier engagement as a core risk function – not a sustainability initiative, not a procurement task – and build the programs to prove it. The ones that start now will spend the next decade responding from a position of readiness. The ones that don’t will still be sending emails to find out who’s affected.

 

Pierre-François Thaler is Co-Founder and Co-CEO of sustainability ratings and insights provider EcoVadis. Before the founding of EcoVadis in 2007, he was director of Managed Services at Ariba and CEO of B2Build, the first B2B marketplace for the European construction industry.