All Posts

Procure Tech

Why Supplier Risk Is Becoming Procurement's Job, Not Legal's

Why Supplier Risk Is Becoming Procurement's Job, Not Legal's

Bhavika J

Editorial Team

What supplier risk management means inside source-to-pay

Source-to-pay software covers the full purchasing cycle: finding suppliers, running sourcing events, negotiating contracts, issuing purchase orders, and matching invoices for payment. Supplier risk management is the layer sitting inside or alongside that workflow that scores and monitors vendors on financial stability, cybersecurity exposure, regulatory compliance, and concentration risk, meaning how much of a company's spend or critical operations depend on a single supplier.

For most of the category's history, that scoring lived in a separate compliance or legal tool, often a spreadsheet updated once a year at contract renewal. That is changing, and the reason is regulatory, not commercial preference.

Why regulators are pulling it into procurement's system of record

Two rules now in effect give procurement teams a concrete reason to keep supplier risk data live inside the systems they already use to buy.

The first is the EU's Digital Operational Resilience Act. It requires financial entities to maintain a Register of Information on every contractual arrangement with an ICT third-party provider. National authorities ran the first full collection cycle in 2025 and forwarded the results to the European Supervisory Authorities, ESMA, EIOPA and EBA, who used the data to identify which ICT providers are critical enough to supervise directly at EU level. Belgium's financial regulator confirmed the 2026 cycle would repeat with a narrower scope, letting firms with no changes simply confirm the prior year's register rather than resubmit from scratch (FSMA, 2026). The requirement itself does not go away between cycles: entities in scope have to keep the register current year-round, which only a structured system, not an annual spreadsheet exercise, can realistically support.

The second is the EU's Corporate Sustainability Due Diligence Directive, recently narrowed by the bloc's Omnibus simplification package. The Council gave final approval on 24 February 2026, and the amending directive entered into force on 18 March 2026, raising the threshold so the rule now applies only to companies with more than 5,000 employees and above 1.5 billion euros in net turnover (Consilium, 2026). Member states must transpose the narrowed rules by 26 July 2028, with obligations applying from 26 July 2029 (Consilium, 2026). Fewer companies are captured, but the ones still inside the threshold are the largest multinational buyers, exactly the organizations with the deepest and most opaque supplier networks. For them, due diligence obligations point directly at data procurement already owns: who the suppliers are, where they sit in the chain, and what has changed since onboarding.

How the market is responding

Two patterns show up in how vendors have built for this. Some sell supplier risk as a dedicated module attached to a broader suite. SAP Ariba Supplier Risk, for example, monitors financial, operational, regulatory and legal risk signals on suppliers using external data feeds and updates risk levels as conditions change, rather than only at onboarding (SAP, 2026). Others fold risk visibility into the full source-to-pay suite as one evaluation factor among several. The category is now large enough to draw dedicated analyst coverage on that basis: Gartner's Magic Quadrant for Source-to-Pay Suites, published 21 January 2026, evaluated 13 providers on their ability to execute and completeness of vision (Gartner, 2026).

The category has room to keep splitting further. Grand View Research valued the global procurement software market at 10.1 billion dollars in 2025, projecting growth to 21.3 billion dollars by 2033 (Grand View Research, 2026), a large enough number that specialist risk-only vendors and full-suite platforms are both finding room to compete rather than one model displacing the other.

What to look at when evaluating these tools

Buyers comparing options should check a few things directly rather than take a vendor's category label at face value. First, monitoring cadence: does the tool reassess suppliers continuously against new data, or only refresh scores at renewal. Second, coverage breadth: financial health, cyber posture, sanctions and watchlist screening, and concentration risk are different data problems, and few tools cover all of them equally well. Third, whether risk data actually feeds back into sourcing decisions and contract terms, or sits in a report nobody reads until an auditor asks for it. Fourth, whether the tool can map suppliers against specific jurisdictional requirements, since DORA and CSDDD are not the only regimes procurement teams now have to answer to, and more are coming.

What commonly goes wrong

The most common failure is treating supplier risk scoring as a one-time onboarding gate. A supplier that passed review two years ago can carry very different financial or cyber exposure today, and a system that only checks at intake will miss that. The second is keeping the register outside the procurement system entirely, in a spreadsheet or shared drive that nobody updates on a schedule, which is precisely the practice DORA's Register of Information requirement was built to end for financial entities, and what non-financial buyers are now recreating voluntarily under pressure from customers and boards. The third is assuming a narrower legal scope means lower operational stakes. CSDDD now applies to fewer companies, but the companies still inside it are the ones with the most suppliers to track, not fewer reasons to track them well.

The next concrete deadline is 26 July 2028, when EU member states must have transposed the narrowed CSDDD rules into national law, with compliance obligations following on 26 July 2029 for the companies still in scope (Consilium, 2026).