Ask Kepler.ai
The World's Business Knowledge

Risk & Compliance

Your supply chain is three layers deeper than you think

Most organizations know their direct vendors but miss the subcontractors, sub-suppliers, and hidden dependencies that sit beneath them—along with the geopolitical, sanctions, and concentration risks they carry. Here's how to map what you can't see.

Ask Kepler Research ·With benchmark data

Most mid-market organizations have visibility into their direct vendor base but lack a systematic picture of second- and third-tier suppliers, sub-tier dependencies, and the concentration points where seemingly diversified supply chains converge. This gap exists because mapping beyond direct vendors requires integration across procurement systems, third-party data feeds, and vendor transparency—most of which companies either don't have or only refresh annually. The consequence is real: concentration risk, geopolitical exposure, and single points of failure buried several tiers down remain invisible until a disruption surfaces them. Closing this gap requires three things: a structured approach to mapping supplier ecosystems, continuous screening for regulatory and sanctions exposure, and a discipline around identifying which vendors are truly critical to your operations.

What good looks like

MetricMinimumStrongWorld-class
Supplier Risk Assessment Completion RatePercentage of active suppliers with current documented risk evaluations (financial, operational, compliance, geopolitical) completed within the past 12 months.60-70%80-90%95-99%
Supplier Risk Remediation TimeAverage number of days from identification of a material supplier risk (credit, quality, compliance, delivery) to documented remediation plan or supplier exit decision.45-6020-355-15
Supply Chain Disruption Recovery RatePercentage of supplier-induced disruptions (quality failures, delivery delays, financial distress) resolved to acceptable service levels within 30 days of incident identification.55-70%75-85%88-96%
Supplier Risk Data Freshness IndexRatio of suppliers with updated financial, compliance, and operational data refreshed within the past 6 months versus total active supplier base.0.50-0.650.75-0.850.90-0.98
Critical Supplier Risk Mitigation CoveragePercentage of suppliers classified as critical (single-source, strategic, long-lead, high-spend, or regulatory-gated) with documented risk mitigation plans including alternatives, buffer stock, or contractual hedges.50-65%75-85%92-98%

The gap between minimum and world-class performance is instructive. Organizations at the minimum tier complete supplier risk assessments on 60-70% of their vendor population and take 45-60 days to remediate discovered risks. World-class performers assess 95-99% and remediate in 5-15 days. That speed difference reflects two things: automation of risk detection (continuous monitoring rather than annual snapshots) and pre-built decision authority (clear escalation and contingency protocols that don't require committee approval). On data freshness—a measure of how current your supplier intelligence actually is—minimum performers operate at a 0.50-0.65 ratio, meaning roughly half their data is stale. World-class organizations maintain 0.90-0.98 freshness by automating third-party data feeds and embedding procurement systems into risk monitoring platforms. The recovery metric matters most for supply chain continuity: minimum-tier organizations recover from disruptions at a 55-70% rate, while world-class performers recover at 88-96%. That differential is not about luck. It reflects dual-sourcing discipline, geographic diversification, and pre-negotiated contingency supplier relationships built before crisis forces their use.

Industry-Specific Benchmarks

These ranges are cross-industry. The figures differ materially by sector and company size.

Find benchmarks for your industry →

Why the gap exists

The journey from middle-tier to world-class performance turns on two structural shifts. First is visibility architecture. Mid-tier organizations typically maintain vendor databases and conduct periodic risk assessments—usually annually—using static data and manual review cycles. This creates a false sense of control: you have a list, it looks complete, but the data ages the moment it's collected. Meanwhile, your subcontractors shift, ownership changes, geopolitical exposure evolves, and sanctions lists update weekly. World-class performers embed continuous monitoring directly into procurement systems, automate third-party data integration, and establish rescreening cadences that catch changes as they happen rather than months later. The second shift is decision velocity. When a risk is discovered, mid-tier organizations often route it through committee structures or require approval chains that stretch remediation timelines to 20-35 days. By that point, the exposure has often widened—additional orders may have gone to the vendor, more integration has occurred. World-class organizations pre-negotiate alternative suppliers, establish clear escalation protocols with defined decision authority, and maintain contractual frameworks that allow rapid switching. They can remediate in days because the decision infrastructure is already in place.

The cost of staying in the middle tier is measurable in three ways. First, you miss disruptions that hit you suddenly because they were invisible. A critical subcontractor goes down, and you discover—only then—that three of your direct vendors rely on it exclusively. Second, you carry compliance risk: sanctions exposure and regulatory violations often stem from doing business with restricted parties buried in your supply chain. A vendor's ownership changes, you don't know, and months later you discover you've been indirectly transacting with a sanctioned entity. Third, you can't optimize where it matters. If you don't know which vendors are truly critical versus interchangeable, you can't strategically invest in dual-sourcing, geographic diversification, or contractual resilience clauses where they'd actually move the needle.

The path to world-class is not about buying a new system. It's about three things: systematizing what you assess (not just direct vendors, but sub-tier suppliers and their interconnections), automating data collection and rescreening (so freshness stays high), and distributing decision authority (so discoveries can be acted on quickly). Organizations that have made this shift typically find that their risk profile doesn't actually change—but their visibility and response speed do, often dramatically.

What leading organizations do

Continuous Regulatory Screening for Vendor Populations

Regulatory agencies maintain extensive lists of individuals and entities subject to sanctions, restrictions, and legal judgments—OFAC lists, EU sanctions regimes, sectoral restrictions, export controls, and integrity watch lists. Doing business with parties on these lists can expose organizations to fines of 20-50% of transaction value or higher, criminal prosecution, license suspension, and reputational damage. The mechanism is straightforward but often overlooked: most organizations screen vendors at onboarding and never screen again. This creates a compliance gap when ownership changes hands, when sanctions lists are updated (which happens constantly), or when a vendor's parent company or beneficial owner is added to a restricted list. An organization screening only at onboarding misses all of these shifts until a regulator surfaces them.

Continuous screening—automated checks at onboarding, periodic rescreening at defined intervals, and automated flagging when vendors' beneficial ownership or jurisdictional status changes—catches compliance exposure before violations occur. This requires integration with reliable third-party data feeds that maintain current lists and ownership records, plus a disciplined process for investigating and resolving false positives (which are common in name-matching across global lists). The payoff is substantial: organizations with automated continuous screening across their vendor population reduce compliance violations and regulatory fines by 80-95% compared to manual or periodic approaches. It also accelerates onboarding by automating compliance verification and reduces the manual investigation burden significantly.

For most mid-market organizations, the roadmap runs in three phases: first, comprehensive screening at vendor onboarding with clear ownership verification; second, integration with third-party data feeds for automated rescreening; third, escalation automation so that flagged vendors route to decision-makers without manual hunting. Few organizations get beyond phase one on their own.

Leading Practice Report

Full detail: Third-Party Regulatory and Sanctions Compliance Screening

The full report covers:

  • Expected benefits
  • Core principles
  • Key success factors
  • Key metrics
  • Risks and mitigations
  • Implementation roadmap
Get the full report →

Industry context

Supply chain mapping urgency varies by regulatory environment and supply chain complexity, but it is not sector-specific. Organizations in regulated industries—pharmaceuticals, defense, financial services—face higher sanctions and export control exposure and therefore move faster on screening discipline. But concentration risk and sub-tier dependency blindness are equally acute in manufacturing, technology, logistics, and consumer goods. An automotive supplier may depend on a specialized electronics manufacturer in a single geography; a food company may rely on a single packaging vendor with one production facility; a tech company may source a critical component from a vendor whose own supply chain is entirely opaque. The difference is not risk severity—all are high—but visibility. Defense and pharma organizations tend to have more mature screening and sanctions disciplines because regulatory oversight is explicit and violations carry material penalties. Other sectors often discover their exposure only after a disruption or acquisition due diligence process reveals gaps. That gap is widening: geopolitical volatility, sanctions regime expansion, and supply chain complexity are all increasing, which means that the cost of staying unmapped is rising faster than most organizations realize.

Where to start

  1. Audit your current vendor data: how recent is it, how many tiers deep can you see, and what percentage of your supplier population has been assessed for regulatory compliance and sanctions exposure in the last 12 months?
  2. Identify your critical vendors—the ones whose failure would materially disrupt operations—and trace their supply chains back two tiers to see what dependencies and concentration points emerge.
  3. Establish a rescreening cadence for regulatory and sanctions exposure, even if it's quarterly to start, rather than one-time onboarding checks.

Ask Kepler how to map your full supplier ecosystem and close the visibility gaps in your supply chain risk profile.

Start free with Ask Kepler →

Advanced and emerging approaches

Geopolitical & Sanctions Risk Mapping for Vendor Networks

Map geopolitical and sanctions exposure across your vendor network to identify indirect contamination risks, secondary sanctions exposure, and regulatory shifts that could render suppliers non-compliant.

Supplier Ecosystem Mapping & Tiering

Construct a three-dimensional map of direct and indirect suppliers categorized by criticality and dependency depth to reveal hidden concentrations and single points of failure.

Vendor Concentration & Single-Point-of-Failure Network Analysis

Analyze interdependencies across your vendor ecosystem to identify where multiple vendors rely on the same sub-tier suppliers or critical resources, creating vulnerability clusters.

Vendor Supply Chain Transparency & Subcontractor Risk Mapping

Systematically identify and assess the full network of subcontractors and sub-suppliers beneath direct vendors to surface concentration risk, geopolitical exposure, and business continuity vulnerabilities.

Advanced & Emerging Practices

Emerging practices are included with Ask Kepler Pro and Max.

Unlock these practices →