For many years, supply chain resilience was discussed primarily in the context of disruption events. A natural disaster, a geopolitical shift or a supplier failure would trigger temporary concern before attention moved elsewhere.
That pattern has changed. Disruption is no longer episodic. It has become a constant operating condition for modern supply chains. That gap between assumed assurance and actual oversight is one of the defining findings of the Achilles Annual Risk and Sustainability Report 2026.
Drawing on responses from 2,805 organisations across construction, energy, industrial manufacturing, financial services and a broad range of other sectors, the research offers one of the most detailed pictures available of how procurement and risk functions are managing supplier complexity in the current environment.
What it reveals should prompt serious reflection among anyone responsible for supply chain governance.
The scale of what we do not know
Start with visibility. Only 6.2 percent of respondents in this year’s survey reported full visibility into their tier-two and tier-three supplier relationships. Nearly half reported limited or no visibility at all.
In industries where a single subcontractor failure can halt a major project, compromise a compliance audit or trigger reputational damage, this is not a minor operational gap. It is a structural vulnerability.
The problem compounds when you consider verification. 40 percent of respondents said that audit-based verification of supplier data is conducted rarely. Nearly 18 percent said they do not conduct it at all. Fewer than one in five expressed strong confidence in the accuracy of supplier-reported safety information, and more than 75 percent acknowledged that inconsistent national regulations across the jurisdictions they operate in have at least some impact on their ability to maintain consistent supplier standards.
Taken together, these figures describe an assurance environment that, for many organisations, is considerably more fragile than it appears from the inside.
A shift in what is driving action
For much of the past decade, the sustainability agenda in procurement was shaped primarily by values and reputation.
Reducing carbon emissions, attracting environmentally conscious customers and demonstrating corporate responsibility: these were the motivations most frequently cited by organisations building out their sustainability strategies.
That picture has changed. In the 2026 survey, legislation and regulatory pressure emerged as the single most cited driver of sustainability strategy, reported by 21.3 percent of respondents, up from 14.2 percent the previous year. It now sits above both environmental commitment and customer expectation as the primary force shaping organisational priorities.
This shift has practical consequences for how procurement functions are structured, resourced and measured.
Sustainability due diligence is no longer primarily a brand exercise. It is increasingly a legal obligation, one that requires ongoing supplier monitoring, evidenced compliance and the ability to demonstrate traceability across supply chains that may span dozens of countries and hundreds of sub-tier relationships.
Periodic questionnaires and annual reviews were not designed to meet that standard. In many cases, they are no longer adequate.
Disruption has become structural, not exceptional
One of the more sobering findings in this year’s data concerns how organisations now experience supplier-related disruption.
Financial failure or distress at a supplier, and quality or performance failures, were each cited as the most common form of disruption by approximately 31 percent of respondents. Labour shortages, extreme weather events and workforce issues also featured prominently.
What has shifted is not the nature of these challenges, but their frequency. For a growing proportion of organisations, disruption is no longer an occasional crisis requiring an exceptional response. It is a recurring feature of supplier management, one that has to be anticipated and absorbed as a matter of operational routine.
The financial stakes attached to that reality vary significantly by sector. In pharmaceuticals, one in four respondents reported that their most significant disruption event carried a cost exceeding ten million dollars. In financial services and real estate, losses in the one-to-ten-million-dollar range were reported by a meaningful segment of respondents.
These are not worst-case projections. They represent the actual financial impact of supplier failures in organisations that believed their risk exposure was being managed.
The consistent differentiator, across sectors and organisation sizes, is the quality of oversight in place before the disruption occurred. Organisations with structured, data-driven monitoring frameworks were better positioned to identify warning signals early and contain the impact before it escalated. Those dependent on manual processes or periodic reviews were not.
The technology divide is widening
The survey reveals a procurement landscape that is increasingly divided along technological lines. Nearly 58 percent of respondents currently manage supplier risk without any dedicated software platform. Around 23 percent rely on internally developed systems, and only 19 percent use established third-party platforms.
The maturity gap between these groups is significant and measurable. Among organisations using third-party supplier risk management platforms, 95 percent reported having a formal sustainability strategy in place. Among those with no dedicated software, that figure was 57 percent. The same pattern holds for AI readiness, confidence in compliance monitoring and the frequency of supplier audits.
This is not an argument that technology investment alone solves the supplier risk problem. It does not, but it does reflect a broader truth about governance maturity: organisations that have committed to structured, platform-enabled oversight of their supplier networks are operating with clearer data, stronger accountability mechanisms and greater confidence in their ability to meet rising regulatory expectations.
Those who have not made that transition are managing increasing complexity with tools that were not designed for the current environment.
What AI can and cannot fix
Interest in artificial intelligence across procurement and supplier risk functions is genuine and growing. More than 44 percent of respondents expressed positive views about AI’s potential.
The most cited perceived benefits are process efficiency, reduced administrative burden and better decision-making from data. However, actual deployment remains limited. Only two percent of organisations report AI that is widely integrated across procurement and supplier risk management. Nearly 39 percent are still at the exploration stage, with no live pilots underway.
The primary constraint is not technology availability or organisational appetite. It is data quality. Where supplier information is held across fragmented systems, regional spreadsheets and disconnected platforms, the structured inputs that AI requires to generate reliable outputs simply do not exist.
The readiness for AI-enabled risk management is, in practice, inseparable from the quality of the supplier data governance that supports it.
For organisations that have invested in clean, consistent, well-maintained supplier data, the path to more sophisticated analytical capability is relatively clear. For those who have not, each new technological opportunity remains dependent on resolving the same foundational problem.
What the data is asking of procurement leaders
The Achilles Annual Risk and Sustainability Report 2026 presents a picture of an industry that is being asked to do significantly more, with greater accountability and under greater scrutiny, than the processes and platforms in place were originally designed to support.
Procurement leaders are not short of awareness. Survey participation increased by 70 percent this year, a signal that supplier risk, sustainability governance and due diligence are being taken seriously at senior levels.
The challenge is translating that awareness into operational capability: the ability to monitor suppliers continuously, verify compliance systematically, identify emerging risk before it escalates and demonstrate evidenced oversight to regulators, investors and boards.
For procurement leaders looking to benchmark their current approach and understand how peers across industries are navigating these challenges, the full report offers detailed insights and practical data points.
You can access and download the report here to explore the findings in greater depth and assess what they mean for your organisation’s next phase of supply chain governance.
The organisations investing now in structured supplier data, scalable governance frameworks and platform-enabled oversight are building a resilience advantage that will compound over time.
Those deferring that investment are accumulating exposure at a rate that is becoming increasingly difficult to manage through manual effort alone.
That gap is already visible in this year’s data, and it is likely to widen considerably over the next two to three years as regulatory obligations intensify and expectations around supply chain transparency continue to rise.
Partial assurance was never a sustainable position. In the current regulatory and operational environment, it is no longer a defensible one.
Note: this article is part of a paid sponsorship between Achilles and PASA


