Clean Supplier Data Is the First Line of Defense

August 18, 2026
Sue Doerfler 3.jpg
By Sue Doerfler
000000000001 data.jpg

The foundation of any supplier risk program is the right data. Many organizations, however, falsely assume they have accurate data in place, says Luis Grisales, senior vice president of supplier risk solutions at enterprise risk solutions provider apexanalytix.

“Without that data, if you begin a risk program, you’re not doing your job — because you’re not focused on what really is the risk,” he says.

Being proactive in data management can facilitate up-to-date visibility into supplier risk and protect the organization.  

Staying On Top of Risk Assessments

Most organizations, when they onboard a supplier, conduct a risk assessment. “But then throughout the life of that supplier, things change,” Grisales says.

For example, the supplier might have moved to a new region, he says: “Let’s say you engaged with that vendor in the U.S., but now it’s providing services in the European Union and is subject to the Digital Operational Resilience Act (DORA). Are you ensuring that that vendor is going through the right regulatory requirements?”

Perhaps to be more competitive, a small or midsized supplier invested heavily in advanced technologies like AI and was impacted financially because it took on too much debt.

“There are a lot of things that can happen,” Grisales says. “And if you are not applying ongoing monitoring to that supplier, then you’re not understanding the risk and you’re not protecting your organization. (And) if you do not have information filtering in from your suppliers on the critical risk subjects that your organization cares about, that’s a huge gap in your program.”

All too often, companies don’t devote adequate resources or time to this process, he says: Having data isn’t enough; it must be curated.

Recent apexanalytix research about procurement organizations found that:

  • Most (87 percent) don’t continuously validate or synchronize data in real time. They manually make updates, which are often inconsistent, “meaning most risk decisions are made on data that is already out of date by the time it is used,” the research report states.
  • Supply data updates are often incomplete or informal, as 87 percent rely on supplier self-reporting or ad-hoc updates. The report states, “For the large majority, critical supplier change surfaces through informal channels, not through proactive detection.”
  • Nearly half (47 percent) don’t have a consistent strategy for deciding which risks to monitor for a given supplier.

Platforms, AI and Sub-Tier Suppliers

Organizations might not analyze supplier and third-party data in a way that ensures the business is protected.

“Companies should be looking at their vendor data in a variety of platforms and systems,” because they may have different attributes, Grisales says. “Anyone in a supplier risk management role should take a look under the hood and see what type of data they have,” he says. “You’re going to notice that at least 30 percent to 40 percent of your data is inconsistent or lacking information.”

Use of AI is another factor organizations should continually monitor. A supplier shifting to AI infrastructure could impact the product or the service it provides, Grisales says.

Ask such questions as: How is the supplier leveraging AI? What is it building with AI? How does this change things financially? Is our relationship going to change? Will AI change the supplier’s capabilities or capacity?

Visibility — having ongoing data about your suppliers’ suppliers — is key to risk programs. “But it’s very hard to get that information,” Grisales says. “That’s a huge, huge gap right now in most organizations, and everybody’s trying to solve for that.”

A variety of third-party solutions can help companies improve their visibility into their suppliers and their suppliers’ suppliers by validating data and ensuring compliance with regulations.

Avoid Being Reactive

Data protection is also crucial. Organizations have to build guardrails to ensure their data remains clean, Grisales says. Question who has access to the data and if this could impact the data.

“Most organizations are reactive,” he says. “They receive risk alerts, whether it’s about the data itself or just risk in general.” They could get an email from a vendor saying one of their suppliers had a data breach — and this is the first the organization has heard of it, he adds: “You may not be monitoring or you’re getting so many alerts, it didn’t even get to you.”

A vendor could have changed its payment instructions or its remittance address. “We find out through invoices,” Grisales says. “We find out through many different avenues, but not the correct ones. You need to be able to have that information.”

Among his recommendations:

Be proactive. “Reach out to your vendors and give them the way to make sure they’re looking at their vendor data and keeping it up to date,” he says.

Ensure continuous monitoring. “Make sure that there’s automation to inform not just the risk team, but also all the stakeholders in the process,” he says.

Understand your organization’s plan. Ask where you are starting from, Grisales says. Do you have clean data or not?” If you don’t have clean data, then make that your priority — especially a budget priority: “Don’t ask for tools. Don’t ask for anything else,” he says. “Your manager and the leadership team approving the budget item is going to appreciate that you’re looking out for the company from a data perspective and not focusing on bringing in additional tools that are just going to sit on the shelf.”

He adds that when building a supplier risk program, make sure it will work for your end users. “Don’t complicate it. Don’t make it complex,” he says. “Do whatever is going to get the job done — but focus on making sure that you’re protecting the organization.”

(Image credit: Getty Images/Gopixa)

About the Author

Sue Doerfler

About the Author

As Senior Writer for Inside Supply Management® magazine, I cover topics, trends and issues relating to supply chain management.