- Home
- Research
- Supply chain
- Supplier monitoring: why 48% have an active risk
Supply chain Research ESGreen Research
Supplier monitoring: why 48% have an active risk
On this page
- Supply chain risk is bigger than it looks
- What the global market shows about this risk
- The scale of the problem, in practice
- What the risk alerts reveal
- Why this risk stays invisible to the contracting company
- From one-off monitoring to continuous monitoring
- The first step is knowing where you stand now
Every company outsources part of its own risk. Each supplier, service provider or business partner that enters your chain carries a history, and most companies have no way to track that history in a timely manner. Supplier monitoring exists precisely to close this gap, but in practice, few companies do it continuously.
The result is a blind spot that grows silently. And the numbers show the real size of that blind spot.
Supply chain risk is bigger than it looks Link para esta seção
The traditional way to assess a supplier is one-off. A qualification at the start of the contract, perhaps an annual document renewal, and after that, silence. The problem is that a supplier's risk is not static. A certificate can expire, a lawsuit can emerge, a company can land on a restrictive list months after being approved.
If your company only revisits that supplier at the next contract renewal, the time between a risk event and its discovery can stretch to months. That gap is where invisible risk lives: it does not disappear, it just stays out of your field of view.
What the global market shows about this risk Link para esta seção
This is not an isolated problem for one company or one sector. A recent global KPMG survey*, which heard from 851 organizations in the healthcare, technology, financial, industrial, retail and energy sectors, shows that one third of companies (33%) suffered financial loss or reputational damage in the last three years because of vulnerabilities linked to suppliers, partners or service providers. Twenty-eight percent (28%) faced direct disruptions to their own production because of supply chain problems.
In other words, this risk is no longer a theoretical concern. It has already materialized, financially and operationally, for a significant share of companies around the world, even among those that already invest in third-party management.
The scale of the problem, in practice Link para esta seção
To understand the real size of this gap in the Brazilian context, it helps to look at a broad monitoring base rather than at a single supplier. Today, more than 85,000 companies are continuously monitored in the ESGreen database, used by more than 60 financial institutions, cross-referencing more than 70 national and international public sources.
It is at this scale that the alert pattern becomes clear. And the pattern is larger than most companies expect.
What the risk alerts reveal Link para esta seção
~48% of monitored companies have at least 1 active alert Link para esta seção
Almost half of the entire supply chain analyzed currently carries some type of open risk. It is not the exception, it is almost the norm.
More than 240 alerts on national and international restrictive lists Link para esta seção
CEIS, CNEP, Ibama, TCU and CVM are some of the official Brazilian databases cross-referenced to identify companies with active restrictions, which often continue operating normally with their contracting parties without anyone having revisited that information.
More than 95 alerts on international sanctions lists Link para esta seção
OFAC, the United Kingdom, the European Union, Interpol and the UN are part of the screening, which matters especially for companies with operations or suppliers exposed to international trade.
More than 1,600 alerts from news and media Link para esta seção
Continuous screening of press sources captures events that would never reach a formal certificate but already signal reputational or operational risk.
Together, these numbers tell the same story from different angles: supplier risk is not rare, it is widespread, and it goes unseen only because the traditional way of monitoring was not designed to track changes all the time.
Why this risk stays invisible to the contracting company Link para esta seção
It is not a lack of care. It is a structural limitation. The information that makes up a supplier's real risk is scattered across dozens of different public sources, each with its own format, its own update frequency and no communication between them. Cross-referencing this manually, supplier by supplier, is unfeasible at any scale beyond a handful of contracts.
The practical effect is that most companies only discover a problem with a supplier when it has already become a problem for them, whether in a client audit, a credit renewal or a regulatory investigation.
From one-off monitoring to continuous monitoring Link para esta seção
The good news is that companies already doing any kind of supplier check, even a one-off one, have already started this process without realizing it. The difference between what is done today and continuous monitoring is not a change in philosophy, it is a change in frequency and coverage.
Continuous monitoring means the check does not happen once a year: it happens with a monthly recalculation and with every relevant new event, for the entire supplier base at once, not supplier by supplier on demand. It is the difference between taking a snapshot of risk and following a video as it unfolds.
ESGreen is an ESG data and climate intelligence infrastructure for credit cooperatives, banks, asset managers, insurers and corporations, built precisely to enable this kind of monitoring at scale, automatically and continuously cross-referencing CNPJs (Brazilian company registration numbers) against more than 70 public sources, already applied today to more than 85,000 monitored companies.
The first step is knowing where you stand now Link para esta seção
Before any decision on how to structure a monitoring process, it is worth answering a simple question: how many of your suppliers currently have an active alert that you have not seen yet?
If the answer is not immediate, your supply chain likely shows the same pattern found in the consolidated database: close to half of suppliers carrying some risk that has not reached you yet.
*Data sources: KPMG, 2026 Global Third-Party Risk Management Survey, 851 organizations surveyed in 2025 (market data); ESGreen consolidated monitoring database, 2025 (alerts); ESGreen client base (monitored companies and user financial institutions).
Frequently asked questions
Short answers to the most common questions.
Still have questions? Talk to an expert
What is supplier monitoring?
It is the process of continuously tracking the compliance, financial, legal and reputational risk of companies that are part of a business's supply chain, cross-referencing data from multiple public sources instead of relying only on a one-time qualification.
What is the difference between supplier qualification and continuous monitoring?
Qualification assesses a supplier at a specific moment, usually when the contract begins. Continuous monitoring repeats that assessment over time, with a monthly recalculation and with every relevant new event, capturing changes that arise after the initial approval.
Why should a company monitor its suppliers' risk?
Because a supplier's risk becomes, in practice, a risk for the contracting company itself, whether in client audits, credit renewals, regulatory requirements or reputational exposure. Continuous monitoring shortens the time between the emergence of a risk and its discovery.
