Survey findings
2. Extended supply chain oversight
This section assesses the maturity of the organisation’s supply‑chain risk management in practice. Specifically, whether it has end‑to‑end visibility into critical supply chains (including deeper tiers), uses near real‑time data to detect disruptions and trigger alerts, quantifies potential supplier failure impacts in enterprise risk metrics, and routinely runs multi‑horizon stress/scenario analyses. It also probes whether these insights are actually embedded in decision‑making, particularly in supplier negotiations, contracting, and ongoing relationship management.
Key takeaway:
Supply chain visibility and scenario analysis are improving, but remain largely limited to tier-1 suppliers and manual monitoring.
Nearly 40% of respondents report that their “full visibility” extends only to direct (tier‑1) suppliers, indicating that end‑to‑end transparency across supply chains remains limited for a substantial share of organisations. At the same time, around one‑third say they also have visibility into tier‑2 and tier‑3 suppliers for critical supply chains. This suggests a meaningful, but not yet predominant, level of deeper‑tier mapping and monitoring capability.
To what extent does your organisation have automated end-to-end visibility, including tier 2 and 3 where applicable, of pre-identified critical supply chains with near-real-time chokepoint detection?
In a structured way through dedicated tools, including tier-2 and tier-3 suppliers
Only on critical supply chains, including tier-2 and tire-3 suppliers
Only on direct suppliers
No end-to-end visibility on supply chains
Source: Marsh
Manual monitoring remains the dominant approach, with 57% of respondents relying primarily on human-led review of alerts rather than system-driven escalation. That said, around one-third report more integrated and automated models — either deployed broadly across most suppliers or targeted to critical supply chains — indicating a growing shift toward near real-time detection and trigger-based workflows.
To what extent do supplier risk processes incorporate live or near real-time data feeds that automatically trigger risk alerts?
Integrated and automated, covering most of the supply chain
Integrated and automated on critical supply chain
Manual monitoring
No monitoring
Source: Marsh
Amid continuous global supply chain issues, the results suggest that while automation is gaining traction, most organisations have yet to scale mapping, monitoring, and alerting across tiers, leaving timely identification of disruptions dependent on manual effort and inconsistent follow-through.
Manual monitoring remains the dominant approach, with 57% of respondents relying primarily on human-led review of alerts rather than system-driven escalation.
To what extent does your organisation run stress or scenario analyses for critical supply chains across defined horizons (short, medium, long) and multiple stressors (logistics, geopolitics, cyber, climate)?
Multiple scenarios and stressors both in the short and medium-long term
On a single scenario in the short and medium-long term
On a single scenario in the short term
No stress or scenario analysis
Source: Marsh
Qualitative assessments of supplier-related risks remain the most common approach (48%). However, a meaningful share of respondents (41%) report using quantitative methods, split between probabilistic (18%) and deterministic (23%) approaches. In most cases, these analyses focus on a single risk scenario and a short-term horizon. Only 25% of respondents undertake multi-risk scenario analysis across both the short term and the medium-to-long term. All of this applies predominantly to tier-1 suppliers.
To what extent is supplier failure exposure quantified and incorporated into enterprise‑level risk metrics (e.g., expected loss, contingency capital)?
Quantitative — both probabilistic and deterministic models
Quantitative — deterministic
Qualitative
No evaluation
Source: Marsh
This reliance on qualitative, single-risk, short-term assessments can limit the actionability of the outputs for supplier negotiation and relationship management. Integration into procurement processes is not yet systematic: 51% of respondents say risk and scenario insights are used for critical suppliers in key procurement categories. Overall, the findings point out the opportunity to strengthen the consistent use of risk analytics in vendor decision-making.
Are supply chain risk and scenario outputs used in supplier negotiations and relationship management?
Across main supplier categories
On all critical suppliers
Only on critical suppliers on selected categories
No
Source: Marsh
Case study: Strengthening supplier resilience in water utilities

A mid-sized European water utilities company identified a critical supply chain vulnerability in its dependence on single suppliers for essential treatment chemicals. With limited market intelligence and no structured contingency planning, the procurement team lacked a clear way to identify alternatives or assess supplier risk consistently.
Through a supplier-risk intelligence solution, the company prioritised the most exposed categories, mapped viable alternative suppliers across geographies, and introduced a more systematic vendor due diligence framework. This replaced informal selection practices with a consistent evaluation of supplier capability, compliance, financial health, and operational risk.
The result was a more resilient sourcing model for critical inputs, with documented alternatives that could be activated more quickly in the event of disruption. The exercise also broadened internal attention from procurement efficiency to wider supply chain resilience and governance.