Skip to content

Mind the tier gap: The real barriers to effective supplier management

Supplier management technology has matured considerably over the last decade. Organizations today have access to platforms capable of screening suppliers against sanctions and adverse media, automating onboarding, tracking corrective action plans, and monitoring risk across sprawling, multi-tier networks.

Yet many sustainability and procurement teams continue to face the same problem: risk visibility that is strong at tier one and degrades sharply the further it travels from the buying organization.

That is not primarily a tooling gap. It is a structural feature of what supplier management actually is.

A supplier isn’t just a data source, it’s a counterparty

Carbon management is fundamentally an internal coordination problem: the data exists somewhere inside the organization’s own systems, and the challenge is finding and reconciling it. Supplier management is a different kind of problem entirely. The data sits with an independent legal entity that has its own commercial incentives, its own competitive sensitivities, its own legal exposure, and its own limited capacity to respond to yet another questionnaire.

This changes the nature of the challenge. You cannot mandate an external supplier to disclose the way you can mandate an internal department to submit its numbers. A supplier weighing whether to disclose a subcontractor relationship, a labor practice, or a financial difficulty is making a judgment call about risk to their own business, not simply completing an administrative task.

The power dynamics cut in both directions. Large buyers can extract disclosure from small suppliers through commercial leverage, but the same small suppliers are often fielding a dozen overlapping questionnaires from a dozen different buyers, each slightly different, each demanding separate verification. Smaller buyers, meanwhile, often struggle to get large strategic suppliers to disclose anything beyond the minimum their contract requires. Visibility, in other words, is not just a function of effort. It is a function of relative leverage in the relationship.

This is the real reason tier one data is comparatively strong while tier two and tier three data is comparatively weak. It is not that organizations haven’t tried to map deeper. It is that leverage, incentive, and trust all thin out with distance from the direct relationship.

Regulation here doesn’t just expand, it swings

Most sustainability reporting regimes have moved in one direction: more disclosure, more frequently, to more stakeholders. Supplier due diligence regulation is unusual in that it genuinely swings.

The CSDDD initially pointed toward due diligence obligations reaching deep into the value chain. The Omnibus simplification proposals now point toward narrowing mandatory scope back to direct, tier one relationships, reducing monitoring frequency, and softening liability. Final positions were still being negotiated between Parliament, Council, and Commission as of this writing, so the exact landing point remains open.

This creates a genuinely distinct strategic question for supplier management that doesn’t have a clean equivalent in carbon reporting: should a due diligence program be sized to the legal minimum, which is cheaper to run but exposed to being rebuilt each time the regulation moves, or sized to commercial and reputational reality, which is steadier but may represent real spend on scope that regulation never ends up requiring?

There isn’t a universally correct answer. A company selling into public sector contracts or to large ESG-conscious retailers may find that customer expectations already exceed whatever CSDDD eventually requires, making the regulatory question close to moot. A company with thinner margins and less customer-driven pressure may reasonably choose to track the legal minimum closely and adjust as it firms up. The point is that this tradeoff is a live, program-design decision in supplier management in a way it generally isn’t in carbon accounting, where the direction of travel has been comparatively predictable.

The FLR doesn’t swing, and it isn’t waiting for CSDDD to settle

While CSDDD’s scope is being negotiated down, a separate piece of legislation is moving toward enforcement on a fixed date, largely outside this debate. The EU Forced Labour Regulation enters into full application on December 14, 2027, and unlike CSDDD, it carries no size or turnover threshold. Any company placing products on the EU market, or exporting from it, falls within scope regardless of headcount or revenue, which means a meaningful share of the mid-market companies that CSDDD and Omnibus negotiations may end up excluding will still have to answer to the FLR.

The mechanism is also different in kind, not just in coverage. CSDDD is a due diligence obligation: it asks companies to run a process and report on it. The FLR is a market access prohibition: it bans the sale of any product made with forced labor, anywhere in the supply chain, with no tier cutoff. Formally, the burden of proving a violation sits with the investigating authority, not the company. In practice, that distinction matters less than it sounds. Once an authority opens an investigation, a company that cannot document where its inputs came from and demonstrate the absence of forced labor has very little to rebut with, and non-cooperation with an investigation is itself held against the company.

A due diligence program that stops at tier one, which is where most supplier management programs are strongest today, does not reach far enough to build that evidence base. The regulation’s practical demand is closer to the reverse of the status quo: be able to show the absence of forced labor deep into the chain, or risk having the product withdrawn from the EU market until you can.

This changes the sequencing argument. Companies that have been waiting to see where CSDDD and Omnibus land before investing in multi-tier supplier visibility are optimizing for the wrong deadline.

The FLR arrives first for many of them, applies more broadly than CSDDD ever will, and does not forgive an unmapped supply chain just because the company sits below whatever size threshold the due diligence directive eventually settles on.

Tenders are already enforcing this, well ahead of any legal deadline

There is a second forcing function that has nothing to do with when a regulation takes effect, and sustainability teams are already living with it. Companies that fall outside CSDDD’s scope, and years before FLR enforcement begins, are increasingly finding due diligence requirements modeled on Germany’s LkSG or on CSDDD itself written directly into customer tenders and procurement contracts. A large buyer that is itself in scope of these regimes has every incentive to push the same expectations down onto suppliers who are not, simply to manage its own upstream exposure.

The practical effect is that legal scope and commercial scope have already decoupled. A mid-sized supplier with no direct regulatory obligation can lose access to a tender, or to a strategic account, for failing to produce the kind of supplier due diligence documentation that only applies to it by contract, not by law. This is a harder problem to plan around than a regulatory deadline, because it does not show up on a public timeline. It shows up unannounced in a request for proposal, and by the time it does, the company either has the documentation and the supply chain visibility to respond quickly, or it doesn’t and loses the account to a competitor who does.

Supplier risk is absorbing other risk disciplines, whether or not anyone planned it that way

Financial health screening, cyber risk assessment, sanctions and trade compliance, quality assurance, and ESG due diligence have historically lived in separate systems, run by separate teams, often assessing the same supplier without ever comparing notes. Procurement runs a credit check.

Compliance runs a sanctions screen. Sustainability runs an ESG questionnaire. Quality runs an audit. None of them talk to each other, and the supplier answers four different intake processes that overlap more than anyone on the buyer’s side realizes.

Due diligence obligations under CSDDD-style regulation are forcing a convergence that arguably should have happened anyway: a single supplier risk profile that treats human rights exposure, environmental risk, financial distress, and geopolitical exposure as facets of the same underlying question, rather than as separate compliance exercises.

A supplier’s financial distress is often the leading indicator of the labor and safety violations that show up in an ESG audit eighteen months later. Treating these as unrelated data streams means each function discovers the same underlying problem separately, and later, than they would if the signals were combined.

This is arguably the single biggest opportunity in supplier management that has no direct analog in carbon reporting: consolidating risk disciplines that were never architecturally separate for any good reason, just organizational history.

The audit calendar doesn’t match how supplier risk actually happens

Carbon reporting has a natural rhythm: an annual reporting period, a defined close, a disclosure date. Supplier risk does not respect that rhythm. A sanctions designation, a factory fire, an insolvency filing, or a forced labor allegation can happen on any day of the year, and by the time the next scheduled audit rolls around, the organization may have been carrying an undetected exposure for months.

An annual or biennial audit cycle, however well executed, is a point-in-time snapshot of a risk that is continuous. This mismatch, not the frequency of the audit itself, is the more consequential design problem. The question worth asking isn’t “how often should we audit,” but “which risk signals can we monitor continuously versus which genuinely require a scheduled, in-depth assessment.”

Sanctions and adverse media exposure can reasonably be monitored in near real time using independent external sources. Working conditions at a tier three facility generally cannot, and still require the human judgment of a site visit or a verified audit.

Independently verifiable data is more available here than it looks

Unlike emissions data, which in most cases genuinely only exists if the supplier or the buyer chooses to calculate and disclose it, a meaningful share of supplier risk information already exists independently of what the supplier chooses to say. Sanctions and denied-party lists, corporate registries, litigation and insolvency records, customs and shipping manifests, certification body databases, and adverse media are all third-party sources that can corroborate, or in some cases substitute for, self-reported supplier data.

This matters because it reduces dependence on the supplier’s willingness to disclose, which is precisely the constraint that makes supplier management harder than carbon accounting in the first place. A supplier can decline to answer a question about a subcontractor relationship. A customs record showing shipments from an undisclosed facility is harder to decline.

There is a second, less obvious advantage available in supplier data that isn’t really available in emissions data either: reuse across buyers. A supplier assessed once, to a recognized standard, can in principle serve that assessment to multiple buyers rather than repeating the same disclosure a dozen times.

Where this works, and it doesn’t always work cleanly across incompatible frameworks and buyer-specific requirements, it directly attacks the fatigue problem described earlier rather than just making each individual questionnaire faster to complete.

What this means for how supplier management programs should be built

Put together, these dynamics point toward a different set of priorities than a straightforward compliance build-out would suggest.

Depth should follow risk concentration, not a uniform tier cutoff. Blanket tier two or tier three mapping across an entire supplier base is rarely the best use of scarce due diligence capacity. In practice this means starting with a spend and category analysis, not a supplier-by-supplier questionnaire push, to identify where raw material extraction, high-labor-intensity manufacturing, or conflict-affected sourcing regions actually sit in the base.

Software has a clear role here: mapping tools that overlay category and geography data against known risk indices can do this triage in days rather than the months a manual review would take. But the judgment of where to draw the line, how much residual risk in a low-priority category is acceptable, belongs with procurement and sustainability leadership, not a default platform setting. A tool can rank risk; it shouldn’t be the one deciding the organization’s risk appetite.

Independent verification should do more of the work currently asked of self-reported questionnaires. Where a sanctions list, a corporate registry, or a customs record can answer a question, it should. Concretely, this means auditing the current questionnaire against what’s actually being asked: any question with a public-record answer is a candidate for automated corroboration rather than repeated self-disclosure.

This is a genuine software opportunity, since screening against registries and watchlists at scale is not something a team can do by hand. It’s worth noting what this doesn’t replace, though: working conditions at a facility, subcontracting practices, or the accuracy of a labor policy on paper versus in practice still require a site visit or a verified audit. Automating the parts that can be automated frees the limited human due diligence capacity for the parts that genuinely need it, rather than spreading that capacity thin across everything.

Continuous monitoring and scheduled deep assessment are different tools for different risk types, not two speeds of the same process. Sanctions designations, adverse media, and insolvency filings can and should be monitored continuously since the underlying data updates in near real time and software can flag changes automatically.

A factory’s working conditions cannot be continuously monitored in the same way, and treating an annual audit as if it were a monitoring system, or treating continuous alerts as if they covered what an audit would catch, both leave real gaps. The practical step is to explicitly split the risk register into what gets machine-monitored on an ongoing basis and what gets a scheduled human assessment, rather than defaulting to a single review cadence for every risk type.

Program scope should be built with the regulatory swing in mind, and against a fixed point that isn’t swinging. Before locking a program’s scope to whatever CSDDD and the Omnibus eventually settle on, map which parts of the current program are driven by legal minimum versus by customer, investor, or reputational expectations that exist independent of the law. The parts sized to customer and reputational reality are worth preserving regardless of where the regulation lands. The parts sized purely to a legal minimum that may move are the ones worth holding loosely, and revisiting once the text is final rather than over- or under-investing now.

The FLR deadline is the one part of this picture that isn’t moving. Regardless of how CSDDD’s scope and thresholds are ultimately negotiated, a program that can demonstrate supply chain visibility well beyond tier one by December 2027 is solving a problem that exists on a fixed date, not a moving one, and that work should not be shelved while waiting for the rest of the regulatory picture to settle.

Tender and procurement requirements deserve their own line item, separate from regulatory compliance. Because customer-driven due diligence requirements are already running ahead of legal thresholds for many companies, a program built only to satisfy current legal obligations will keep getting caught out by contract requirements it wasn’t designed to meet.

Treating supplier due diligence readiness as a commercial capability, not solely a compliance one, means the documentation and visibility built for one purpose can be reused to win or retain the next tender, rather than assembled from scratch under deadline pressure each time a customer asks.

Working on these challenges?

If any of this sounds familiar, you’re not alone. Sustainability and procurement teams across industries are managing supplier risk that spans financial, environmental, human rights, and geopolitical dimensions, often through separate systems that were never designed to inform one another, while the regulatory scope defining what’s mandatory continues to move, a hard deadline that doesn’t move approaches regardless, and customer tenders are already asking for more than the law does.

Position Green helps organizations bring these pieces together: risk that concentrates unevenly across tiers, regulation that moves in both directions alongside a deadline that doesn’t, and risk disciplines that belong together rather than apart.

Explore supplier management

Stay up to date with the latest ESG-trends.