Skip to main content


      Navigate the new realities of third-party risk management

      The landscape of third-party risk is evolving rapidly, with regulatory compliance and cyber risk now the primary drivers shaping TPRM strategies across the globe. As organisations face an unprecedented pace of change and increasing threats, the 2026 KPMG Global Third-Party Risk Management (TPRM) Survey explores how leaders are responding to these challenges — and where critical gaps remain.

      This is not the time for incremental improvements or fragmented approaches. Our latest survey of 851 organisations reveals that while many are making progress, true integration and effectiveness in TPRM remain elusive for most. The findings highlight both the advances, and the persistent hurdles organisations face as they strive for resilience and confidence in their third-party ecosystems



      Discover how organisations are reshaping TPRM

      Explore the 2026 KPMG Global Third-Party Risk Management Survey now to see how leading organisations are reshaping third-party risk management, by:

      • tackling regulatory compliance and cyber threats 
      • navigating increasingly complex third‑party ecosystems
      • using AI and managed services to strengthen resilience.
      Download

      Achieving resilience in third-party risk management

      2026 global third-party risk management survey


      Key findings from the survey

      looks_one

      Compliance and cybersecurity: Twin pillars of TPRM strategy

      Regulatory compliance and cyber threats are the most pressing priorities today, but they also highlight a gap: programs need capabilities that anticipate emerging risks so they can act before the next wave hits.

      looks_two

      Integration challenges: TPRM and ERM still speak different languages

      With only 53 percent of TPRM programs "mostly integrated" with enterprise risk management (ERM) — and just 18 percent "fully integrated"- there is a significant opportunity to create an enterprise-wide view of risk.

      looks_3

      Managed services and outsourcing: Scaling TPRM with external support

      Truly scalable, strategic TPRM operating models are an emerging trend: Many organisations are outsourcing discrete, high-volume tasks, creating a path toward end-to-end managed services, which are in place in just 5 percent of organisations.

      looks_4

      Technology and AI: Unlocking TPRM maturity and creating value

      More than half of organisations are exploring artificial intelligence (Al), and with 22 percent finding it "very effective," there is a clear opportunity to better translate technology investments into tangible value.

      looks_5

      Data quality and confidence: The foundation of trustworthy TPRM

      As only 15 percent of leaders express high confidence in the data that underpins their program, improving data quality presents a foundational opportunity to enhance TPRM effectiveness from the ground up.

      download

      Explore the 2026 KPMG Global Third-Party Risk Management Survey now. 


      High-quality data is foundational to effective Third Party Risk Management. It underpins the monitoring of control effectiveness, enables leading risk indicators, and demonstrates the value delivered through TPRM. Yet, our latest global survey shows that 17% of leaders lack confidence in their data quality, highlighting a significant opportunity to strengthen capability. By investing in better third-party risk data, organisations can enhance resilience through more timely, relevant insights that support stronger, more informed decision-making.
      Gavin Rosettenstein

      Partner, Third Party Risk Management Lead

      KPMG Australia


      Strategic recommendations to future-proof your TPRM program

      By following these actions, organisations can reposition TPRM from a cost center to a strategic enabler that drives efficiency, effectiveness, and competitive advantage.

      • Focus your firepower

        Pivot from broad, low value screening to a targeted, risk based approach — focus time and investment on the small subset of third parties that present material threats.

      • Break down the silos

        Align TPRM with enterprise risk management (ERM) to establish a unified, organisation‑wide risk view that informs strategic choices beyond compliance obligations.

      • Treat data as a strategic asset

        Implement robust data governance to build a single source of truth that powers effective AI, reliable reporting, and confident decision‑making.

      • Move past “AI theater”

        Embed automation and intelligent workflows across the full TPRM lifecycle to speed execution and surface hidden risks.

      • Look beyond your own backyard

        Expand visibility into Nth‑party relationships to identify deeper supply chain exposures and manage concentration risk.

      • Outsource outcomes, not ownership

        Use managed services to scale capabilities and improve efficiency, while keeping strong ownership of governance and strategic direction.



      Download the survey

      Download

      Achieving resilience in third-party risk management

      2026 global third-party risk management survey


      Contact us

      Gavin Rosettenstein

      Partner, Third Party Risk Management

      KPMG Australia