Context
Procurement's responsibilities for third-party risk management in indirect categories have grown more rapidly than the training and support available to meet them. Two recent CASME roundtables, one in North America and one in EMEA, brought members together to compare how their teams are executing TPRM in practice, what is working with limited resources, and where the pressure points sit.
The discussions covered practical execution, always-on monitoring, the balance between Procurement and specialist teams, and the tools members are using or considering. The points below are a short summary; the full reports are available to members in the CASME Resource Centre.
What most often undermines TPRM in practice
When asked what most gets in the way of practical execution, two-thirds of North America participants pointed to a lack of clarity on what "acceptable risk" means inside their organisation. The same proportion said the tools and data exist, but do not translate into clear insights or decisions. Half cited too many risks to cover for the time available.
Members described the difficulty of applying standardised assessment types to suppliers whose operational realities differ, and of communicating complex risk information to stakeholders in a way that supports decision-making. When indicators point to heightened supplier risk, participants reported that the most common outcome is case-by-case management rather than a consistent, defined response.
Reframing risk activity in cost terms
Both discussions returned to a shared theme: procurement teams are increasingly being asked to justify risk management activity in cost terms, particularly when cost control or savings is the dominant business objective. The approaches members described include:
- Scenario planning to demonstrate the potential impact of supplier risk on revenue, business continuity or customer commitments
- Quantifying the financial implications of compliance failures and cyber security incidents
- Using examples of geopolitical disruption, tariff exposure or market instability when discussing resilience investment
- Monitoring regulatory requirements ahead of implementation deadlines to avoid retrospective spend
Across both discussions, risk mitigation was described as more usefully positioned as value-adding rather than compliance hygiene, particularly when internal budgets are under scrutiny.
Practices delivering the most impact for the least effort
When asked what the single most effective action is for staying on top of TPRM, supplier segmentation by criticality and business impact came through most strongly across both roundtables. Members described:
- Segmenting suppliers according to materiality, business criticality and risk exposure to allocate resources where they are most needed.
- Applying tiered classifications so that due diligence is proportionate rather than blanket.
- Prioritising the assessment of suppliers who handle sensitive data, confidential information or critical business systems.
- Establishing contractual flow-down requirements for subcontractors and fourth-party providers
- Using red, amber and green dashboards to keep supplier risk status and remediation progress visible
Members with only an hour a week to spend on TPRM described concentrating that time on direct conversations with critical suppliers, reviewing exception reports, and engaging category managers on their supplier performance responsibilities.
Where small teams are finding capacity
The EMEA discussion returned to a practical question: where do teams with limited headcount find room to do TPRM well? Two approaches came through:
- Auditing ticket and tracker data to identify where TPRM workload is concentrated and using that evidence to make the internal case for automation and resource.
- Applying robotic process automation and AI to monitor operational processes, providing real-time information and flagging potential risk before it escalates
Members also discussed how AI is being used for contract reviews and to monitor category-specific developments, and how internal dashboards consolidate risk indicators from multiple monitoring sources into a single management view.
Ongoing topics
Both discussions closed with areas members expect to return to in future sessions: integrated approaches for consolidating supplier risk information from multiple monitoring sources, monitoring and managing fourth-party provider risk, and the application of AI within TPRM programmes.
About these discussions
The North America roundtable was held on 2 June 2026. The EMEA roundtable was held on 30 June 2026. Both are part of CASME's peer-only member community, where procurement practitioners share practical experience and benchmark approaches in a supplier-free, sponsor-free environment.
Back to News