Loading…

Guest blog: Why supplier concentration risk needs a sector-wide view

Adam Butler, Financial Services Lead at Risk Ledger Ltd explores third-party risk and the need to understand how supply chains intersect cross-sector.

https://www.riskledger.com/Every building society reading this will have a supplier risk register. Most will have tightened it further over the past two years, in step with the Bank of England, PRA and FCA's operational resilience rules. That work matters, and it shows. But it is also, on its own, no longer enough.

The reason is not that individual due diligence has got worse. It is that the picture any one organisation can build of its own supply chain, however rigorous, is incomplete, as it stops at direct contractual relationships. And in a sector like ours, where a relatively small number of core banking platforms, payment processors and cloud providers sit underneath a large proportion of building societies, and crucially their critical suppliers, what matters most to the sector as a whole is often invisible to any single firm acting in isolation.
 
Why direct supplier oversight is no longer enough

Risk Ledger's 2026 State of Supply Chain Security report, based on a survey of 500 UK risk and security professionals, puts some numbers against a feeling many of us already had. 82.4% of respondents had experienced at least one supply chain cyber incident in the past year. Consequently, 86% still rank supply chain risk among their top three concerns, yet only 38% can complete security due diligence on a new supplier within two weeks, and only 6% could map their full exposure across their extended supplier ecosystem within four hours of a major incident. Most would need a day or more, and almost a quarter said it would take over a week and require manually contacting suppliers one by one. Crucially for the argument of this article, 69.2% of respondents reported insufficient visibility into their extended supply chain dependencies beyond their direct third parties.

None of that is a criticism of the people doing the work. It is a description of a model, traditional third-party risk management, that was built for a world where each supplier relationship could be assessed on its own terms. That world has gone. Today's dependencies run four, five, six tiers deep, and they cluster in ways that only become visible when organisations compare notes.
 
Why shared infrastructure creates shared risk

This is also where building societies have a specific and under-discussed exposure. Mutuals have long shared infrastructure by necessity, from core banking systems to industry utilities, in a way that larger banks with more bespoke technology stacks sometimes haven't. That shared infrastructure has real benefits: it keeps costs down and lets smaller societies access capability they couldn't build alone.

But it also means that a single compromised supplier several tiers down could plausibly disrupt member services at a dozen societies simultaneously through these shared suppliers, not because any one of them was careless, but because none of them could see how their supply chains overlapped with their peers'.
 
Regulation is moving towards a sector-wide view

Regulators are beginning to think in exactly these terms. The Bank of England, PRA and FCA's operational resilience rules already require building societies to identify their important business services and demonstrate they can stay within impact tolerances during severe disruption, including disruption that starts with a supplier.

The newly finalised third-party reporting rules go further still: firms will need to submit standardised registers of material third-party arrangements by March 2027, feeding directly into the Critical Third Parties regime, which gives the PRA and FCA direct oversight of the suppliers judged most systemically important to the sector.

The logic connecting all of this is the same: regulators want to assemble a sector-wide map of who depends on whom, so they can spot systemic concentration risk before it becomes a crisis rather than after. Firm-level assurance is being treated as necessary but insufficient. Sector-level visibility is becoming the expectation.

That leaves risk and resilience teams at building societies with a genuinely useful question to sit with, separate from whatever tools or processes they currently use: if a critical supplier several tiers down were compromised tomorrow, would we know, within hours rather than days, which of our services depend on it, and whether other societies are exposed to the same failure point?

For most organisations, based on the survey data above, the honest answer is not yet. Getting to “yes” doesn't require abandoning the due diligence work already done. It requires supplementing it with something individual assessment can't provide: a shared, standardised view of dependencies that lets peer organisations compare their supply chain maps and see where they cluster. Risk Ledger's own experience running such communities for public sector and financial services organisations shows what this can surface.

In one financial services community of 30 UK firms, mapping direct suppliers alone surfaced over 6,500 further dependencies at the fourth tier and beyond, and identified 727 potential concentration risks at the third-party level, 288 of them critical, meaning an incident at that supplier could plausibly disrupt several institutions at once.
 
Managing shared risk 

None of this is an argument for a particular tool or vendor. It is an argument for a shift in mindset: from “have we assessed our suppliers” to “do we understand how our supply chain intersects with everyone else's”. For a sector built on mutual support, that shift should feel less like a burden and more like familiar territory. The building society movement has always understood that shared risk is best managed together. Supply chain security may be the next place that principle needs to be applied.

Data referenced above is drawn from Risk Ledger's "Every Link Matters: The State of Supply Chain Security 2026" report. Read the full report at riskledger.com/promoted/every-link-matters-2026-report.
 

You may also be interested in...

BSA Card
  • BSA.Event Event
  • Audit & Taxation

Audit and Accounting Seminar

After another successful event in 2025, and responding to delegate feedback, this year's annual update will take place in London. The full-day e...

BSA Card
  • BSA.Event Event
  • Mortgages & Housing

Annual Meet-up for Mortgage Professionals

Join us for the BSA's Annual Mortgage Meet-up, bringing together mortgage professionals from across the sector for a day of insight, discussion and ne...

BSA Card
  • BSA.IndustryPublication Research & Reports
  • Audit & Taxation

Audit for growth: Proportionality in audit and reporting

A joint update from the Association of Financial Mutuals and the Building Societies Association

BSA Card
  • BSA.PressRelease Press Release
  • Savings

Young workers face £300 shortfall as money worries hit work

New research by the Building Societies Association for UK Savings Week reveals the financial pressure facing young working adults and suggests that re...

BSA Card
  • BSA.IndustryResponse Industry Response
  • Audit & Taxation

BSA responds to HMRC consultation on tackling lower value tax debts

While the BSA supports the objective of improving debt recovery and reducing the tax gap, the response highlights significant concerns regarding the o...