Skip to main content

Insights / Articles

Why Tier-2 and Tier-3 Suppliers Are Your Biggest Hidden Risk

Are your Tier-2 and Tier-3 suppliers a ticking time bomb? Learn how to identify emerging market risks before they cripple your business.

AT
Auras Tanase
2 days ago9 min read
Third-Party & Vendor RiskConcept Explainer
Key takeaways
  • 70% of organizations report poor data quality from their Tier 2 to Tier 4 suppliers.
  • Tier 1 suppliers withhold sub-supplier data to protect margins.
  • 26% of organizations don't assess fourth-party risk at all.

Most companies can name their direct suppliers easily.

Ask them who supplies those suppliers, and the answers can fade fast.

That blind spot is where the costliest disruptions hide, since Tier 2 and Tier 3 vendors sit outside your contracts and your view.

This article explains why sub-tier visibility breaks down, and how better company data helps procurement and risk management teams see the dependencies that matter.

Why Sub-Tier Supplier Visibility Fails

Nobody decides to lose track of their supply chain.

The lack of visibility is created through many factors, all leading to key component and material manufacturers becoming more difficult to track or completely unknown to you.

Each of the reasons we cover next plays a big part in creating that visibility gap.

No Direct Contracts, No Data

The straightforward reason sub-tier visibility fails is a lack of data.

In fact, companies rarely have direct contact or a working relationship with their Tier 2 or Tier 3 vendors.

Those relationships are mediated by Tier 1 suppliers, who sit between you and everyone further upstream.

So any information you get about the lower tiers reaches you secondhand, filtered through a company with its own commercial interests.

Sime Curkovic, a professor of supply chain management, describes this arrangement as a real problem, as quoted by IndustryStar.

Curkovic quote

Illustration: Veridion / Quote: Medium

His point becomes clearer once you examine what rights supplier contracts and due diligence give you.

With a direct supplier, you have the right to request documents, inspect a facility, and hold the vendor to the terms they agreed to in writing.

Those rights exist because a supplier signed something, which is lacking with a Tier 2 or 3 supplier.

Consider the standard checks a buyer runs on a Tier 1 supplier before and during the relationship.

Tier 1 supplier due diligence measures, including risk assessments, data requests, code of conduct enforcement, audits, contracts, and financial health reviews

Source: Veridion

These practices are usually done during sourcing and onboarding, and they give a buyer reasonable confidence in a direct supplier.

Once that’s established, the vendor gets approved, and a contract is signed.

The problem is that this confidence stops at that contract and never reaches the suppliers that your suppliers depend on.

The information you do receive tends to be thin as a result.

That’s supported by a Sphera survey, which asked 250 chief procurement and supply chain officers about how well they understand their lower tiers.

70% of organizations report data accuracy and quality issues from tier 2 to tier 4 suppliers statistic

Illustration: Veridion / Data: Sphera

With the majority of organizations reporting poor data quality across Tiers 2 to 4, every risk assessment built on that data inherits the same weakness.

What ends up happening is that organizations start making decisions and supplier risk management plans that rely on figures nobody has independently verified.

That can make a supplier look acceptable on paper while carrying problems nobody has yet discovered.

Tier 1 Disclosure Gaps

If your direct suppliers are the source of upstream data, the next question is why you can't fully trust what they share.

The issue is that Tier 1 suppliers frequently withhold information about their own suppliers, and the motives behind that vary more than most buyers assume.

Here are a few of the reasons behind these disclosure gaps.

Reasons tier 1 suppliers withhold data: competitive advantage, supplier NDAs, pricing leverage, and limited knowledge

Source: Veridion

Competitive advantage explains much of it.

Supplier relationships take years to build, and many manufacturers treat their sourcing network as an asset worth protecting from customers who might use it.

Concealing that network also keeps the cost structure hidden, which prevents buyers from calculating what a component costs to produce and negotiating the price down.

There is also the fear of disintermediation, which is the risk that a buyer contacts the supplier's source directly and removes the supplier from the transaction.

Sometimes the explanation is less strategic.

Tier 1 suppliers often withhold upstream information because they have no clear view of it themselves.

In fact, Deloitte and the Manufacturers Alliance found this when they interviewed supply chain executives about visibility across their networks.

The executives reported that any problems originating with a Tier 3 supplier would frequently remain invisible.

Deloitte quote

Illustration: Veridion / Data: Deloitte

This disconnect means that nobody in the chain identifies the problem until its effects surface downstream, by which point a delay or a shortage has already reached your production line.

The stakes rise when a sub-tier supplier operates unethically, since the resulting damage lands on your finances and your brand.

The Giorgio Armani case is a clear example of just that.

A company owned by Armani outsourced leather goods production to suppliers who subcontracted the work to Chinese-owned workshops that exploited their workers.

Reuters article screenshot about an Armani-owned company placed in receivership amid a labour exploitation investigation

Source: Reuters

While the brand said it was unaware of the extent of the issue, it was still placed under a one-year receivership over the labour practices in its supply chain, later paired with a regulatory fine.

Whether a supplier stays silent because of a competitive strategy or plain lack of visibility, the outcome is the same.

You inherit risks you never knew existed, and you find out about them at the worst possible moment.

Where Disruptions Actually Begin

These visibility gaps matter more once you realize that major supply chain disruptions often begin in the lower tiers.

Sometimes, a whole industry can feel diversified because it has several backup Tier 1 vendors, while a single sub-tier source or region supplies all of them.

The result is concentration risk, which is exposure to a single point of failure that your supplier list does not show.

Research from the European Central Bank measures how common this is.

Analyzing a database of roughly 12,300 euro area firms, the ECB found that most large European companies sit no more than three intermediaries away from a Chinese rare earth producer.

Over 80% of large European firms are within three intermediaries of a Chinese rare earth producer pie chart

Illustration: Veridion / Data: ECB

Volkswagen and Renault were closer still, separated by a single intermediary.

A large number of companies, therefore, depend on one region for critical raw materials, whether or not they have ever mapped that dependency.

And when that region imposes restrictions, the effects spread quickly.

That’s exactly what happened when China restricted rare earth exports, forcing some carmakers and suppliers to pause operations completely.

A single facility can produce the same effect.

When fire broke out at a Renesas semiconductor plant in Japan, the damage removed a supplier that a large number of automakers rely on.

Article screenshot about Japanese carmakers assessing the impact of the Renesas chip plant fire and production shutdown

Source: Nippon

The plant’s customers were mostly automotive parts makers rather than the carmakers themselves, placing it a tier away from the manufacturers whose lines eventually stopped.

The production disruption ultimately worsened an already severe chip shortage for automakers worldwide.

These are not simple problems to solve.

Dan Hearsch, a managing director in AlixPartners' automotive and industrial practice, notes that it’s increasingly difficult to stop a problem in one part of the world from affecting companies everywhere.

Hearsch quote

Illustration: Veridion / Data: AlixPartners

He adds that it matters more than ever for companies to work from solid information and analysis.

After all, a company that knows about a shared dependency can look for a second source before the first one fails.

Without that knowledge, a disruption four tiers deep becomes a surprise instead of a managed event.

Standard Tools Stop At Tier 1

Supplier information is needed more than ever, yet the tools and practices most teams rely on don't reach far enough.

Consider the standard supplier evaluation and risk-assessment flow.

Companies run it while sourcing a new vendor, and it operates strictly inside the direct vendor boundary.

Tier 1 supplier evaluation process from identification and data gathering to risk scoring, onboarding, and ongoing monitoring

Source: Veridion

Each step concentrates on the one company you are preparing to contract with.

A request goes out, a questionnaire follows, someone reviews the responses and scores the vendor, and the supplier gets approved.

Monitoring then continues for the life of the relationship, though it watches that same direct supplier and nobody behind them.

The design of risk management and evaluation platforms reinforces this.

Even leading tools like SAP Ariba Supplier Risk organize everything around a supplier record that someone created during onboarding, and that record exists because a contract exists.

SAP dashboard

Source: SAP

SAP describes the solution as calculating risk exposure based on your relationships, with due diligence based on your supplier engagement.

Each assessment attaches to an engagement with a named supplier, which is the level where a company holds a contract and can ask questions.

When it comes to platforms that do offer fourth-party visibility, they usually work by asking your direct vendor to name their critical suppliers, which returns you to the disclosure problem.

The result is a poor fourth-party vendor assessment.

Ncontracts found in its State of Third-Party Risk Management research that 26% of organizations perform no fourth-party risk assessment at all.

Fourth-party vendor review methods bar chart, led by 58% reviewing third-party risk programs and 26% not assessing fourth parties

Illustration: Veridion / Data: Ncontracts

Plus, the strategy for the majority of organizations is to simply assess their suppliers’ third-party risk management program.

Organizations know they hold no contractual relationship or leverage over a fourth party, so they check whether their vendor is performing adequate due diligence instead.

In other words, they still put trust in their direct suppliers and perform a fourth-party evaluation only indirectly.

That leaves the tiers where most disruptions start almost entirely unwatched.

Closing the Sub-Tier Visibility Gap

Closing this gap means changing where your data comes from.

Instead of waiting for Tier 1 suppliers to disclose their sources, you can try to surface those dependencies from broad, external company data.

Coverage replaces disclosure, and that is what makes hidden sub-tier risk visible.

Sayan Debroy, Head of Supplier Risk Intelligence at WNS Procurement, points to quality data as key to the effectiveness of your approach.

Debroy quote

Illustration: Veridion / Quote: Supply Chain Digital

Comprehensive intelligence reveals dependencies and early risk signals that no single supplier would provide on request.

The size and coverage of that data matter just as much, and here is where Veridion fits in.

Veridion's database tracks over 130 million companies across 500 million operating locations worldwide, with this data getting refreshed weekly.

Veridion dashboard

Source: Veridion

This coverage also includes the small and mid-sized businesses that standard databases tend to miss.

According to the World Bank Group, these firms make up about 90% of all businesses worldwide, and they are exactly the kind of hidden companies that sit at Tier 2 and Tier 3.

Many are digital-first, unregistered, or too small to file the records that traditional providers rely on.

Finding those companies leaves one question open, which is how they relate to one another.

Veridion's corporate family data answers it by connecting each company to its parent organization, which is what makes third and fourth-party risk assessment possible.

Veridion dashboard

Source: Veridion

However, sub-tier suppliers rarely appear the same way twice in your records.

The same factory might be registered under a legal name nobody uses, invoice under a brand alias, and turn up in a supplier disclosure under a third name entirely.

You end up with several records and no way to tell whether they describe three companies or one.

Veridion approaches this entity resolution issue with a dual-view model.

The Operating View captures a company's digital footprint, including its website and product mentions, while the Legal View then draws on official registries and filings.

Matching one against the other collapses scattered records into a single resolved company, and the corporate family data then connects that company to its parent.

That is how a shared upstream dependency, invisible on paper, finally shows up.

Conclusion

Sub-tier suppliers stay hidden because the data, the disclosure, and the tools all stop at Tier 1.

This article looked at why that happens and what it costs when disruptions start upstream.

The takeaway is that better visibility comes from broader, verified company data, not from waiting on your suppliers to volunteer it.

To see how deep your own supply chain really goes, start by closing the data gap.

Articles

Discuss how these trends affect your organization.

Our analysts are available for a short call. Bring a specific question and we will ground it in the data.