Maturity Levels Remain Limited
Many companies assess their TPRM maturity more positively than their actual capabilities suggest. While 31% consider themselves to have reached an integrated maturity level, the detailed findings indicate that fully integrated TPRM remains the exception rather than the rule. This highlights a key reality: although standardized processes are widely in place, consistent execution across functions and risk dimensions is still uncommon.
Governance Often Remains Decentralized
One of the study’s key findings concerns the organizational structure of TPRM. Only 45% of companies have implemented an integrated, cross-functional governance approach.
The governance models are distributed as follows:
15% manage TPRM centrally.
40% coordinate TPRM through a central function.
25% operate with partially aligned structures.
20% manage TPRM in a decentralized manner or within individual functions.
These results show that many organizations continue to operate with varying responsibilities, assessment methodologies, and decision-making processes. This makes consistent risk assessment and prioritization particularly challenging.
Fragmented Technology Landscapes Continue to Dominate
Many organizations also lack an end-to-end technology solution, and modern integrated platforms remain rare.
38% of companies rely primarily on manual or Excel-based processes.
54% use specialized point solutions for specific risk areas, such as cyber, ESG, or financial risk.
Only 8% use an integrated TPRM platform.
As a result, organizations face data silos, duplicate assessments, and significant manual effort in consolidation and reporting.
NIS2 Increases the Urgency to Act
The need for action becomes especially evident when examining regulatory requirements. According to the benchmark, approximately 90% of surveyed companies are not yet fully compliant with NIS2.
With Germany’s NIS2 implementation legislation, the European NIS2 Directive was transposed into national law at the end of 2025. Since the law came into effect, harmonized minimum standards for cyber and information security have applied across Europe in critical and essential sectors. In addition to stricter requirements for governance, risk management, and incident reporting, supply chain security has become a significantly greater area of focus.
Companies must therefore systematically incorporate suppliers into risk analyses, assessments, monitoring activities, and escalation processes. As a result, procurement is increasingly evolving from a purely sourcing-focused function into a central orchestrator of third-party risk management and supply chain resilience.
However, the findings of the Horváth Benchmarking Study show that many organizations are not yet adequately prepared. NIS2 implementation within TPRM is still largely at a partial implementation stage. Only 8% of study participants report having a largely implemented solution, and no company has achieved a fully integrated and compliant setup. Significant gaps remain, particularly in continuous monitoring, tool support, escalation processes, and the contractual integration of NIS2 requirements.
Processes Are Defined, but End-to-End Integration Is Often Missing
Strategies, governance structures, role models, and risk frameworks are already defined and documented in many companies. However, the benchmark shows that high maturity levels are rarely achieved across all TPRM components. In particular, downstream processes such as risk mitigation, continuous monitoring, and reporting are often implemented only selectively. This creates gaps between risk assessment and effective risk management.
Focus Remains on Tier 1 Suppliers
For many organizations, supply chain analysis continues to end at the first supplier tier.
Approximately 70% of companies assess risks primarily at the Tier 1 level. Only 15% systematically analyze Tier 2 structures or use dynamic, risk-based approaches to extend the scope of their assessments.
As a result, critical dependencies deeper within the supply chain often remain hidden. Yet transparency at these lower tiers is becoming an increasingly important differentiator, particularly in addressing geopolitical, regulatory, and operational risks.
Conclusion
The Horváth TPRM Benchmark Study 2026 demonstrates that TPRM is organizationally established and methodologically defined in many companies. At the same time, significant challenges remain in governance, process integration, digitalization, and regulatory compliance.
The most critical gaps lie not within individual framework components, but in how those components interact. Organizations seeking to establish TPRM as an integrated management instrument must strengthen the connections among governance, data, processes, and monitoring.
The findings also make clear that there is no “one-size-fits-all” approach to TPRM. Successful organizations develop a TPRM operating model aligned with their risk profile, organizational structure, and regulatory requirements. Horváth supports companies in defining a tailored target operating model and advancing the professionalization of third-party risk management.
Die Ergebnisse verdeutlichen, dass es kein „One-size-fits-all“-TPRM gibt. Erfolgreiche Unternehmen entwickeln ein TPRM Operating Model, das zu ihrem Risikoprofil, ihrer Organisation und ihren regulatorischen Anforderungen passt. Horváth unterstützt dabei, ein unternehmensspezifisches Target Operating Model zu definieren und die Professionalisierung des Third Party Risk Managements gezielt voranzutreiben.
Source: Horváth TPRM Benchmarking Study 2026 (N=20, as of March 2026)
Hambsch, K. / Mäntele, K. / Müllerschön, D. / Pöhner, B.