The Next Compliance Problem for CFOs Is Their Vendor’s Vendor List
Twenty-seven nations are likely to come up with 27 different definitions of vendor risk. The European Union’s member nations are finding that out in real time. And while the long-standing debate around whether equipment from suppliers such as Huawei should sit inside critical communications infrastructure is nothing new, there is a more consequential problem for […] The post The Next Compliance…
CFOs are facing a new compliance challenge related to their vendors' vendors. While companies typically verify the corporate registration, beneficial owners, sanctions exposure, and bank accounts of their suppliers before approving invoices, they often have limited visibility into the deeper layers of technology, equipment, and components supplied by those vendors.
This blind spot is becoming more problematic as governments increase scrutiny on technology origin, ownership, and concentration. A new Royal United Services Institute (RUSI) analysis reveals significant differences in national approaches to handling high-risk ICT vendors across Germany, Spain and the United Kingdom, highlighting the need for better visibility into technology dependencies throughout supply chains.
Companies must now consider not only the legal identity of their suppliers but also the underlying technology, deployment location, function, and regulatory regime governing it, as risk can vary depending on these factors.
Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.