Financial Services Supply Chain Statistics

20 stats6 sources

PRESSURE CHOLLIMA conducted the largest financial theft ever reported: $1.46 billion in cryptocurrency via a trojanized supply chain compromise.

CryptocurrencySupply ChainFinancial Theft

Third-party involvement occurs in 30% of financial-sector breaches.

Supply ChainThird-Party RiskFinancial Sector

73% of large organizations with 5,001 or more employees fall into the lowest TPRM confidence tiers.

Financial ServicesTPRMThird-Party RiskEnterprise RiskRisk Management

Individual TPRM professionals are responsible for 100 or more vendor relationships.

Financial ServicesTPRMVendor ManagementThird-Party Risk

13% of the most mature TPRM programs view TPRM as little more than a compliance formality.

Financial ServicesTPRMThird-Party RiskOrganizational MaturityCompliance

Financial institutions using manual TPRM processes report 50% lower satisfaction with their tools.

Financial ServicesTPRMManual TPRM ProcessesThird-Party Risk

Nearly 87% of financial institutions use TPRM software.

Financial ServicesTPRMThird-Party Risk

Financial institutions using manual TPRM processes are 71% more likely to receive exam findings.

Financial ServicesTPRMComplianceThird-Party RiskManual TPRM Processes

72% of financial institutions are only partially aware of which vendors use AI, and 0% feel extremely confident managing vendor AI.

Financial ServicesTPRMArtificial IntelligenceThird-Party RiskVendor Management

63% of TPRM programs operate with just one or two dedicated full-time employees.

Financial ServicesTPRMThird-Party Risk

13% of TPRM programs have no dedicated staff.

Financial ServicesTPRMThird-Party Risk

26% of the most mature TPRM programs report TPRM delivering high value across the organization.

Financial ServicesTPRMThird-Party RiskRisk Management

67% of organizations with no TPRM processes view TPRM as little more than a compliance formality.

Financial ServicesTPRMThird-Party RiskCompliance

53% of TPRM programs manage 300 or more vendors.

Financial ServicesTPRMVendor ManagementThird-Party Risk

10% of financial institutions still rely on spreadsheets, down from 13% in 2025.

Financial ServicesTPRMThird-Party RiskSpreadsheetsCompliance

33% of leaders at financial services firms say they are unprepared to recover effectively from a Supply chain attack.

Financial services RecoverySupply chain attack

It takes financial organisations nearly 16 hours to respond to supply chain attacks on average.

Financial institutionSupply chain attackUK

35% of financial services professionals identified political instability as a challenge to supply chain assessment.

Political instabilitySupply chainFinancial services

26% of financial services professionals identified geopolitical risk as a challenge to supply chain assessment.

GeopoliticsSupply chainFinancial services

Among financial services professionals who were less than "very confident" in their program's ability to assess their supply chains for threats, more than half (56%) of global respondents identified cybercrime as the biggest challenge to their programs in 2025.

CybercrimeSupply chainFinancial services