Audit & Assurance

Third-Party Risk Management for Manufacturing Supply Chains in India

14 min read Expert verified
TL;DR Summary
One vendor failure can halt your entire production line. Third-party risk management is about knowing what you are signing up for, before you sign. Risk is high: over half of Indian suppliers experienced a third-party breach in the past year. Not all vendors need the same scrutiny. Classify them by criticality and focus resources on high-risk suppliers. Before onboarding, run financial health checks. A supplier in distress is a supplier that may fail. Verify GST registration, labor law compliance, and statutory filings. Their non-compliance can become your liability. Onboarding checks are not enough. You need ongoing monitoring: financial, compliance, and cybersecurity. Build vendor risk management into your contracts. Include audit rights, SLAs, and data protection clauses. PKC helps Indian manufacturers design risk frameworks, conduct due diligence, and monitor compliance across their vendor network.

Third-party risk management for manufacturers means identifying, assessing, and controlling risk from vendors, suppliers, and contractors – starting with classifying them by criticality (Tier 1 critical to Tier 4 low-risk), running financial and compliance checks before onboarding, and monitoring GST status, labor law compliance, and cybersecurity on an ongoing basis rather than only at signup.

Weak suppliers can disrupt production, create compliance issues, or expose your businesses to cybersecurity threats. Third-party risk management helps manufacturers identify, assess, and control such risks from vendors, suppliers, and contractors. 

This guide explains the key elements of third party risk management for Indian manufacturers. You will learn why vendor risk is often underestimated, how to categorize suppliers by criticality, what financial and compliance checks to run before onboarding, and how to build ongoing monitoring into your operations.

Why Vendor Risk Is Underestimated in Manufacturing Supply Chains

Modern manufacturing depends on complex, multi-tier supply chains involving hundreds of external partners. Every additional vendor introduces operational, financial, legal, and technological risk.

Most manufacturers invest heavily in their own internal controls. They audit production lines, monitor quality systems, maintain statutory compliance, and secure their IT infrastructure. 

Yet they rarely apply the same level of scrutiny to suppliers, contractors, and service providers. That gap creates one of the biggest blind spots in modern supply chains.

Vendor risk does not occur as a single dramatic event. It develops gradually. 

A single-source supplier for a critical component carries risk that is invisible until that supplier shuts down, gets acquired, or faces a labour dispute. At that point, production stops, and the manufacturer discovers there was no backup vendor, no documented specifications to hand to an alternative, and no contractual right to demand advance notice of such disruptions.

India’s manufacturing supply chains are expanding rapidly, driven by the Production Linked Incentive (PLI) schemes and the “Make in India” programme. As India emerges as a global manufacturing hub, it also faces unique risks that global risk frameworks often overlook:

Operational continuity poses a major challenge. Job work and subcontracting, common in textiles, auto components, and engineering goods, extend GST and quality risks beyond direct vendors.

If a registered job worker uses an unregistered subcontractor, hidden compliance risks can also arise. 

Vendor concentration is another blind spot. Many businesses rely on a handful of suppliers for a large share of their raw materials or components. 

This arrangement may improve pricing and simplify procurement, but it also creates dependency. A labour dispute, ownership change, equipment failure, or liquidity crisis at a single supplier can quickly disrupt production.

Financial fragility adds to the problem. A significant proportion of India’s ancillary manufacturers and component suppliers are MSMEs operating on tight margins and limited working capital. 

Rising raw material costs, delayed payments, or credit constraints can weaken these businesses long before customers become aware of the problem.

Regulatory risk is equally underestimated. Vendors that stop filing GST returns, default on EPF contributions, or operate without valid licences expose manufacturers to input tax credit disputes, compliance issues, and reputational consequences during audits or inspections.

Cybersecurity is another growing concern. Recent industry data shows that more than half of Indian suppliers experienced at least one third-party cyber incident in the past year, while only a small fraction publicly disclosed those breaches. 

When vendors manage sensitive information, cloud infrastructure, ERP systems, or industrial IoT networks, their vulnerabilities become your vulnerabilities.

Manufacturers that consider vendor onboarding as a one-time paperwork exercise are often the most vulnerable when suppliers fail. 

Effective third-party risk management requires a structured and repeatable process for vendor selection, monitoring, and offboarding. Trust matters, but verification matters more.

Categorizing Vendors by Criticality – Not All Suppliers Need the Same Scrutiny

You cannot treat every vendor the same way. Applying the same level of due diligence to every vendor wastes resources on low-risk suppliers while leaving critical ones under-scrutinised.

An effective third-party risk management framework starts with vendor criticality assessment: classifying suppliers according to the impact they have on your business and the risks they introduce.

How Vendor Criticality is Assessed

For manufacturers, vendor criticality typically depends on four factors:

  • The financial impact of a supplier failure
  • The availability of alternative suppliers
  • The time and cost required to switch vendors
  • The regulatory, safety, or quality implications of a disruption

Suppliers that score highly across multiple parameters require deeper due diligence and ongoing oversight.

The widely used Kraljic Matrix offers a practical framework by evaluating vendors against two dimensions: supply risk and business impact. Suppliers with high scores on both axes demand the highest level of scrutiny, while low-risk, low-impact vendors can be managed through lighter controls.

Practical Vendor Classification Framework

Vendor TierDescription & ExamplesRecommended Scrutiny
Tier 1: CriticalSingle-source or high-impact suppliers (e.g., contract manufacturers, cloud providers)Full due diligence, annual review, continuous monitoring
Tier 2: ImportantKey operational suppliers (e.g., logistics, packaging)Standard due diligence, periodic audits
Tier 3: RoutineReplaceable suppliers (e.g., maintenance, consumables)Basic compliance checks, periodic review
Tier 4: Low RiskLow-impact suppliers (e.g., office supplies, catering)Simplified onboarding, standard checks

Tier 1: Critical Vendors

These supply components or raw materials with no ready substitute, long lead times to replace, or direct impact on product safety and compliance.  Examples include:

  • Sole-source suppliers of proprietary components
  • Vendors certified under customer-mandated quality standards
  • Suppliers of safety-critical parts
  • Contract manufacturers handling intellectual property
  • Technology providers with access to sensitive business data

These vendors need full financial due diligence, site visits, compliance verification, and contractual protections including exit clauses and business continuity commitments.

Tier 2: Important Vendors

These matter operationally but have viable alternatives, even if switching takes effort. A packaging material supplier or a logistics partner with two or three competitors in the same region typically sits here. 

Due diligence should cover financial stability checks, GST and statutory compliance verification, and periodic performance review, without the intensity applied to Tier 1.

Tier 3: Routine Vendors

General maintenance contractors, and low-value consumables fall into this bucket. 

Basic registration checks and standard commercial terms are usually sufficient. Over-auditing here adds cost without reducing meaningful risk.

Tier 4: Low Risk Vendors

These cover suppliers with minimal operational impact such as office supplies, catering services, etc. 

A simplified onboarding and standard commercial checks are sufficient here. 

Vendor Criticality Changes Over Time

Vendor classification is not permanent. A supplier that poses little risk today may become business-critical tomorrow.

For example:

  • A Tier 2 supplier may become your sole source after a competitor exits the market.
  • A routine component may become safety-critical after a product redesign.
  • New regulatory requirements may increase compliance obligations for specific vendors.

Businesses should reassess vendor classifications at least once a year and whenever there is a significant change in products, suppliers, or regulations.

This tiering exercise also shapes how you allocate your risk management budget. Spending equal time on a stationery vendor and a sole-source component supplier is a misallocation that leaves the vendor that actually matters under-protected. 

A documented criticality framework, even a simple spreadsheet-based one, gives you a defensible basis for where scrutiny goes and why.

Financial Health Checks Before Onboarding a New Vendor

A vendor’s financial health determines whether they can deliver consistently over the life of your contract, not just at the point of signing. 

Financial distress is one of the most common reasons suppliers default on their obligations. When that happens, your production line stops.

Before you onboard a new vendor, you need to verify their financial stability. It helps ensure that your vendors have the resources to support your business over the long term. For a consolidated checklist covering financial, compliance, and operational checks in one place, see our vendor due diligence checklist for manufacturing firms.

Basic Business Verification

Before reviewing financial performance, confirm that the vendor is legally registered and compliant. Request and verify:

  • Certificate of Incorporation or partnership deed
  • Permanent Account Number (PAN)
  • GST registration certificate
  • MSME Udyam registration, where applicable
  • Bank account details

Do not rely solely on scanned documents. The official GST portal allows businesses to verify a supplier’s GSTIN, registration status, legal name, and filing history. A suspended or cancelled GST registration should immediately pause the onboarding process.

Review Financial Statements 

For companies and LLPs, ask for at least the last two or three years of audited financial statements. Smaller businesses that do not maintain audited accounts should provide provisional financials, income tax returns, and recent bank statements.

Focus on long-term trends rather than a single year’s performance. Key indicators include:

  • Revenue growth or decline
  • Profit margins
  • Current ratio and liquidity position
  • Debt-to-equity ratio
  • Cash flow stability
  • Outstanding loans and borrowings

A vendor with falling revenues, shrinking margins, or mounting debt may struggle to maintain inventory, invest in equipment, or absorb fluctuations in raw material costs.

Working Capital and Debt Exposure

Working capital is particularly important in manufacturing supply chains, where suppliers often operate on thin margins and extended payment cycles.

A vendor with insufficient working capital may face difficulties in:

  • Procuring raw materials
  • Maintaining safety stock
  • Funding production expansion
  • Managing payment delays
  • Addressing quality issues and rework

For companies registered in India, the Ministry of Corporate Affairs’ official MCA portal provides information on charges registered against company assets. Significant secured borrowing or multiple lender charges may indicate financial stress and should be reviewed carefully.

You should also verify whether the company has been involved in insolvency proceedings or has a history of delayed financial filings, as persistent non-compliance often points to weak internal controls.

Creditworthiness and Payment Behaviour

Credit ratings can provide an additional layer of assurance, particularly for larger suppliers. Ratings from agencies such as CRISIL, ICRA, and Acuité offer insights into a company’s repayment capacity and financial stability.

For smaller vendors that may not have formal ratings, request:

  • Trade references from existing customers
  • Supplier references
  • Recent bank statements
  • GST return filings

Speaking to other buyers in your industry often reveals operational issues that financial statements alone cannot capture, including delayed deliveries, payment disputes, or inconsistent service levels.

Legal Exposure and Insurance Coverage

Pending litigation, tax disputes, and regulatory actions can significantly affect a vendor’s financial position. Legal proceedings consume management attention and may restrict access to credit.

Equally important is insurance coverage. Confirm that critical vendors maintain adequate:

  • Product liability insurance
  • Property insurance
  • Business interruption coverage
  • Employer and worker compensation policies

Insurance cannot eliminate risk, but it can reduce the financial impact of unexpected disruptions.

Financial due diligence is not a one-time exercise. You should review the financial health of critical vendors at least annually. 

A vendor that was financially stable last year may not be stable this year. Market conditions change. Raw material prices fluctuate. Demand shifts. Your monitoring needs to keep pace.

Compliance Risk: GST Registration Status, Labour Law, and Statutory Filings

Compliance failures by your vendors can become your compliance failures. Before onboarding any vendor, you need to verify their compliance with applicable laws and regulations.

GST Compliance

Verify that the vendor has a valid Goods and Services Tax Identification Number (GSTIN). However, registration alone is not enough. A supplier that has stopped filing returns or paying taxes can expose your business to denied or reversed input tax credits.

Before onboarding a vendor, verify:

  • Whether the GSTIN is active and not suspended or cancelled
  • The legal name and registered business address
  • Whether GST returns are being filed regularly
  • Any history of non-compliance or tax disputes

The official GST portal allows businesses to verify GST registration status. For critical suppliers, consider requesting periodic confirmation of GSTR-2A or GSTR-2B reconciliations to identify potential mismatches early.

Labour Law Compliance 

Manufacturers frequently engage vendors that employ contract labour or operate as job workers. In these cases, labour law non-compliance can create direct exposure for the principal employer.

Key regulations to verify:

  • The Factories Act, 1948
  • The Contract Labour (Regulation and Abolition) Act, 1970
  • The Employees’ Provident Fund and Miscellaneous Provisions Act, 1952
  • The Employees’ State Insurance Act, 1948
  • Applicable minimum wage laws

Two statutory thresholds are important:

  • Establishments employing 20 or more workers must register under the EPF framework.
  • Establishments with 10 or more employees, where eligible workers earn up to ₹21,000 per month, must register under the ESI scheme.

If a contractor fails to make mandatory contributions, liability may extend to the principal employer under certain circumstances.

As part of vendor due diligence, request:

  • EPF and ESIC registration numbers
  • Monthly contribution acknowledgements
  • Labour licences and contractor registrations
  • Evidence of wage and statutory payments
  • Details of any pending labour disputes or penalties

These checks should continue throughout the relationship, particularly for Tier 1 and Tier 2 vendors.

Environmental and Operational Compliance

Manufacturing suppliers must also comply with environmental regulations and operational licensing requirements. Depending on the industry, verify:

  • Consent to Establish and Consent to Operate from the State Pollution Control Board
  • Waste management and disposal approvals
  • Emission and effluent compliance records
  • Factory licences and safety approvals

For businesses operating in regulated sectors, additional licences may apply. Vendors supplying food-contact materials, for example, may require approvals from the FSSAI.

Other Statutory Registrations 

Your compliance checklist should also include:

  • Professional Tax registration
  • Shops and Establishments registration
  • Trade licences
  • Import Export Code (IEC), where relevant
  • Industry-specific certifications such as BIS approvals

The required documents will vary depending on the vendor’s size, location, and business activity, but they should always be verified independently rather than accepted at face value.

The financial consequences of vendor non-compliance can be significant, but the operational and reputational costs are often even greater. 

A structured vendor due diligence checklist, supported by regular monitoring, helps ensure that your suppliers remain compliant long after the onboarding process is complete.

Ongoing Monitoring vs. One-Time Onboarding Checks

Vendor due diligence doesn’t end at onboarding. A supplier that met every requirement two years ago may now have GST defaults, financial distress, ownership changes, or cybersecurity issues. One-time checks leave these risks hidden until they disrupt your business.

Vendor risk  also changes over time. Effective third-party risk management requires continuous monitoring, not just annual reviews or supplier declarations. 

Regulators, customers, and auditors increasingly expect businesses to demonstrate ongoing oversight of their supply chains, making real-time visibility essential.

Build Monitoring Around Vendor Criticality

The frequency and depth of monitoring should mirror the vendor classification framework established during onboarding.

Vendor TierMonitoring Approach
Tier 1: CriticalQuarterly compliance reviews, annual financial assessments, continuous performance monitoring
Tier 2: High PriorityAnnual compliance verification and regular operational reviews
Tier 3&4: Moderate and Low RiskPeriodic checks or reviews triggered by specific concerns

For Tier 1 suppliers, a quarterly review is often appropriate. This should include:

  • Verification of GST registration status
  • Annual review of financial statements
  • Monitoring of delivery performance and rejection rates
  • Checks for regulatory actions and litigation
  • Review of licences and certifications

A sudden increase in late deliveries or quality issues from a previously reliable supplier is often the earliest sign of financial or operational stress.

Combine Scheduled Reviews With Trigger-Based Monitoring

Calendar-based reviews are important, but they are not enough on their own. Businesses should also establish trigger events that automatically initiate an off-cycle assessment.

Immediate review should occur if a vendor:

  • Misses multiple delivery deadlines
  • Requests advance payments outside agreed terms
  • Changes ownership or senior management
  • Receives regulatory notices
  • Experiences a cybersecurity incident
  • Shows a sharp increase in product defects or customer complaints

These triggers often reveal emerging problems much faster than annual reviews.

What Continuous Monitoring Should Cover

An effective vendor-monitoring programme typically includes five key areas:

  • Compliance tracking: Monitor GST registrations, licences, certifications, environmental approvals, and labour law compliance to identify lapses before they affect your business.
  • Financial reviews: Assess critical suppliers at least once a year for signs of stress, including declining revenues, increasing debt, and deteriorating cash flow.
  • Cybersecurity oversight: Vendors increasingly manage sensitive operational and customer data. Their cybersecurity controls, software updates, and certificate management should be reviewed regularly.
  • Performance monitoring: Track delivery timelines, quality metrics, service-level agreements, and responsiveness. Operational failures often signal deeper financial or organisational problems.
  • Sub-tier supplier risk: Do not limit visibility to direct suppliers. Risks originating from fourth parties and subcontractors can be just as disruptive.

Continuous monitoring does not require expensive software. Many mid-sized manufacturers can manage with a central vendor master file tracking GST status, compliance dates, financial reviews, and audit findings. 

Larger organisations may use automated third-party risk platforms, but technology is only effective if someone is responsible for reviewing and acting on the information.

Ownership should usually rest with procurement, supported by finance, legal, and internal audit for critical vendors.

The cost of monitoring is minimal compared to the impact of supplier failure. Production delays, emergency sourcing, higher logistics costs, regulatory penalties, and missed customer commitments can far exceed the effort of regular reviews.

Effective monitoring is about focusing on the right suppliers at the right intervals so risks are identified before they become disruptions.

Building Vendor Risk Into Contracts and SLAs

Vendor due diligence helps identify risks, while contracts and service level agreements (SLAs) help manage them. 

Without clear agreements, you may be exposed if a vendor fails to deliver, breaches compliance, or exits unexpectedly. A well-drafted contract sets expectations, allocates risk, and provides remedies when issues arise.

Start With Compliance Representations and Warranties

Every vendor agreement should require the supplier to confirm, in writing, that it complies with all applicable laws and will continue to do so throughout the contract period.

The contract should cover compliance with:

  • GST laws and tax filings
  • Labour regulations, including EPF and ESI requirements
  • Environmental and pollution-control rules
  • Data protection obligations
  • Industry-specific licences and certifications

For manufacturers, this clause should be supported by an indemnity requiring the vendor to cover losses from their non-compliance, including tax credit reversals, penalties, and regulatory action.

Define Clear and Measurable Service Levels

Service level agreements should establish objective performance standards that can be monitored and enforced.

Your SLAs should specify:

  • Delivery timelines and lead times
  • Product quality and acceptance criteria
  • Maximum defect or rejection rates
  • Response and resolution times
  • Reporting obligations
  • Penalties and remedies for non-performance

Possible remedies include price adjustments, liquidated damages where legally appropriate, the right to procure materials from an alternative supplier at the vendor’s cost, or termination after repeated breaches.

Include Audit and Inspection Rights

For Tier 1 and other high-risk suppliers, audit rights are essential. The contract should clearly define:

  • Scope of audits
  • Notice periods
  • Audit frequency
  • Access to records and facilities
  • Responsibility for audit costs

Audit rights should extend beyond financial records to cover operational performance, statutory compliance, quality systems, and cybersecurity controls where relevant.

Address Subcontracting and Fourth-Party Risk

Subcontracting is common in sectors like automotive, engineering, textiles, and consumer goods. However, unapproved subcontracting can create quality, compliance, and intellectual property risks.

Your contract should state:

  • Whether subcontracting is permitted
  • Which activities may be outsourced
  • Whether prior written approval is required
  • The vendor’s responsibility for subcontractor performance
  • The requirement to disclose subcontractor registrations and licences

Even when work is subcontracted, the primary vendor should remain fully liable for the actions of downstream suppliers.

Strengthen Data Protection and Intellectual Property Clauses

As manufacturers increasingly share designs, technical specifications, and customer data with external partners, contracts must clearly allocate ownership and responsibility.

Include provisions covering:

  • Ownership of drawings, tooling, and product specifications
  • Confidentiality obligations
  • Restrictions on using your intellectual property for third parties
  • Return or destruction of proprietary information after termination
  • Data handling and security requirements
  • Breach notification timelines

With the Digital Personal Data Protection Act, 2023 now in force, contracts should also address data processing responsibilities and any restrictions on sub-processing arrangements.

Plan for Business Continuity and Exit

Vendor contracts should assume that disruptions will occur and define how both parties will respond.

For critical suppliers, include:

  • Business continuity and disaster recovery obligations
  • Requirements to maintain backup production capabilities
  • Notice periods for termination
  • Transition support during vendor replacement
  • Exit management procedures

The goal is to ensure continuity of supply when circumstances change.

Review Liability Caps and Insurance Carefully

Many supplier agreements limit liability to the value of recent invoices. That may be inadequate if a defective component causes a product recall, production shutdown, or customer claim.

Review liability limitations alongside the vendor’s insurance coverage, including:

  • Product liability insurance
  • Property damage coverage
  • Business interruption insurance
  • Cyber insurance, where relevant

The contract should require vendors to maintain adequate coverage and provide evidence upon request.

PKC’s Third-Party Risk Advisory for Manufacturers

PKC Management Consulting has supported Indian businesses since 1988, with a Risk Advisory practice integrated with internal audit, financial audit, and governance and compliance.

For manufacturers, this is critical because vendor risk often reflects broader weaknesses in procurement controls, approval processes, and financial governance.

Our third party risk advisory covers: 

Vendor due diligence

We conduct comprehensive due diligence on potential vendors before onboarding. This includes financial health checks, compliance verification, operational capability assessment, and cybersecurity evaluation.

Vendor audit services

PKC helps organisations evaluate third-party vendors through structured audits. The focus areas include data analysis on transactions and records, vendor questionnaires, review of contracts and policies, documentation of findings, and identification of process improvement opportunities.

Procurement process auditing

We audit the procurement process to ensure transparency, fairness, and compliance with established policies and regulations. This includes evaluating vendor selection and contract compliance.

Risk framework design

We help businesses design and implement risk management frameworks tailored to their specific needs. This includes vendor classification, due diligence protocols, monitoring mechanisms, and governance structures.

Compliance monitoring

PKC assists with ongoing compliance monitoring across the vendor network. This includes tracking regulatory changes, verifying vendor credentials, and ensuring continued adherence to contractual obligations.

If your manufacturing business is scaling its vendor base, entering new geographies, or preparing for institutional scrutiny, a structured third-party risk review is worth doing before a vendor failure forces the issue. 

PKC’s Risk Advisory team works with manufacturers to build that structure from the ground up, or to strengthen what already exists.

FAQs

Q1: How should manufacturers categorize vendors for risk assessment?

Sort vendors into tiers based on financial impact of failure, availability of alternative sources, lead time to switch, and safety or regulatory exposure. Sole-source suppliers of critical components are in Tier 1 and need the deepest scrutiny. Routine consumable suppliers sit in Tier 3 or Tier 4a no need only basic checks. Reassess tiers annually or after any major supply chain change.

Q2: What financial checks should be done before onboarding a new supplier?

Verify GSTIN status on the GST portal, review two to three years of financial statements or provisional financials, check debt levels and any charges registered with the MCA, and confirm on-time filing history. For smaller vendors, reconcile GST turnover against bank statement credits as a proxy for revenue authenticity before committing volume.

Q3: Does vendor risk management include checking GST compliance status?

Yes. A vendor with a cancelled or suspended GSTIN, or one that has stopped filing returns, puts your input tax credit at risk under GST matching provisions. Checking GSTIN status at onboarding and periodically afterward is a core, low-cost part of third-party risk management for any manufacturer.

Q4: Should third-party risk be reviewed only at onboarding or on an ongoing basis?

Ongoing. Vendor financial health, compliance status, and delivery performance can all deteriorate after onboarding. Critical vendors warrant quarterly reviews, important vendors an annual refresh, and any vendor should move to an immediate off-cycle review if delivery performance drops or ownership changes.

Q5: How can vendor risk clauses be built into supplier contracts?

Include compliance representations covering GST and labour law registration, indemnity for losses caused by vendor non-compliance, measurable SLAs with defined remedies for breach, sub-contracting approval requirements, and exit provisions covering notice periods, audit rights, and return of specifications or tooling.

Q6: What’s the difference between vendor due diligence and vendor risk management?

Vendor due diligence is the point-in-time check done before onboarding a supplier, covering financial health, compliance, and background verification. Vendor risk management is the broader, ongoing discipline: due diligence at onboarding, tiered monitoring throughout the relationship, and contractual controls that manage risk for as long as the vendor relationship lasts.

How PKC can help you

Your dream business is just a click away. Book a FREE 30-minute consultation.

Call us: +91 91761 00095

Got a question after reading?

Drop your details and one of our consultants will call you back — usually within a business day.

Want to talk? Get a call back today
+91 91761 00095

Fill out your details

Once submitted, a calendar will open to book your 30-minute meeting slot.

or call us: +91 91761 00095

Table of Contents

Index