Why supplier non-response isn't just one problem
Supplier non-response covers five distinct failure points, from an invitation that's never opened to a completed profile nobody keeps current. Each has a different cause, so treating them as one problem is why reminders alone rarely fix it.
The easy explanation is that suppliers are busy. That's often true, but it can't be the whole story. Our analysis here at Risk Ledger found that the same onboarding process, run by different buying organisations, produced completion rates from under 20% to over 78%. Suppliers don't get five times busier depending on who's asking, something in the process does.
Five conditions decide whether a supplier responds:
- Relevance: The request reaches someone who can actually answer it, not a generic mailbox or an account manager with no security context.
- Trust: The supplier can verify the request is legitimate before they open it.
- Motivation: There's a commercial reason to prioritise this over paying work.
- Ability: The recipient has the internal support, evidence and time to complete it.
- Proportionality: The scope matches the actual risk of the relationship, not a fixed template applied regardless of size or access.
Miss one, and the request stalls somewhere in the process. Miss several, and it's never attempted at all.
Where suppliers actually drop out of the process
"Supplier didn't respond" hides five different problems: A supplier can ignore the invitation outright, open an account and go no further, start an assessment and abandon it, decline to connect with a specific client, or let a completed profile go stale.
Treat these as one "response rate" and you fix the wrong thing…
A wrong contact at Stage 1 needs better data, not a friendlier email. A stalled assessment at Stage 3 needs help from a colleague, not another reminder. Diagnose the stage before you chase.
What Risk Ledger's platform data shows
Our Risk Ledger platform data - 4,069 supplier invitations across our client base - shows onboarding failure has less to do with the technology and more to do with how it's used.
Overall, around 77% of invitations were accepted. But that headline number hides the variable that actually matters.
Manual, personalised invitations were accepted roughly 82% of the time. Bulk invitations, sent to a generic contact with little context, landed at around 63%.
The gap widens further downstream: of suppliers who accepted, manual invitations converted to a completed assessment about 72% of the time, against 57% for bulk.
The sharpest evidence is client-level variance. Different organisations, running the same platform and the same workflow, saw invite-to-completion rates ranging from below 20% to above 78%.
One Risk Ledger customer, Virgin Money, reported 96.7% completion across 120 invitations - including a 92% completion rate on bulk-sent invites, well above the average for that method. So bulk isn't the problem, an unmanaged bulk send is.
If two organisations get five times the result from the same process, the process isn't the variable. What surrounds it is.
Reach the right person, not just any contact
Most non-response isn't refusal, it's misdirection. In our rejection data, 17.1% of free-text rejections simply redirected the buyer to someone else - an account manager, a bids team, a DPO.
Another 5.4% cited outdated or incorrect contact information. Add in recipients who were never briefed and couldn't identify who should own the response, and wrong contact is the single biggest reason connection requests fail.
The invitation data backs this up. Generic addresses (info@, sales@, support@) get around 47% acceptance and just 27% invite-to-completion. Named contacts do far better on both.
A reminder sent to the wrong person isn't a follow-up strategy, it's essentially the same mistake, sent again.
Fix it before you send, not after you've chased:
- Collect a named commercial contact and a named security or compliance contact, not one generic inbox.
- Ask the business owner to confirm the contact is still current before the invitation goes out.
- Let suppliers redirect the request without killing the workflow - a wrong-person reply should route, not dead-end.
- Revalidate contacts at renewal, when people are most likely to have moved on.
Give suppliers a reason to trust the request
You're asking a supplier to hand over sensitive security information. And so rejecting an unexpected request for that is rational, not obstructive.
In our rejection data, 8.4% of free-text rejections were relationship-verification problems - the supplier couldn't confirm the relationship existed, couldn't find an active contract, or genuinely didn't recognise who was asking. A further group asked outright why access was needed. This isn’t necessarily refusal, it's a supplier declining to act on a message they can't yet verify.
Suppliers should never have to decide whether a legitimate assurance request is a phishing attempt. If your process makes them guess, some will guess wrong and close it.
Send a buyer-owned primer before the platform invitation ever lands. It should cover, in plain terms:
- Who's asking, and which relationship or contract this relates to
- Why the information is needed and what it will be used for
- What's expected of them and by when
- Who to contact if they want to verify any of it first
Where possible, send it from a person or domain the supplier already recognises.
Time the ask around real commercial leverage
Supplier security work competes with paying, revenue-generating priorities. And so timing often decides which one wins.
One Risk Ledger customer saw this directly. During a live tender, two suppliers completed their profiles quickly because doing so was tied to winning the business.
Existing suppliers, with the contract already signed, showed far less urgency unless renewal was close. Same request, same platform, completely different response, because the commercial moment was different.
That pattern holds generally. Suppliers move faster when completion sits before contract signature, when a tender is still live, or when renewal is close enough to matter. They deprioritise it once the contract's signed and there's nothing left to win or lose.
The best time to secure supplier engagement is before the supplier has won the contract. After that point, you're asking for cooperation with no leverage attached to it.
Where you still have leverage, use it deliberately:
- Make onboarding a condition of contract signature, not a follow-up task after it.
- Attach unresolved assessments to renewal, so there's a real date forcing the issue.
- Have the business owner - not just the security team - reinforce why it matters. They're the one with the commercial relationship.
- Be honest about requests sent well after signature: expect lower urgency, and plan your fallback accordingly rather than assuming reminders will close the gap.
Make the assessment proportionate to the relationship
A supplier will rationally deprioritise a long assessment if it doesn't match what's actually at stake. Low-risk service, no sensitive data, no system access, a small commercial relationship - and yet they're facing the same form as your most critical supplier.
That mismatch doesn't just slow things down, it signals the request wasn't thought through, and suppliers respond to that accordingly.
This shows up constantly in our supplier feedback - over 200 pieces flag assessment length, irrelevant questions, or scope that doesn't match the relationship as a reason completion stalls.
One customer's experience makes the nuance clear: a full framework was excessive for small, niche suppliers with no meaningful access, but some of those same small suppliers still needed real scrutiny when they held sensitive data. Size alone didn't predict risk either way.
Proportionality isn't lowering the bar. It's applying the right bar to the right risk.
Scope the assessment to the relationship, not the supplier's size or your default template:
- Triage before you send anything - decide the depth needed based on data, access and criticality, not habit.
- Strip out domains and questions that don't apply to this specific relationship.
- Accept relevant certifications and existing evidence instead of asking suppliers to retype what they've already documented elsewhere.
- Separate "small supplier" from "low-risk supplier" explicitly - they are not the same judgement, and treating them as one will misjudge both directions.
- Tell the supplier upfront which internal roles they'll likely need to involve - security, IT, sometimes legal - so they're not discovering that mid-assessment.
- Let the supplier bring colleagues in early and assign sections to them, rather than assuming one person can answer everything.
- Preserve progress across sessions so a stalled assessment isn't a lost one - the same person shouldn't have to start over because a colleague took a week to reply.
Work with suppliers who already have an assurance process
Not every non-response is a dead end dressed up as one. In our rejection data, 8.8% of free-text rejections pointed the buyer to an existing process instead - a trust centre, a security portal, a standard document pack. This is a supplier engaging, just not in the format you asked for.
Large providers do this constantly. They maintain one trust centre and expect every customer to use it rather than completing a bespoke questionnaire each time. From the supplier's side, that's a reasonable position - answering the same questions repeatedly for every customer doesn't scale for them either.
So instead of treating this as a rejection and escalating, work with what they've offered before assuming you need to fight for something else.
Before escalating, check what's actually on the table:
- Review what the trust centre or document pack already covers.
- Map it against your own requirements - most of it will overlap.
- Identify only the genuine gaps, and ask specifically about those, not the whole assessment again.
- Record the source and date of what you've reviewed, so it's auditable later.
- Escalate only if a material gap remains that the existing material doesn't answer.
A supplier who offers a trust centre is still engaging, even if it’s not in the format you asked for.
Build in escalation before you rely on reminders
Reminders feel like progress. Often they aren't. An automated reminder can't fix a bad contact, a disproportionate request, or a supplier with no commercial reason to prioritise you. Send the same email five times to the wrong person, and you get the same non-result five times.
Risk Ledger's supplier-engagement research found excessive reminders can actively backfire - duplicate emails, digests and repeated sequences create notification fatigue rather than urgency. Past a point, more reminders don't nudge a supplier toward finishing. They train them to ignore you.
The fix isn't fewer reminders. It's changing the intervention when the current one isn't working.
A working escalation model looks like this:
What to do when a supplier still won't engage
Some suppliers won't participate, regardless of how well you've run the process. Risk Ledger data puts this at roughly 5-10% of suppliers based on our platform data. Non-response isn't approval but it shouldn't leave you with nothing either.
Not every unresponsive supplier is the same problem, and they don't need the same response:
- Healthy responders: Engaged, named owner, profile kept current. Keep the process light. Don't manufacture extra chasing where none is needed.
- Recoverable suppliers: Some engagement exists, but it's stuck on a wrong contact, unclear value, or a stalled internal process. Fix the routing, clarify the benefit, and a personal follow-up usually moves it.
- Structurally resistant suppliers: Consistent non-engagement, a policy against third-party platforms, or a trust centre offered in place of everything else, with no sign that's going to change. Stop expecting a different outcome from the same approach.
For that last group, the answer isn't more escalation. It's a fallback record:
Build a baseline instead of leaving a blank:
- Pull together whatever documents you already hold from prior dealings with the supplier.
- Review their trust centre or public assurance material directly.
- Verify any certifications they hold independently, rather than taking the claim at face value.
- Check relevant public information - company filings, breach history, security disclosures.
- Build a baseline record from what you've gathered, and label clearly what's supplier-confirmed versus what you've sourced externally.
- Record what's uncertain rather than glossing over it.
- Make an actual risk decision on what you have, with an owner attached.
- Revisit at renewal - the picture can change even if the supplier hasn't engaged since.
The point isn't to force every supplier through the same door. It's to make sure "pending" never becomes a permanent status that nobody's actually decided anything about.
How Risk Ledger approaches supplier engagement
We ask for a named contact at both invitation and connection stage, not a generic inbox, and we let suppliers redirect a request to the right person without killing the workflow - directly addressing the wrong-contact problem behind most rejections.
Suppliers maintain one security profile that's reusable across every connected customer, rather than starting from zero each time. A supplier can see the assessment isn't a one-off cost for one customer, but something that compounds.
We support small and full assessment frameworks with configurable domains, so the scope can actually match the relationship rather than defaulting to one template for everyone. Suppliers can bring colleagues in early and split sections between them, rather than one person carrying the whole response alone.
Discussions and remediation requests sit against the specific control they relate to, rather than scattering across email threads that go stale the moment someone changes role.
And when a supplier won't engage at all, unclaimed profiles let us hold categorisation, notes and documents against that supplier from day one - so a non-response doesn't mean starting the fallback record from a blank page later.

What security teams ask next
- Vendor Risk Assessment: A Framework for Making Defensible Risk Decisions
- CISO Briefing: Speed vs. Security - Eliminating the Commercial Bottleneck of Supplier Due Diligence
- Third-Party Risk Management Trends 2026: What's Changing and What Security Teams Should Do About It
Sources
NCSC - Supplier assurance questions
NCSC - Phishing: defending your organisation

