Supplier audits are good at what they were designed to do. They verify that a facility meets established requirements at the time of the review. Permits are current. Reporting obligations are being met. Environmental performance metrics fall within acceptable ranges. The audit closes, the supplier passes, and the relationship continues on the assumption that a passing result is a reliable indicator of ongoing viability.

That assumption worked reasonably well when the risks most likely to affect supplier operations were also the risks audits were designed to find. It is working less well now. CDP's Corporate Health Check 2026 found that organizations face a reported $1.47 trillion in environmental physical risks, yet only 9% of assessed companies have disclosed physical adaptation investments. The gap between the scale of the exposure and the investment going into managing it is not a reporting anomaly. It is a signal that most organizations are not yet treating physical environmental risk as an operational management problem. They are treating it as a disclosure problem, and their supplier assessment processes reflect that.

The Audit Was Designed for Compliance, Not for What Is Coming

The structure of most supplier environmental audits reflects the regulatory environment they were built for. They ask whether a supplier is compliant with current requirements. That is the right question for managing enforcement risk today. It is the wrong question for managing supply chain risk over a three-to-five-year horizon, because the conditions that determine whether a supplier will be able to operate reliably three years from now are often not visible in a compliance snapshot.

Water stress is the most straightforward example. A manufacturing facility can hold all the necessary permits, satisfy every applicable water use reporting requirement, and maintain clean audit results while operating in a region where available freshwater is declining, where competing demands from agriculture, municipalities, and other industrial users are intensifying, and where new national or regional water conservation laws are tightening withdrawal limits. The audit says the facility is compliant. It does not say the facility's water position is becoming structurally more difficult. ISO 14001:2026, published April 15, 2026, addresses this directly: the revised standard now requires that environmental risk planning explicitly consider value chain risks and that climate change, biodiversity loss, and resource scarcity be incorporated into emergency scenario planning. Organizations certified to ISO 14001:2015 have three years to transition. The standard is moving toward resilience. Most supplier audit programs have not.

Physical Climate Risk Is the Category Most Audit Programs Have Not Priced

Beyond water, the physical climate risk exposure sitting inside most supplier networks is substantially larger than what current audit programs are capturing. Facilities may satisfy every environmental standard while operating in locations exposed to flooding, extreme heat, wildfire activity, or severe storms that have been increasing in frequency and intensity. Those conditions do not create immediate compliance issues. They create operational interruptions that can last weeks or months when they materialize, and they create insurance and financing pressures that affect supplier financial stability well before any disruption occurs.

Procurement risk is increasingly forming before sourcing decisions begin, shaped by system-level constraints that procurement teams neither own nor directly control. Power access, grid timelines, permitting exposure, and infrastructure readiness are setting boundaries that no request for proposal (RFP) can override. The same dynamic applies to physical climate risk: by the time a climate-related disruption forces a procurement response, the options for responding have already narrowed. A supplier network built on facilities in flood-prone logistics corridors or heat-stressed manufacturing regions does not become resilient when the next weather event arrives. It reveals, at that point, how resilient it was before the event.

Regulatory Momentum Is a Risk Category Audits Are Poorly Positioned to Assess

Environmental audits evaluate compliance with existing regulations. Very few systematically assess how the regulatory environment around a supplier is likely to change and what that trajectory means for operating costs, permit complexity, and production constraints over the medium term. That is a meaningful gap, because regulatory momentum in environmental compliance tends to move in one direction, and the industries and geographies facing the most significant increases in scrutiny around emissions, water use, waste management, and chemical handling are often the same ones concentrated in major manufacturing supply chains.

A supplier in a sector facing increasing emissions regulation may be fully compliant today while carrying capital expenditure requirements for pollution controls, process changes, or fuel switching that will materially affect its cost structure within the planning horizon of a multi-year supply agreement. A facility whose permits are approaching renewal in a jurisdiction where environmental standards have tightened may face a more complex permitting process than it has historically encountered, with community opposition, infrastructure constraints, or changed agency priorities all capable of affecting the outcome. Neither of those conditions shows up in an audit result. Both of them are material to whether the supplier relationship will perform as modeled.

What Assessing Environmental Resilience Rather Than Compliance Actually Looks Like

The organizations beginning to close this gap are asking a different set of questions alongside their standard audit programs.

  • What environmental pressures exist in the regions where critical suppliers operate?
  • Which facilities depend on resources facing increasing constraint?
  • What does the physical climate risk profile of key supplier locations look like over a five-to-ten-year horizon?
  • What future regulatory developments could affect production costs or operating conditions?
  • Where do environmental vulnerabilities concentrate in the same facilities that represent the highest business dependency?

Those questions require data that does not come from the supplier's own compliance documentation. They require regional environmental analysis, climate risk modeling, regulatory trajectory assessment, and in many cases direct engagement with suppliers on their own contingency planning. Sedex's 2026 due diligence analysis describes the direction of travel clearly: companies that embed environmental due diligence into procurement and supplier relationships, rather than treating it as a compliance verification exercise, are better positioned to identify developing risks before they become operational crises. The audit is not going away. What is changing is the expectation that a passing audit is sufficient evidence of supply chain resilience.

Environmental accountability is evolving from verification toward something harder: understanding how environmental conditions, not just environmental compliance, influence business performance across entire supply chains. The organizations that build that capability now will find risks earlier and with more time to respond. Those that treat the audit result as the endpoint will discover the gap between compliance and resilience when the next disruption makes it visible