Managing Upstream Exposure: What a Food Recall Teaches Us About Nth-Party Risk

August 21st, 2026 David Rusher Reading Time: 5 minutes
Managing Upstream Exposure: What a Food Recall Teaches Us About Nth-Party Risk

A recent food recall caught my attention, not just because of the immediate food safety concerns, but because of what it says about the way third-party risk works today. 

Taylor Farms recently recalled certain products containing jalapeño peppers after the peppers were connected to an earlier recall by Coast Citrus Distributors over potential Salmonella contamination. The affected peppers had made their way into finished products sold through major retailers. 

There are important food safety and supply chain implications here. For consumer packaged goods (CPG) and other consumer-facing companies, incidents like this can be especially instructive because an issue originating with one upstream party can quickly become a product, regulatory, retailer, reputational, and consumer trust issue. The situation also illustrates something third-party risk leaders have been grappling with for years: a company can have strong controls around its direct suppliers and still be exposed to risks several tiers upstream. By the time those risks surface, they may already have significant operational, regulatory, customer, or reputational consequences. 

Your Supplier’s Supplier Is Your Risk 

Companies have understandably focused most of their third-party risk efforts on the organizations they contract with directly. But your direct third party is only one part of your risk picture. 

Behind that organization might be a manufacturer, processor, logistics provider, technology company, subcontractor, or another party it depends on to deliver a product or service. You may never contract with those companies or even know they exist, but their problems can still become your problems. 

That’s what situations like the Taylor Farms recall bring into focus. The company selling the finished product isn’t necessarily where the issue began. Risk originated further upstream and moved through a series of business relationships until the consequences reached companies and consumers downstream. 

That dynamic is particularly visible in CPG, where brands often operate across complex networks of ingredient suppliers, contract manufacturers, packaging providers, distributors, logistics partners, and retailers. A problem at any one of those points can potentially affect products carrying the company’s name, even when the source of the issue sits several relationships away. 

The same dynamic plays out across industries. A manufacturer discovers that a critical supplier depends on a single sub-tier facility. A bank learns that a technology provider relies on another provider experiencing an outage. A global company finds itself answering questions about practices involving an organization several tiers removed from its direct relationship. 

This is why third-party risk programs increasingly need to understand the broader network of dependencies surrounding their most important relationships. That doesn’t mean managing every organization at every tier as though it were a direct supplier. It means identifying where critical dependencies exist and where an Nth party could create material exposure. 

Knowing your third parties is important. Increasingly, understanding who your critical third parties depend on is part of knowing your risk. 

Third-Party Risk Doesn’t Stand Still 

Assessments tell you what was true at a particular point in time. Risk doesn’t work that way. 

A supplier can complete an assessment today and experience a cyberattack next month. Its financial condition can deteriorate. A facility can close. A regulatory action, quality issue, geopolitical event, or natural disaster can suddenly change its ability to deliver. Assessments remain foundational to TPRM, but they shouldn’t be mistaken for a continuous understanding of risk. 

Continuous monitoring helps close that gap by identifying changes in the risk profile of a third party or potentially a critical Nth party. In a scenario like the Taylor Farms recall, the value is in identifying relevant risk signals, understanding whether they could affect critical third-party relationships or dependencies, and determining where further investigation or action may be needed. 

AI, when natively embedded within TPRM, can take that further. Risk teams are navigating supplier data, assessments, intelligence feeds, alerts, news, regulatory information, and internal findings while trying to determine what actually matters. AI can help surface relevant signals, synthesize information, identify relationships and potential exposure, and help users answer more useful questions: What changed? Why does it matter to us? Who could be affected? What deserves our attention first? 

This isn’t about replacing the judgment of risk professionals. It’s about giving them a stronger starting point and enabling them to work at a speed and scale that manual analysis can’t easily match. 

But more alerts and more intelligence aren’t the end goal. What matters is being able to act faster and make better decisions. 

This is where AI and automation can work together. AI can help teams understand a risk signal and its relevance; automation can help operationalize the response. Potentially affected third parties can be identified and engaged, educated on the issue, asked to assess their own exposure, given clear actions to take, and required to provide evidence of their response. 

When the risk warrants it, that engagement can also extend beyond the strategic suppliers receiving the most attention to relevant relationships and dependencies that might otherwise sit outside day-to-day oversight. 

Visibility Matters. What You Do With It Matters More. 

Visibility by itself doesn’t make an organization more resilient. Knowing that a problem exists is useful only if you can determine whether it matters to your business and respond accordingly. 

Consider the questions an event like the jalapeño recall can create downstream: Do any of our suppliers use the affected product? Which products, facilities, or operations could be exposed? Are there other dependencies we need those suppliers to investigate? Who within our organization needs to know? 

For a CPG organization, those questions can become urgent quickly. Teams may need to determine which products, brands, manufacturing locations, distribution channels, or retail relationships could be affected while simultaneously considering regulatory obligations and potential impacts on consumers. 

For TPRM teams, the job is to help the organization understand that third-party dimension of the problem, bring the right information and stakeholders together, and provide a structured way to manage the response. Third parties may need to investigate. Corrective actions may need to be tracked. Evidence may need to be collected. Issues may need to be escalated, while business stakeholders may ultimately need to make decisions about mitigation or alternatives. 

Broader visibility, AI, and automation become especially powerful when they work together. An emerging risk is detected. AI helps interpret the signal and surface relevant relationships and context. Exposure is assessed. The appropriate third parties are engaged. Responses and evidence are collected, and issues are escalated where necessary. 

The value of AI in TPRM isn’t simply that it helps us process more information. It’s that it can reduce the distance between insight and action. 

What This Means for Third-Party Risk Leaders 

The lesson from incidents like this isn’t that third-party risk teams should anticipate or manage every possible supply chain disruption. They can’t, and that’s not their mandate. 

Organizations do, however, need to get better at understanding how their third-party relationships and dependencies create business exposure, recognizing when those risks change, and responding before they become larger operational, regulatory, or reputational issues. 

The future of third-party risk management isn’t about collecting more information. Most organizations already have more than their teams can reasonably process. It’s about understanding what matters, why it matters, and what needs to happen next. 

That’s where resilience begins: not with the expectation that every disruption can be prevented, but with the ability to see risk developing and respond while there’s still time to do something about it. 

How Aravo Helps Organizations Put This Into Practice 

At Aravo, we believe effective third-party risk management starts with having the right information in one place along with the context to understand what it means. 

The Aravo Intelligence First™ Platform brings together information from internal systems, external risk intelligence providers, and third parties to create a more complete view of risk. That information can be assessed and scored at multiple levels, from the third party overall to individual engagements and the specific risk domains that matter to the organization. 

That view also needs to stay current. Continuous monitoring helps teams identify changes in third-party risk as they happen, while Aravo’s native AI helps users make sense of new information, surface relevant insights, and determine what needs attention. 

From there, workflow orchestration helps turn insight into action. Teams can engage third parties, conduct additional due diligence, collect evidence, initiate remediation, or escalate issues to the right stakeholders. Aravo AI agents can support users throughout that process, helping them work more efficiently as the volume and complexity of third-party risk grows. 

That’s particularly relevant to events like the recent recall. TPRM can’t prevent every issue that originates further upstream, but it can help organizations understand where they’re exposed, recognize when risk changes, and act before that risk becomes a bigger problem for the business. 


Contact us to learn how Aravo helps manufacturers centralize third-party risk, compliance, performance, and governance to identify potential issues and respond with greater speed and confidence.

David Rusher

Chief Customer Officer

As Chief Customer Officer, Dave is responsible for leading Aravo’s customer experience teams across Customer Success, Technical Account Management, Customer Support, and Value Engineering. His teams are focused on optimizing the value existing customers receive from their investments in Aravo’s solutions while continuously improving their third-party risk management program. Dave is passionate about helping customers solve critical business issues with solutions that support their long-term success and strategic objectives. By delivering the best outcomes for customers, Dave’s teams help ensure Aravo’s continued market leadership and differentiation.

Dave has more than 30 years of experience in the enterprise software industry, which spans across most functional areas of business including engineering, product management, product marketing, professional services, and customer support.

Prior to Aravo, Dave served as SVP of Enterprise Feedback at Market Tools where he was responsible for global sales of MarketTools CustomerSat™ Enterprise Feedback Management solution. Prior to MarketTools, Dave worked with RightNow Technologies – a leading provider of SaaS customer experience management solutions. He initially served as Vice President of Solutions Consulting for the Americas where he worked closely with Product Management and Engineering to influence and prioritize key features and capabilities, addressing functional gaps and innovations based on market demand; he was promoted to Vice President of Sales for the Eastern U.S. and Latin America. Prior to that, he held various solutions leadership roles during a 9-year period with Siebel Systems, culminating in the role of Director, Industry Solutions.

Mr. Rusher holds a Bachelor of Science degree in Computer Science from Oklahoma City University.

Chief Customer Officer

As Chief Customer Officer, Dave is responsible for leading Aravo’s customer experience teams across Customer Success, Technical Account Management, Customer Support, and Value Engineering. His teams are focused on optimizing the value existing customers receive from their investments in Aravo’s solutions while continuously improving their third-party risk management program. Dave is passionate about helping customers solve critical business issues with solutions that support their long-term success and strategic objectives. By delivering the best outcomes for customers, Dave’s teams help ensure Aravo’s continued market leadership and differentiation.

Share with Your Friends:

Subscribe to Blog Updates

Tags