Skip to main content

Third Party Risk Management

The Energy Transition's Hidden Third-Party Risk

New Vendors, New Exposure, Same Blind Spot

The energy transition has introduced an entirely new category of supplier into the oil and gas sector's orbit - solar inverter manufacturers, battery energy storage system providers, smart grid software vendors and distributed generation technology companies - most of which sit well outside the vendor risk frameworks that decades of upstream and midstream procurement practice were built around. The exposure this creates is now moving from theoretical concern to active regulatory intervention, in the space of little more than a year.

The clearest illustration is the solar inverter supply chain. Inverters are the devices that convert the DC electricity generated by solar panels into the AC electricity used on the grid - and critically, they are increasingly network-connected, remotely monitored and, in many installations, remotely controllable by the manufacturer. Analysis published in 2026 puts the scale of the exposure starkly: more than 200 gigawatts of European solar capacity is linked to Chinese-manufactured inverters, with two manufacturers - Huawei and Sungrow - accounting for roughly 55 percent of global shipments. The European Commission's own Economic Security Doctrine has explicitly identified these inverters as a high-risk dependency, citing supplier concentration, cyber-manipulation risk and the inverter's access to grid-relevant operational data.

The regulatory response has moved unusually fast. In April 2026, the European Commission confirmed it would restrict EU funding - including through the European Investment Bank and European Investment Fund - for solar, wind and storage projects using inverters from suppliers designated high-risk, specifically naming China, Russia, Iran and North Korea. Wood Mackenzie's subsequent analysis, published in July 2026, forecasts that this funding restriction will affect approximately 14 percent of European solar demand and 12 percent of energy storage deployments through to 2030 - equivalent to more than 28 gigawatts of solar inverter demand alone. Projects not connected to the EU grid face a hard exclusion deadline of 15 April 2027.

What makes this a third-party risk story rather than purely a geopolitical or trade policy one is the mechanism of exposure itself. The concern is not simply where an inverter is manufactured - it is that inverters, as network-connected devices with firmware update access and operational data visibility, represent exactly the kind of third-party technology dependency that traditional oil and gas vendor risk frameworks, built around EPC contractors and OT equipment suppliers, were never designed to assess. The same logic extends to battery storage management systems, smart meter software and distributed energy resource management platforms - all relatively new entrants into an energy company's vendor ecosystem, all carrying data and connectivity profiles that merit the same rigor historically reserved for core operational technology vendors.

The near-term implication is a widening, not a narrowing, of the third-party risk perimeter that energy sector organisations need to actively manage. A vendor risk framework calibrated to assess drilling contractors, pipeline maintenance providers and refinery equipment suppliers will not, without deliberate extension, capture the risk profile of a battery storage software vendor or a smart inverter manufacturer - yet these suppliers are becoming as embedded in the sector's operational future as any traditional oilfield services contractor. Organisations that extend their existing due diligence rigor - jurisdictional risk assessment, firmware and update governance, data access mapping - to this new vendor category now will be considerably better positioned than those treating energy transition procurement as a parallel, lower-scrutiny track.