How Continuous Supply Chain Risk Assessment Builds Digital Trust in ASEAN
BDO in Indonesia’s Yudhi Prasetyo discusses the importance of holistic trust culture through continuous supply chain risk assessment, and its implications for ASEAN’s digital economy.

As Southeast Asia’s digital economy expands, trust has become a critical currency. Organizations across ASEAN are grappling with how to secure customer confidence in an environment where data breaches and cyber threats are increasingly common. According to Yudhi Prasetyo, Head of Digital Services at BDO in Indonesia, the answer lies not in one-time compliance checks but in a holistic culture of trust built through continuous supply chain risk assessment.
Prasetyo, who served as a judge at the Indonesia Technology Excellence Awards 2026, notes that cybersecurity maturity varies widely across the region. In Indonesia, heavily regulated sectors such as financial services have reached high maturity levels, driven by mandates from OJK that align with global frameworks like NIST and NIS2. In contrast, less regulated industries like manufacturing often lack robust oversight, leaving them vulnerable. For ASEAN as a whole, this disparity poses a challenge to regional digital integration. As cross-border digital trade grows, supply chain interdependencies mean that a weak link in one country can compromise trust across the entire ecosystem.
Regional Impact
Continuous supply chain risk assessment directly affects ASEAN’s digital economy competitiveness. When organizations proactively verify the security posture of their vendors, partners, and third-party services, they reduce the risk of data breaches that can erode consumer confidence. This is particularly important in sectors like e-commerce, digital payments, and cloud services, which underpin the region’s digital transformation. For example, Indonesia’s Personal Data Protection (PDP) Law mandates strict data handling, but enforcement requires mechanisms to authenticate digital interactions. Prasetyo emphasizes that pairing PDP Law compliance with Certificate Authority Providers (PSrE) is essential, drawing parallels to the EU’s eIDAS and India’s Aadhaar. A region-wide adoption of similar identity verification standards could streamline cross-border transactions and foster a more integrated ASEAN digital market.
Moreover, the lack of a unified AI governance framework across ASEAN creates uncertainty. While the ASEAN Guide on AI Governance and Ethics provides voluntary guidance, individual countries are moving at different paces. Prasetyo advocates for cross-functional AI committees and a ‘human-in-the-loop’ approach to ensure fairness and transparency. These practices, if adopted broadly, can help ASEAN become a trusted hub for AI innovation, attracting international investment in digital infrastructure and startups.
Future Outlook
Over the next three to five years, several trends will shape how ASEAN organizations build digital trust through supply chain risk assessment. First, regulatory harmonization is likely to accelerate. The anticipated 2026 Presidential Regulation in Indonesia on AI, along with similar moves in Singapore, Thailand, and Vietnam, could converge around common principles. This would reduce compliance complexity for businesses operating regionally and encourage the adoption of continuous risk monitoring tools.
Second, technology will play a bigger role in automating risk assessment. Advances in AI and blockchain can enable real-time verification of supply chain partners, from cybersecurity postures to identity credentials. Cloud-based platforms that aggregate risk data across the region may emerge, giving organizations a holistic view of their digital supply chains.
Third, the demand for digital trust will drive investment in cybersecurity talent and infrastructure. ASEAN’s digital workforce will need to upskill in areas like risk analytics, AI governance, and data privacy. Governments and private sectors will likely collaborate on training programs and certifications to close the talent gap.
Finally, as cross-border digital trade deepens under frameworks like RCEP, continuous supply chain risk assessment will become a baseline requirement for participation. Companies that fail to embed trust into their operations may find themselves excluded from lucrative regional value chains.
In conclusion, building a culture of trust through continuous risk assessment is not just a defensive measure — it is a strategic imperative for ASEAN’s digital future. As Prasetyo puts it, organizations win customer confidence not by promising protection, but by consistently proving the integrity and authenticity of every digital interaction. For ASEAN to realize its ambition of becoming a globally competitive digital economy, it must embed this principle across industries and borders.
Sources
Covering e-commerce and fintech across Southeast Asia for 8 years. Based in Singapore, Sarah provides deep insights into the region's digital payment landscape.


