TPRM glossary

Concentration risk, when the register hides a single point of failure

Concentration risk is the exposure created when too much depends on one thing: a single vendor, a single region, or one underlying provider that many of your vendors quietly share. It is measured across the portfolio rather than per vendor, which is why a register of individually low-risk suppliers can still carry it.

Why vendor registers miss it

A register scores vendors one at a time. Concentration is a property of the set, so a portfolio in which every vendor is individually acceptable can still be one cloud region away from a bad afternoon. The exposure is invisible at the row level and obvious at the portfolio level, and most tooling only looks at rows.

It appears in three shapes. Vendor concentration — one supplier running several critical processes. Geographic concentration — multiple vendors in one region, jurisdiction or data centre. And fourth-party concentration, the one that actually bites: eleven vendors that look unrelated on the register and resolve to the same hosting provider, payment processor or identity platform underneath. That one is only visible if you map fourth-party relationships.

What regulators expect

For EU financial entities, DORA makes this explicit: firms must assess whether an ICT contract would lead to concentration before signing it, and the register of information exists partly so supervisors can see concentration across the sector that no single firm can see from inside its own register. The UK's critical third parties regime is built on the same observation — that systemic exposure sits with providers several firms share.

Practically, the reporting that matters is a portfolio view: critical processes by vendor, vendors by region, and vendors by shared fourth party. If you can only produce the first of the three, concentration is being managed on the basis of the exposure you can see.

Common questions

How is concentration risk measured?
By counting dependencies rather than scoring vendors: how many critical business services depend on one supplier, how many suppliers sit in one region or jurisdiction, and how many resolve to the same underlying provider. The useful output is a list of single points of failure, not a number.
What does DORA require on concentration risk?
In-scope financial entities must assess ICT concentration risk before entering a contract — including whether the arrangement involves a provider that is hard to substitute, and the cumulative effect of multiple contracts with the same provider. The register of information supports supervisory oversight of concentration across firms.
Is concentration risk the same as vendor lock-in?
No, though they travel together. Lock-in is about the cost and difficulty of leaving a supplier. Concentration is about how much fails at once if that supplier does. A vendor can be easy to exit and still carry concentration risk if half your critical processes run through it today.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.