Concentration risk, when the register hides a single point of failure
Concentration risk is the exposure created when too much depends on one thing: a single vendor, a single region, or one underlying provider that many of your vendors quietly share. It is measured across the portfolio rather than per vendor, which is why a register of individually low-risk suppliers can still carry it.
Why vendor registers miss it
A register scores vendors one at a time. Concentration is a property of the set, so a portfolio in which every vendor is individually acceptable can still be one cloud region away from a bad afternoon. The exposure is invisible at the row level and obvious at the portfolio level, and most tooling only looks at rows.
It appears in three shapes. Vendor concentration — one supplier running several critical processes. Geographic concentration — multiple vendors in one region, jurisdiction or data centre. And fourth-party concentration, the one that actually bites: eleven vendors that look unrelated on the register and resolve to the same hosting provider, payment processor or identity platform underneath. That one is only visible if you map fourth-party relationships.
What regulators expect
For EU financial entities, DORA makes this explicit: firms must assess whether an ICT contract would lead to concentration before signing it, and the register of information exists partly so supervisors can see concentration across the sector that no single firm can see from inside its own register. The UK's critical third parties regime is built on the same observation — that systemic exposure sits with providers several firms share.
Practically, the reporting that matters is a portfolio view: critical processes by vendor, vendors by region, and vendors by shared fourth party. If you can only produce the first of the three, concentration is being managed on the basis of the exposure you can see.
Common questions
How is concentration risk measured?
What does DORA require on concentration risk?
Is concentration risk the same as vendor lock-in?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.