Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Vendor concentration risk chart showing dependence on a few critical suppliers

Vendor Concentration Risk: How to Assess It 2026

Vendor concentration risk is the danger that too much of your operation depends on a single supplier, or on a small group of suppliers that share a common weakness. A vendor assessment may show that each supplier is individually sound, yet the organisation is still exposed if one cloud provider, one payment processor or one software platform carries all its critical services. When that provider fails, everything fails together.

This guide explains the types of vendor concentration risk, how to measure it, how to set thresholds and what you can do about it, including the expectations that financial regulators now place on firms.

What vendor concentration risk means

Concentration can arise in several ways. It appears when a single vendor supplies many services, when many critical functions rely on one technology, when several vendors depend on the same upstream provider, or when suppliers are located in one region exposed to the same hazard. The common feature is a shared point of failure that individual assessments do not reveal, because each one looks at a vendor in isolation. Our guide to third-party risk assessment covers the individual view, and this article covers the portfolio view.

Free third-party risk assessment

How much risk does this vendor bring?

Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.

Start the free vendor risk assessment →  or  View premium report sample

Types of vendor concentration risk

TypeDescriptionExample
Single-vendorMany services depend on one supplierOne provider hosts ERP, email and storage
Single-serviceOne critical function has only one supplierOnly one payment gateway is integrated
GeographicSuppliers share one region or data centre areaThree vendors all in one flood zone
Fourth-partyDifferent vendors rely on the same sub-supplierSeveral SaaS tools run on the same cloud
TechnologyReliance on one platform, protocol or productAll authentication passes through one identity provider
Contractual or exitLock-in makes leaving impracticalProprietary data format, no export

Fourth-party concentration is the least visible. Our guide to fourth-party risk explains how to ask suppliers about their own dependencies.

Regulatory context for vendor concentration risk

Financial regulators have made concentration a named topic. The EU Digital Operational Resilience Act, Regulation (EU) 2022/2554, requires financial entities to carry out a preliminary assessment of ICT concentration risk at entity level before entering into contractual arrangements, in Article 29. The regulation is available on EUR-Lex. It also creates an oversight framework for critical ICT third-party providers; see our guide to critical ICT third-party providers. Other regimes, such as US interagency guidance on third-party relationships, ask banks to consider concentration in their risk management; see the overview of the interagency guidance on third-party relationships. Whether or not you are regulated, the logic applies to any organisation with critical suppliers.

How to measure vendor concentration risk

Map dependencies

Start with the critical business services and list the vendors, systems and locations each one depends on. A simple matrix with services in rows and vendors in columns quickly shows where many services pile up on the same supplier. Extend it with fourth parties where you have the information.

Choose measures

Useful measures include the share of critical services that rely on each vendor, the share of spend and transactions with the top three vendors, the number of critical services with a single supplier and no alternative, the number of critical vendors in one region and the percentage of critical vendors with a tested exit plan. Track them over time so leaders see the direction of travel.

Rate the impact

Combine dependency with impact: how long could the services tolerate an outage, what would it cost, and how quickly could you switch? A vendor that supports a service with a four-hour tolerance and takes six months to replace represents a much higher concentration risk than one supporting a service with a month’s tolerance and a ready alternative.

Setting thresholds for vendor concentration risk

Decide in advance what level of dependency is acceptable. Thresholds might say that no single vendor should support more than a stated share of critical services without a documented and tested exit plan, that critical services must not depend on a single region without a recovery option, or that any single-supplier critical function needs board-level acceptance. The numbers should reflect your risk appetite, and be reviewed regularly. Our guide to risk appetite explains how to set them.

Mitigating vendor concentration risk

There are several ways to reduce concentration, each with costs.

  • Diversify. Use a second supplier for critical functions, in a hot or warm standby arrangement.
  • Architect for portability. Use open standards, containers and data export so that switching is possible.
  • Contract for resilience. Include service levels, incident notification, audit rights, transition assistance and step-in rights.
  • Plan the exit. Prepare and test an exit plan for each critical vendor, including data return and migration.
  • Hold contingency. Keep manual workarounds, spare capacity or stock for the most critical functions.
  • Accept knowingly. Where diversification is impractical or too costly, a senior person accepts the risk in writing with compensating controls.

Diversification is not free. A second supplier increases cost and complexity, and two vendors that share the same underlying cloud provide less resilience than they appear to. Assess whether the alternatives are truly independent.

Testing exit and substitution

An exit plan on paper is not a capability. Test at least the critical steps: can you retrieve your data in a usable format, how long would migration take, who would do it, and what would it cost? Run a tabletop exercise where the primary provider is unavailable for a week. The findings often reveal hidden dependencies, such as a licence key or an identity link that only the failed vendor can provide. Our guide to the vendor offboarding checklist covers the end of a relationship.

Monitoring early warning signs

Watch for signals that a dependency is becoming more dangerous: a supplier’s acquisition by a competitor, financial stress, repeated outages, a change of hosting location, loss of key staff or a rise in the share of your services that use it. Set up alerts on news and supplier notices, and ask relationship owners to report changes at each quarterly review. Early notice gives you months, not days, to arrange an alternative.

A hypothetical example of vendor concentration risk

The following is a hypothetical example invented for illustration. A mid-sized insurer maps its ten critical services against 40 vendors. The matrix shows that seven critical services depend on one cloud platform either directly or through other software, and that both its claims system and its customer portal use the same identity provider. Three vendors listed as independent all run their platforms in one cloud region.

The board sets a threshold that no single provider may support more than half of critical services without a tested exit plan, and that authentication must have a fallback. The insurer adds a secondary identity provider in standby, negotiates data export and transition clauses with the cloud provider, and runs a regional failover test. Two services remain concentrated, and the board accepts the risk with quarterly monitoring. The exercise turned an unseen dependency into a managed one.

Common mistakes with vendor concentration risk

Typical weaknesses include assessing vendors only one at a time, ignoring fourth parties, treating hosting location as an IT detail, counting a second vendor that shares infrastructure as diversification, no thresholds, no exit plans or untested ones, forgetting that concentration in a payment or identity service can stop the whole business, and no reporting to the board. Another is discovering the concentration only during an outage.

Reporting vendor concentration risk

Show leaders a short view: the top dependencies, the services affected, the tolerance and exit time for each, the thresholds and any breaches, with actions and owners. A heat map of vendors against services is a clear way to display it. Update the view quarterly and after major supplier changes, and feed it into your vendor risk tiering so that concentrated suppliers are classed as critical.

Templates for vendor concentration risk

A structured report helps you capture dependencies, ratings and mitigation for each supplier in a consistent way. The Third-Party Risk Assessment Report and Workbook provides a report and register to document supplier assessments and actions. Whichever tool you use, keep the same fields across suppliers so that concentration can be analysed across the whole portfolio.

Vendor concentration risk FAQ

What is vendor concentration risk?

The risk that excessive dependence on one supplier, or several suppliers sharing a common weakness, causes serious disruption if that supplier or weakness fails.

Does DORA address concentration risk?

Yes. Article 29 requires financial entities to assess ICT concentration risk at entity level before entering into contractual arrangements, and the regulation also establishes oversight of critical ICT third-party providers.

Is using two vendors always safer?

No. If both rely on the same underlying provider or region, the benefit is limited. Check that alternatives are genuinely independent and that switching has been tested.

How do we measure it?

Map critical services to vendors, then measure the share of services per vendor, single-supplier functions, regional clustering and the percentage of critical vendors with tested exit plans.

Who should accept a concentration risk?

A senior person or committee with authority over the affected services, with a written rationale, compensating controls and an expiry date for the decision.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.