Vendor Concentration Risk
43% Revenue through One Vendor. 67% Infrastructure: One Provider. 81% Support: One Platform. Each Green. Together: Existential.
4 min read · 3 May 2026 · Third-party oversight
Vendor concentration risk is the portfolio-level risk that accumulates when a disproportionate share of critical functions, revenue, or operations depends on a single vendor or a small number of vendors. Individual vendor assessments that confirm each vendor's security controls are adequate do not surface concentration risk , because concentration risk is not a property of any individual vendor but of the relationship between the portfolio of vendors and the enterprise's ability to sustain operations if one of them fails, is breached, or becomes unavailable. An enterprise that has confirmed each of its vendors is individually well-secured may still have a portfolio-level concentration risk that could disable operations through a single third-party disruption.
The accumulation mechanism is the challenge. Vendor concentration does not typically result from a single decision to consolidate. It accumulates over time through individually rational decisions , expanding with a vendor who has proven reliable, consolidating similar services onto a single platform for operational efficiency, growing with a vendor who offers better pricing at scale. Each of these decisions makes sense in isolation. Cumulatively they can create a concentration that no individual decision-maker was responsible for and that no individual vendor assessment identified.
The correlated failure risk is the specific supply chain dimension. Vendor concentration creates correlated failure risk , the risk that multiple enterprise functions are disrupted simultaneously by a single vendor event rather than independently. An enterprise whose cloud infrastructure, development tools, and analytics platform all run on the same hyperscaler faces a simultaneous disruption of all three if that hyperscaler experiences an outage. The individual vendor assessments confirmed each service was well-managed. They did not identify that the three services would fail together.
Why this matters
Vendor concentration risk matters because it is a portfolio property that individual vendor assessments are structurally unable to identify , it requires aggregating data across the vendor portfolio to measure. DORA's concentration risk requirements make this an explicit regulatory obligation for financial institutions , requiring organisations to identify and manage dependencies on single ICT providers that create systemic risk. For enterprises outside financial services, the business continuity and operational resilience implications are equivalent even without the regulatory mandate.
- Individual vendor assessments without portfolio-level concentration analysis
- Revenue concentration not measured , percentage of revenue through each vendor
- Infrastructure concentration not measured , percentage of operations on each provider
- Correlated failure risk not identified , shared provider across multiple services
- Accumulation not tracked , concentration growing through individually rational decisions
What good looks like
Mature vendor concentration risk programmes measure concentration at the portfolio level , tracking what percentage of critical functions, revenue, or infrastructure depends on each vendor or provider, identifying thresholds above which concentration is considered material, and building concentration reduction plans for vendors that exceed those thresholds.
- Concentration measurement by function , revenue, infrastructure, support, data processing
- Concentration thresholds defined , percentage above which review is required
- Alternative vendor readiness for highest-concentration relationships
- Correlated failure mapping , which services would fail together if a shared provider failed
- Concentration trend tracking , measuring whether concentration is growing or reducing
Tooling
Concentration Analysis , TPRM platforms with portfolio analytics; manual concentration mapping in GRC systems
Portfolio-level concentration analysis requires aggregating vendor data across the TPRM programme , something most TPRM platforms can support through reporting and analytics if the data model captures vendor function and business impact alongside security posture. The concentration report is a portfolio view that requires combining vendor assessment data with business impact data from the vendor inventory.
Governance challenges
The governance challenge with vendor concentration risk is the business case for diversification. Reducing concentration often means moving some business away from a well-performing vendor to an alternative who has not yet proven equivalent value. The governance resolution is framing concentration risk in business continuity terms rather than security terms , the question is not whether the concentrated vendor is secure but whether the enterprise could sustain operations if the concentrated vendor became unavailable.
- Measure concentration annually , revenue, infrastructure, and function concentration by vendor
- Define concentration thresholds requiring review and remediation planning
- Build alternative vendor readiness for highest-concentration relationships
- Report concentration metrics to senior leadership alongside individual vendor risk ratings
- Include concentration reduction in business continuity planning
If you are a small team
Build a concentration matrix: list your top ten vendors by spend or criticality, and for each one estimate what percentage of a critical function , revenue processing, infrastructure, customer support, data management , they represent. Any vendor above 40% in a critical function is a concentration risk worth documenting and discussing with leadership. That matrix takes a day to build and surfaces the portfolio-level risk that individual assessments do not.
- Build top ten vendor concentration matrix by critical function
- Identify vendors above 40% concentration in any critical function
- Document concentration risk for leadership review
- Build alternative vendor readiness plan for highest-concentration relationships
What to require
Ask directly:
"What percentage of your own critical operations depend on your largest single provider , and what is your business continuity plan if that provider experiences a significant outage or security incident?"
Expect as evidence
- Vendor's own concentration risk assessment
- Business continuity plan for largest provider failure
- Alternative provider readiness for critical functions
- Concentration trend and management plan
A vendor who confirms acceptable risk ratings should be asked about their own concentration risk. Their concentration in critical providers is the fourth-party concentration risk that their individual security posture does not address.
How to evidence it
- Concentration measurement records
- Concentration threshold documentation
- Alternative vendor readiness assessment
- Concentration reporting to leadership
Key Takeaway
43% of revenue through one vendor. 67% of infrastructure on one provider. 81% of support through one platform. Each individually assessed, each green. Three single-vendor failures , independently occurring , each capable of operational crisis. The concentration accumulated through individually rational decisions that no single decision-maker was responsible for and no individual assessment identified. Concentration is a portfolio property. Individual vendor assessments measure individual vendor risk. Portfolio concentration measurement identifies the aggregate risk that the individual assessments cannot surface. Concentration thresholds trigger review. Alternative vendor readiness provides the exit. Together they manage the risk that accumulates one good vendor decision at a time.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association