Concentration is not decided, it accumulates
Almost nobody chooses concentration. It grows because a provider that has performed well picks up further work, because a platform turns out to be convenient, because consolidation saves money. Each step is defensible on its own. The aggregate is rarely assessed at all. No meeting takes place at which someone proposes that six critical functions should sit with one supplier.
| Dimension | Typical form |
|---|---|
| Provider | one provider carries several critical functions |
| Technology | one platform, product or protocol underneath many processes |
| Site | a data centre, operating location or region as a shared point of failure |
| People | knowledge of a critical system sits with a single person |
| Chain | different providers rely on the same upstream supplier |
| Customers and markets | economic dependence on a small number of buyers |
The form you cannot see
The hardest concentration to detect is the one a level down. Three formally independent providers can all sit on the same infrastructure, the same data centre or the same network operator. A two-provider strategy resting on a shared upstream supplier produces cost without producing independence. It also produces false comfort, which is worse, because it closes the question.
This is the fourth-party problem, and it is only tractable if subcontractors and their locations are part of the inventory in the first place. Without those details, concentration cannot be assessed, only guessed at.
Measure rather than estimate
Workable inputs are: the number and importance of critical functions per provider, how substitutable the service is in the market, the estimated time to migrate, the share of data holdings sitting with one provider, and whether a tested alternative exists at all. Those inputs produce a ranking, and a ranking grounds the discussion, even when it rests on estimates.
The decisive figure is rarely the provider's market share. What matters is how long a replacement would actually take. That number is uncomfortable precisely because it is the one nobody has measured.
The supervisory view
In financial services the subject is regulated. DORA, the EU regulation on digital operational resilience for the financial sector (Regulation (EU) 2022/2554), treats concentration among ICT providers as a subject of its own within third-party risk. ICT is the EU's term for information and communications technology; read it as your IT suppliers. Beyond that, the regulation establishes in Chapter V, Section II (Articles 31 to 44) an oversight framework for critical ICT third-party providers: providers whose failure would affect the financial sector as a whole are supervised at European level. The European Supervisory Authorities published a first list of such providers in November 2025.
The reasoning travels beyond financial services. Concentration is a risk even where every individual firm considers it manageable for itself, because the correlation only becomes visible in aggregate, and no single firm is positioned to see it.
What helps
- Multiple providers where the service is genuinely interchangeable — but only where the independence reaches down into the upstream suppliers.
- Portability as a requirement in selection and in the contract: open formats, documented interfaces, data returned in usable form.
- Prepared exit strategies for the providers that carry the most weight.
- Separated sites and transmission paths for infrastructure.
- Deputising arrangements and documentation against concentration in people.
Concentration is not always a mistake
One very good provider can be safer than four mediocre ones, and multi-provider strategies create risks of their own: more interfaces, more access paths, uneven security levels. The requirement is therefore not to avoid concentration but to know it, assess it, and take the decision deliberately with a named risk owner attached to it.