Concentration Risk

Concentration risk arises when dependencies bundle onto a few points — one provider, one technology, one site, one region. A single failure then does not stay local; it hits several processes at once. In the ICT context it is one of the reasons the EU put critical third-party providers under supervision at European level.

RisikomanagementLast reviewed:

Concentration is not decided, it accumulates

Almost nobody chooses concentration. It grows because a provider that has performed well picks up further work, because a platform turns out to be convenient, because consolidation saves money. Each step is defensible on its own. The aggregate is rarely assessed at all. No meeting takes place at which someone proposes that six critical functions should sit with one supplier.

DimensionTypical form
Providerone provider carries several critical functions
Technologyone platform, product or protocol underneath many processes
Sitea data centre, operating location or region as a shared point of failure
Peopleknowledge of a critical system sits with a single person
Chaindifferent providers rely on the same upstream supplier
Customers and marketseconomic dependence on a small number of buyers

The form you cannot see

The hardest concentration to detect is the one a level down. Three formally independent providers can all sit on the same infrastructure, the same data centre or the same network operator. A two-provider strategy resting on a shared upstream supplier produces cost without producing independence. It also produces false comfort, which is worse, because it closes the question.

This is the fourth-party problem, and it is only tractable if subcontractors and their locations are part of the inventory in the first place. Without those details, concentration cannot be assessed, only guessed at.

Measure rather than estimate

Workable inputs are: the number and importance of critical functions per provider, how substitutable the service is in the market, the estimated time to migrate, the share of data holdings sitting with one provider, and whether a tested alternative exists at all. Those inputs produce a ranking, and a ranking grounds the discussion, even when it rests on estimates.

The decisive figure is rarely the provider's market share. What matters is how long a replacement would actually take. That number is uncomfortable precisely because it is the one nobody has measured.

The supervisory view

In financial services the subject is regulated. DORA, the EU regulation on digital operational resilience for the financial sector (Regulation (EU) 2022/2554), treats concentration among ICT providers as a subject of its own within third-party risk. ICT is the EU's term for information and communications technology; read it as your IT suppliers. Beyond that, the regulation establishes in Chapter V, Section II (Articles 31 to 44) an oversight framework for critical ICT third-party providers: providers whose failure would affect the financial sector as a whole are supervised at European level. The European Supervisory Authorities published a first list of such providers in November 2025.

The reasoning travels beyond financial services. Concentration is a risk even where every individual firm considers it manageable for itself, because the correlation only becomes visible in aggregate, and no single firm is positioned to see it.

What helps

  • Multiple providers where the service is genuinely interchangeable — but only where the independence reaches down into the upstream suppliers.
  • Portability as a requirement in selection and in the contract: open formats, documented interfaces, data returned in usable form.
  • Prepared exit strategies for the providers that carry the most weight.
  • Separated sites and transmission paths for infrastructure.
  • Deputising arrangements and documentation against concentration in people.

Concentration is not always a mistake

One very good provider can be safer than four mediocre ones, and multi-provider strategies create risks of their own: more interfaces, more access paths, uneven security levels. The requirement is therefore not to avoid concentration but to know it, assess it, and take the decision deliberately with a named risk owner attached to it.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework