Glossary
Concentration risk
Concentration risk is the exposure created by an organisation's dependency on a small number of vendors, technologies or geographies, such that a single failure affects several essential activities at once.
Three distinct forms
| Form | Question to ask | Example |
|---|---|---|
| Vendor concentration | How many essential activities rely on the same third party? | One publisher covering payroll, HR and billing |
| Technology concentration | Do my alternatives share the same infrastructure? | Two SaaS hosted on the same cloud |
| Geographic concentration | Are my data and backups in the same region? | Production and backup in one region |
The second row is the costliest to detect: it only surfaces once vendor-declared dependencies are consolidated, that is at the fourth-party risk level.
What the regulator expects
DORA requires financial entities to explicitly assess concentration risk before using a critical ICT provider, and to keep a register of contractual arrangements allowing the authority to supervise that concentration at sector level. The expected analysis is therefore not purely internal: it must be documented and defensible. See the concentration and SPOF guide.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours