Vendor and Third-Party Concentration Risk

Concentration risk is the exposure regulators worry about most and firms understand least. It is not simply “we depend on a big vendor”; it is the systemic fragility that builds up when many critical functions rest on a small number of providers — and when the apparent diversification of using two vendors turns out to be an illusion because both sit on the same underlying infrastructure. This theme recurs across DORA, CSSF guidance and PRA expectations precisely because it is where a single failure can take down more than anyone planned for.

Why firms underestimate it

The common mistake is to measure concentration at the contract level. A firm sees that it uses two cloud providers, two data vendors, two payment processors, and concludes it is diversified. But concentration lives deeper. Two “different” services may both run on the same hyperscaler. A provider you depend on may itself depend on a fourth party that you never see and never assessed. The failure that matters is often not your direct provider’s but the shared dependency underneath several of them — the fourth-party concentration that a contract-level view is blind to. Genuine assessment means mapping not just who you pay, but what they depend on.

What the regulators actually expect

Across the regimes, the expectations converge on a few demands. Know your critical dependencies, including the ones behind your direct providers. Assess your concentration against a defined risk appetite, rather than noting it exists. Maintain the contractual rights — audit, information, exit — that let you act on what you find. And hold a tested exit or substitution plan for critical arrangements, because concentration only becomes tolerable if you can actually move. The EU’s designation of critical ICT third-party providers under DORA formalised what firms already suspected: the sector clusters on a handful of providers, and supervisors now expect each firm to understand and mitigate its own piece of that.

Free · 4 minutes

Do you know what could take the business down — and have you priced it?

Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.

Turning the assessment into something useful

  • Map to the fourth party. Your dependency picture is incomplete until it includes what your providers depend on. This is where the real concentration hides.
  • Assess against appetite, not in the abstract. “We are concentrated” is not a finding; “our critical trading function depends on a single provider with no tested alternative, which exceeds our stated tolerance” is.
  • Fix the contracts. Concentration you cannot exit is worse than concentration you can; audit and exit rights are what convert a dependency into a managed risk.
  • Test substitution. A plan to move that has never been exercised is a document. The value is in knowing you could, within the time your tolerance allows.

Concentration risk is a board-level exposure because it is systemic and often invisible from inside a single contract. The firms that manage it well map their dependencies to the fourth party, assess them against a real appetite, and can demonstrate they could move — which is exactly the trio a supervisor now expects to see.

Who this is for

This reading is for:

  • Risk owners and CTOs mapping third-party dependencies
  • Boards asked whether the firm is over-reliant on a few providers
  • Compliance leads across DORA, CSSF and PRA third-party expectations
  • Firms that assume using two providers means they are diversified

Sixteen Pillars maps your dependencies to the fourth party, assesses concentration against a real risk appetite, and tests whether you could actually move. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming