All resources
Third-Party Risk8 min read

Concentration risk: seeing the providers behind your providers

Direct provider diversity can hide substantial concentration one layer down. Several independent SaaS providers frequently run in the same cloud region, use the same identity provider or depend on the same payment infrastructure.

Tomas Lindqvist · Principal, ICT Risk

Collect the chain where it matters

Mapping every subcontractor of every provider is not realistic or useful. Focus on subcontractors that effectively support a critical or important function, which is also where DORA requires visibility and contractual conditions.

Ask for the chain in the assessment

The reliable source for subcontracting information is the vendor questionnaire, asked as structured fields: entity name, country, service provided, data location, and whether the subcontractor supports the critical part of the service.

Free-text answers produce information you cannot aggregate. Structured answers produce a graph you can query.

Look for the patterns that matter

Once the chain is structured, useful views appear: providers per underlying infrastructure, functions dependent on a single fourth party, data locations outside the EU, and providers that would be difficult to substitute within your tolerated downtime.

  • Shared infrastructure across nominally independent providers
  • Single fourth parties supporting several critical functions
  • Data processing locations outside your stated boundaries
  • Substitutability against maximum tolerable downtime

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.