Skip to main content
Category: Resilience and Concentration

ICT Concentration Risk

Also known as: ICT Third-Party Concentration Risk
Simply put

ICT concentration risk is the danger that arises when a financial entity, or the financial sector as a whole, depends too heavily on a single information and communication technology (ICT) provider or a small number of them. If that provider fails or its services are disrupted, the effects can be difficult to absorb because there are few or no easy alternatives. In some cases, this dependency is significant enough to raise concerns not just for one firm but for the wider financial system.

Formal definition

ICT concentration risk refers to the exposure created when a financial entity, or the financial sector collectively, is excessively reliant on a single or limited number of ICT third-party service providers, particularly where such providers are not easily substitutable. Under the Digital Operational Resilience Act (DORA), it is addressed both at the entity level, through a preliminary assessment considering factors such as substitutability of the provider, and at a systemic level, where the oversight framework targets concentration risks stemming from the sector's reliance on a limited pool of critical ICT providers. It is distinct from broader single-source dependency or single-point-of-failure concerns in that it is framed specifically around ICT third-party relationships and their aggregation across entities; DORA-related work has explored quantitative approaches using Register of Information (RoI) data to measure it. This term addresses the dependency and substitutability dimension of ICT sourcing and does not by itself cover the full range of operational, financial, or geopolitical risks associated with a given provider, nor does identifying it constitute a mitigation control.

Why it matters

ICT concentration risk matters because the resilience of a financial entity, and potentially the wider financial sector, can hinge on providers that are not easily substitutable. When many firms rely on the same limited pool of ICT third-party service providers, a disruption at one provider can propagate across multiple entities simultaneously, making the effects harder to absorb precisely because alternatives are scarce or slow to stand up. This is why the concern is framed not only at the level of an individual firm but also systemically, where aggregated reliance on a small number of critical providers becomes a supervisory issue in its own right.

Who it's relevant to

Third-party risk and procurement teams at financial entities
These teams are responsible for the entity-level preliminary assessment DORA envisions, including judging whether a prospective ICT provider is easily substitutable. Their evaluation feeds contracting and, where relevant, exit planning decisions, though the substitutability assessment addresses only the concentration dimension and does not by itself cover the full range of provider risks.
Operational resilience and compliance functions
Functions tasked with DORA readiness must integrate concentration considerations into how they document and monitor ICT third-party relationships. Because concentration can build up across many contracts over time, this is not a one-off exercise, and identifying it does not on its own reduce the underlying dependency.
Supervisors and systemic risk analysts
Under the DORA oversight framework, supervisors focus on concentration risks arising from the financial sector's reliance on a limited number of ICT providers. Quantitative work has explored using Register of Information (RoI) data to measure such concentration, supporting a sector-wide view that goes beyond any single firm's exposure.

Inside ICT Concentration Risk

Provider-level concentration
Dependence on a limited number of information and communication technology (ICT) providers such that disruption to one provider could materially affect multiple critical services. This includes cloud service providers, managed service providers, and other outsourced technology vendors on which the organization directly relies.
Service and function concentration
Reliance on the same underlying ICT service, platform, or function across many business processes, so that an outage of that single service disrupts several activities at once. This is distinct from provider-level concentration because the same provider may deliver multiple services, or several providers may depend on the same underlying function.
Nth-party and shared-dependency concentration
Concentration that arises below the direct contractual tier, where multiple third parties themselves rely on a common fourth-party or lower-tier ICT provider. Visibility into this layer is typically limited, and concentration at this level may not appear in first-tier assessments.
Geographic and infrastructure concentration
Clustering of ICT capacity in a shared physical location, data center region, or network path, such that a localized event could affect otherwise separate providers or services. This dimension addresses the physical and logistical layer rather than only the contractual relationship.
Substitutability constraints
The degree to which a concentrated ICT provider or service can be replaced within an acceptable timeframe. Where switching costs, technical lock-in, or a scarcity of alternative providers are high, concentration risk is more severe because remediation options are constrained.

Common questions

Answers to the questions practitioners most commonly ask about ICT Concentration Risk.

Is ICT concentration risk the same as having a single point of failure in your technology stack?
No. These are related but distinct concepts. A single point of failure refers to one component, system, or node whose failure would disrupt an entire process or service. ICT concentration risk is broader and describes the risk that arises when an organization, or a wider market, relies heavily on a limited number of ICT providers, technologies, or service concentrations, such that a disruption at one provider affects many functions or many firms at once. A single point of failure may exist without meaningful concentration, and concentration can create systemic exposure even where individual redundancies exist. It is also worth distinguishing both from single-source dependency, which describes reliance on one supplier for a specific input or service.
If we spread our workloads across multiple regions of the same cloud provider, have we addressed our ICT concentration risk?
Not necessarily. Distributing across regions or availability zones of a single provider can improve resilience against localized outages, but it typically does not reduce concentration at the provider level. If the concentration stems from dependence on one provider's control plane, identity services, contractual relationship, or corporate viability, multi-region deployment within that same provider leaves that concentration largely intact. Provider-level concentration and geographic or infrastructure-level redundancy are different dimensions, and addressing one does not automatically address the other.
How can an organization begin to identify where ICT concentration risk exists in its provider landscape?
In many programs, identification starts with mapping ICT dependencies beyond the first tier, since concentration often emerges at the fourth-party or Nth-party level where multiple direct providers rely on a common underlying platform or subcontractor. This typically involves inventorying critical services, the providers supporting them, and the shared technologies or infrastructure beneath those providers. A common limitation is visibility: organizations frequently have reasonable insight into direct providers but reduced clarity into downstream dependencies, so mapping may remain incomplete depending on the disclosures suppliers are willing or contractually required to provide.
What role do contractual provisions play in managing ICT concentration risk?
Contractual provisions can support concentration risk management by seeking disclosure of a provider's own material subcontractors and dependencies, rights to information on resilience arrangements, exit and portability terms, and notice of significant changes. However, contract terms address information and obligations rather than the underlying market structure; they do not, on their own, reduce the fact that many firms may depend on the same provider. Depending on jurisdiction and sector, regulatory expectations around exit strategies and subcontractor transparency vary, so contractual approaches should be aligned with the applicable regime rather than assumed to be uniform.
How should ICT concentration risk factor into risk tiering and monitoring?
In many programs, providers or services associated with higher concentration are placed in higher risk tiers, which can drive more frequent monitoring, deeper due diligence, and closer resilience scrutiny. Because concentration exposure can shift as providers acquire competitors, as adoption of a shared platform grows, or as the organization's own dependencies change, point-in-time assessments can become stale. Ongoing monitoring rather than onboarding review alone is therefore typically needed to detect emerging concentration, though the effectiveness of monitoring depends on the visibility available into downstream dependencies.
What are the practical limits of trying to reduce ICT concentration through diversification?
Diversifying across providers can lower concentration in principle, but it carries practical constraints. Substitutes may be limited where few providers offer a given capability at required scale, migration and integration costs can be significant, and adding providers can introduce its own operational and security complexity. Diversification may also be partial if multiple candidate providers themselves rely on a common underlying technology or subcontractor, in which case apparent diversity does not remove the shared dependency. For these reasons, diversification is generally one option weighed alongside resilience measures and exit planning, rather than a complete remedy, and it does not eliminate concentration risk.

Common misconceptions

ICT concentration risk is the same as having a single-source dependency or a single point of failure.
These are related but distinct. A single-source dependency refers to reliance on one supplier for a given service; a single point of failure is a specific component whose failure halts a process. ICT concentration risk is broader, describing aggregated exposure where many services, functions, or even multiple providers converge on a limited set of ICT providers, services, or locations. Concentration can exist even where nominal alternatives are contracted, if they share the same underlying dependency.
Using several different vendors eliminates ICT concentration risk.
Multiple direct vendors do not necessarily reduce concentration if those vendors rely on the same underlying cloud platform, data center region, or lower-tier provider. Concentration frequently reappears at the Nth-party or infrastructure level, where visibility is typically limited and first-tier due diligence may not surface it.
A point-in-time assessment confirming diversified providers resolves concentration concerns.
Concentration exposure changes as providers, architectures, and lower-tier dependencies evolve, so a point-in-time view can become stale. Assessments also often do not extend beyond the first tier, meaning shared dependencies below the direct relationship may go undetected without ongoing monitoring.

Best practices

Map concentration across multiple dimensions, provider, service or function, geographic or infrastructure location, and Nth-party dependencies, rather than assessing only the count of direct vendors.
Seek visibility into lower-tier and shared dependencies where feasible, recognizing that first-tier due diligence typically does not reveal common fourth-party or infrastructure-level convergence.
Evaluate substitutability for concentrated ICT providers and services, including switching costs, technical lock-in, and the availability of alternatives, to gauge how quickly exposure could be remediated.
Treat concentration as a monitored condition rather than a one-time finding, since provider architectures and lower-tier dependencies change and point-in-time assessments become stale.
Prioritize scrutiny by criticality and risk tier, focusing on ICT dependencies that support multiple critical services or processes where a single disruption would have aggregated impact.
Document the scope and known limitations of any concentration analysis explicitly, noting where visibility beyond the first tier is incomplete and which risk dimensions the assessment does not cover.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps