Skip to main content
Category: Resilience and Concentration

Redundancy

Simply put

In a supply chain and resilience context, redundancy means having more than one way to meet a need, such as a second supplier, an extra facility, or backup capacity, so that if one option fails, another can take over. The goal is to reduce the chance that a single failure disrupts the delivery of goods or services. Note that the word 'redundancy' also has an unrelated meaning in employment law (the elimination of a job role), which is a distinct concept not covered by this resilience-focused definition.

Formal definition

Redundancy, in the context of supply chain and operational resilience, refers to the deliberate provisioning of duplicate or excess capacity, suppliers, routes, systems, or components so that the loss of any single element does not necessarily halt a function or service. It is a mitigation strategy that addresses single points of failure and single-source dependency, and it is closely related to, but distinct from, diversification and concentration risk management. Redundancy typically reduces the likelihood or impact of disruption rather than eliminating risk; it carries cost and complexity trade-offs, may still leave residual risk (for example, where nominally separate suppliers share an upstream Nth-party dependency), and does not by itself constitute a business continuity or disaster recovery plan. The evidence packet provided does not contain supply-chain or engineering source material specific to this resilience usage; the definition above reflects the term's general resilience meaning and should be corroborated against recognized frameworks before authoritative use. The evidence provided defines only the separate employment-law sense of 'redundancy' (dismissal arising when an employer no longer needs a role), which practitioners should not conflate with the resilience concept.

Why it matters

Redundancy matters to third-party and supply chain risk practitioners because concentration is one of the most common ways a resilient-looking program fails in practice. When a critical good or service depends on a single supplier, facility, route, or system, the loss of that element can halt a function even if every other control is well designed. Redundancy is the deliberate response: provisioning more than one way to meet the same need so that a single failure does not necessarily become an outage. It reduces the likelihood or impact of disruption, but it does not eliminate risk, and treating it as a guarantee is a frequent error.

The value of redundancy depends heavily on whether the alternatives are genuinely independent. Two nominally separate suppliers may share an upstream Nth-party dependency, the same sub-tier manufacturer, the same logistics hub, or the same cloud region, so that a single event takes both offline at once. Practitioners should therefore treat redundancy as related to, but distinct from, diversification and broader concentration-risk management, and should verify independence rather than assume it. Redundancy also carries cost and complexity trade-offs that must be weighed against the risk tier of the function it protects.

A final note of caution specific to this term: 'redundancy' has an entirely separate and unrelated meaning in employment law, where it refers to a form of dismissal that arises when an employer no longer needs a role. That usage is jurisdiction-specific and governed by employment regulation, for example, UK guidance published by GOV.UK and Acas, and should not be conflated with the resilience concept described here.

Who it's relevant to

Resilience and business continuity teams
These teams use redundancy as one input to reducing single points of failure across suppliers, facilities, routes, and systems. They should treat it as a component of a broader continuity approach rather than a substitute for a business continuity or disaster recovery plan, and should test whether redundant options remain available under the same disruption scenario.
Procurement and supplier management
Procurement functions weigh the cost and complexity of maintaining secondary or backup suppliers against the risk tier of what those suppliers provide. Redundancy is closely tied to managing single-source dependency, but adding a second supplier only helps if it is genuinely independent of the first.
Third-party and concentration risk analysts
Analysts assessing concentration risk should verify that redundant suppliers or systems do not share an upstream Nth-party dependency that could fail simultaneously. Distinguishing redundancy from diversification and confirming true independence is central to judging whether stated redundancy meaningfully reduces exposure.
HR and legal readers (disambiguation)
Practitioners who encounter 'redundancy' in an employment context should note this is a separate, jurisdiction-specific concept referring to a form of dismissal when a role is no longer needed, as described in UK guidance from sources such as GOV.UK and Acas. It should not be confused with the resilience meaning covered by this entry.

Inside Redundancy

Backup and failover capacity
The provisioning of duplicate or standby resources, such as alternate suppliers, secondary facilities, or spare production capacity, that can assume load when a primary resource fails or becomes unavailable. In a third-party context this often means qualified alternate vendors kept in a ready state, though the readiness of such backups varies and may require lead time to activate.
Multi-sourcing and geographic diversification
The deliberate distribution of a given good, service, or capability across more than one supplier or across suppliers in different locations, so that a disruption affecting one does not remove the capability entirely. This is distinct from simply having more suppliers; it addresses correlated failure only when the alternatives are genuinely independent of the same underlying risks (for example, sharing an upstream tier or a common region).
Component-level versus system-level redundancy
Redundancy can be built at the level of an individual component (an alternate part or subcontractor) or at the level of an entire process or system (a parallel delivery pathway). Component redundancy does not necessarily protect against a system-level single point of failure if all paths still converge on one shared dependency.
Active-active versus active-standby configurations
Redundant capacity may run continuously in parallel (active-active), sharing load and providing immediate continuity, or remain in reserve until needed (active-standby), which is typically less costly but introduces activation delay. The chosen configuration affects how quickly continuity is restored and should be matched to the criticality and recovery objectives of the dependency.
Relationship to concentration and single points of failure
Redundancy is a primary control for reducing single points of failure and mitigating concentration risk and single-source dependency. It does not, by itself, eliminate concentration risk when apparent alternatives share a hidden common dependency at a lower supply tier (fourth-party or Nth-party), which limits visibility and can undermine the assumed independence of backups.

Common questions

Answers to the questions practitioners most commonly ask about Redundancy.

Is redundancy in a supply chain resilience context the same as workforce redundancy in employment law?
No. In the third-party and supply chain risk context, redundancy refers to the deliberate provisioning of duplicate or alternative capacity, suppliers, routes, or systems so that a function can continue if one element fails. This is distinct from the employment-law sense of redundancy, which concerns the elimination of a role or position. This glossary entry addresses the resilience meaning, not the workforce meaning, and the two should not be conflated when reading program documentation.
Does having redundancy mean an organization has eliminated concentration risk and single points of failure?
Not necessarily. Redundancy can reduce exposure to a single point of failure, but it does not automatically remove concentration risk or single-source dependency. Redundant suppliers may still rely on the same sub-tier provider, the same geographic region, or the same logistics corridor, reproducing the concentration at a lower tier. Redundancy is only effective to the extent the alternatives are genuinely independent; overlapping dependencies can leave the underlying risk in place despite the appearance of duplication.
How can an organization verify that a redundant supplier is genuinely independent rather than sharing hidden dependencies?
Verification typically involves mapping the redundant supplier's own upstream dependencies, geographic footprint, and shared infrastructure to identify common points with the primary supplier. Because visibility often diminishes beyond the first tier, this analysis may be incomplete, and self-reported information may lack independent validation. Where feasible, programs corroborate claims through documentation, site assessments, or Nth-party mapping, while recognizing that full independence is difficult to confirm.
How does redundancy relate to business continuity and disaster recovery planning?
Redundancy is often one enabling mechanism within business continuity and disaster recovery, but it is not synonymous with either. Business continuity concerns sustaining critical functions during disruption, while disaster recovery focuses more narrowly on restoring systems and data after an incident. Redundant capacity may support both, but plans still require defined triggers, roles, and tested procedures to convert available redundancy into an actual continued or restored operation.
How do organizations decide which relationships warrant redundant suppliers or capacity?
Decisions are typically driven by risk tiering and criticality, since maintaining redundancy carries cost and management overhead. In many programs, redundancy is prioritized for suppliers or components deemed critical to core operations, high in inherent risk, or difficult to substitute quickly. Lower-criticality relationships may be managed through other controls rather than duplicated capacity, depending on the organization's risk appetite.
What are the main limitations of relying on redundancy as a resilience control?
Redundancy has several known limitations. It may address only certain risk types while leaving financial, geopolitical, or ESG exposures unaddressed. Redundant arrangements can share hidden common dependencies, and validation of independence is constrained by limited visibility beyond the first tier. Maintained but untested redundancy may fail when activated, and point-in-time assessments of a backup supplier can become stale. Redundancy also adds cost and complexity, so it reduces rather than eliminates risk and works best alongside monitoring and other controls.

Common misconceptions

Adding more suppliers automatically creates effective redundancy.
Redundancy is effective only when the alternatives are genuinely independent of the same failure modes. Multiple suppliers that rely on a shared upstream tier, common facility, or single region remain exposed to correlated failure, so supplier count alone does not confirm resilience.
Redundancy eliminates the risk of disruption.
Redundancy reduces the likelihood and impact of certain disruptions but does not remove risk. Standby capacity may require activation time, may itself become unavailable, or may not cover all risk dimensions (for example, financial, geopolitical, or ESG exposure rather than just operational continuity).
Redundancy and business continuity are the same thing.
Redundancy is one control that supports continuity, but business continuity is a broader discipline covering plans, processes, and recovery objectives, and disaster recovery is narrower still. Redundant capacity contributes to these outcomes but is not equivalent to a continuity or recovery capability.

Best practices

Map dependencies beyond the first tier before assuming redundancy exists, because apparently independent suppliers may converge on a shared fourth-party or Nth-party dependency that reintroduces a single point of failure.
Match the redundancy configuration to the criticality of the dependency, reserving active-active arrangements for the most critical flows where activation delay is unacceptable and using active-standby where lead time is tolerable.
Validate that backup and failover capacity is actually available and can be activated within required timeframes, rather than treating a named alternate supplier as ready capacity without testing.
Assess whether diversification is genuine by checking for common regions, facilities, and upstream sources, so that multi-sourcing reduces correlated failure rather than only increasing supplier count.
Treat redundancy as one control within a broader resilience and continuity program, and confirm which risk dimensions it addresses and which (such as financial, geopolitical, or ESG exposure) it does not.
Reassess redundancy arrangements periodically, since supplier relationships, capacity, and shared dependencies change over time and point-in-time assumptions about backup availability can become stale.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps