Single-Provider Dependency
Single-provider dependency exists when an organization relies on one supplier, platform, or service provider for a critical product, service, or capability. Because there is no readily available alternative, any disruption, failure, or unfavorable change at that provider can directly affect the organization. This dependency is often accepted as a trade-off for convenience, integration, or cost, but it concentrates risk in a single external relationship.
Single-provider dependency describes a condition in which a critical product, service, platform, or transport path relies on a single supplier, region, or channel, leaving the dependent organization exposed to that provider's availability, performance, and commercial decisions. In cloud and platform contexts it is closely associated with vendor lock-in, where accumulated switching costs, technical coupling, and ecosystem integration make migration to an alternative provider difficult or economically impractical. This term addresses the concentration of reliance on one provider and should be distinguished from single point of failure (a specific technical or process node whose failure halts a system) and from broader concentration risk across multiple providers; the presence of dependency does not by itself specify whether financial, operational, security, geopolitical, or ESG exposures are being evaluated, nor does it indicate whether alternatives, exit plans, or ongoing monitoring are in place. Depending on the program and risk tier, mitigations may include contingency arrangements, multi-provider strategies, or exit and portability planning, but the evidence here does not establish the effectiveness of any specific control.
Why it matters
Single-provider dependency concentrates an organization's exposure in one external relationship, so a disruption, failure, or unfavorable commercial change at that provider can flow directly through to the dependent organization with limited ability to substitute an alternative. Because the dependency is frequently accepted as a trade-off for convenience, integration, or cost, it can accumulate quietly until a provider outage, price change, or policy shift forces the issue. As commentary in this space has noted, the trade-off for platform convenience is dependency, and enterprises are increasingly being pressed to reassess how much reliance on a single provider or platform they are willing to accept.
In cloud and platform contexts the exposure is compounded by vendor lock-in, where accumulated switching costs, technical coupling, and ecosystem integration make migration to an alternative provider difficult or economically impractical. Analyses of cloud vendor lock-in describe how switching costs and platform dependency economics form over time, and how an organization can become so dependent on one provider that changing becomes hard to justify. This means the practical cost of a single-provider dependency is often not visible at onboarding but instead materializes later, when an exit or diversification would otherwise be warranted.
It is important not to overstate what this term establishes. The presence of a dependency does not by itself specify which risk dimension, financial, operational, security, geopolitical, or ESG, is being evaluated, nor does it indicate whether alternatives, exit plans, or ongoing monitoring exist. Single-provider dependency should also be distinguished from a single point of failure, which is a specific technical or process node, and from broader concentration risk spread across multiple providers. Whether the dependency represents an acceptable trade-off or an unmanaged vulnerability depends on the program, the risk tier, and the controls in place.
Who it's relevant to
Inside Single-Provider Dependency
Common questions
Answers to the questions practitioners most commonly ask about Single-Provider Dependency.
