ICT third-party management
ICT concentration risk: spotting it before the regulator does
When several critical functions depend on one provider, DORA calls it concentration risk. How to identify it, including cascading subcontracting.

The register of information is not a simple inventory of providers. Its purpose, from the supervisor's point of view, is notably to reveal concentration risk: situations where too much rests on too few players. It is an angle the ACPR examines explicitly from submitted registers, and a point many entities overlook because it does not jump out when you look at your providers one by one.
What is concentration risk?
DORA requires identifying cases where several critical or important functions depend on the same provider, or on a limited number of providers. The logic is intuitive: if a single player supports valuation, regulatory reporting and the hosting of your data, its failure does not affect one function, but several simultaneously. The risk is not additive, it is systemic at the scale of your entity.
This concern goes beyond each entity's framework. The European authorities aggregate registers to identify critical ICT third-party providers (CTPPs) — typically the large cloud hyperscalers — whose failure would threaten the entire financial sector. Your individual concentration analysis feeds this macro view.
Why it escapes classic analysis
The problem with concentration is that it is invisible in a line-by-line reading. Each contract, taken in isolation, can seem under control. It is by cross-referencing providers with the functions they support that the pattern appears. And it is precisely this cross-referencing that separate files do not easily allow: the contract is in one spreadsheet, the function mapping in another, and no one naturally makes the join.
The three forms of concentration to watch
Direct concentration. The same provider supports several of your critical functions. The most visible case — and yet often not formalised.
Sectoral concentration. You appear diversified, but your different providers all rely, in the background, on the same hyperscaler. Surface diversity masks a deep dependence.
Concentration via cascading subcontracting. The most insidious. Your direct provider itself subcontracts to a player who ends up, without your knowing, at the convergence point of several of your chains. DORA explicitly requires the analysis to cover this cascading subcontracting — which implies visibility beyond your first tier of suppliers.
What the regulator expects
The ACPR uses registers to assess the mapping of interdependencies and concentration risk. Concretely, it expects you to be able to:
- Identify your single points of dependence (provider-level single points of failure).
- Document the criticality of the functions attached to each provider.
- Extend the analysis to material subcontracting.
- Integrate this analysis into your risk management framework, rather than treating it as a separate exercise.
A register that lists providers without allowing this cross-referenced reading misses its reason for being.
How to structure your analysis
A few reflexes to make concentration visible:
- Systematically link provider ↔ function. Each critical function must point to the provider(s) supporting it, and vice versa.
- Map beyond the first tier. Inventory the material subcontractors of your direct providers.
- Visualise rather than list. A dependency map reveals the concentration nodes a table hides.
- Reassess regularly. Concentration evolves with every new contract or subcontracting change.
A stake that goes beyond compliance
Detecting your concentration is not just a regulatory obligation: it is strategic information. It informs your procurement decisions (should we diversify?), your crisis management (what happens if this node falls?), and your negotiations (what is your real level of dependence on this supplier?). Here, compliance coincides with better operational control.
Where Axenia fits in. Axenia maps your ICT dependencies by linking each provider to the functions it supports, highlights concentrations — including via subcontracting — and turns your register into a genuine risk map, readable at a glance rather than reconstructed by hand.
This article is educational in purpose and does not constitute legal advice. Refer to the official texts and your competent authority's guidance.
See how Axenia maps your concentrations. Book a demo →
