Vendor Concentration and Dependency

Understand where the technology estate is concentrated.

Concentration is a structural fact about the estate, not a prediction. This decision area documents where spend and critical capability sit with a small number of vendors, which dependencies lack an alternative, and what the contracts actually provide.

Questions this decision area addresses

  • Which vendors support business-critical functions?

  • Where is spend or capability concentrated in a small number of vendors?

  • Which dependencies have no practical alternative currently in place?

  • What contractual protections, service levels, and exit terms apply?

  • Which dependencies would be difficult to unwind, and for what reason?

  • What does the risk committee or board need to see on this?

Typical inputs

  • Vendor list with spend and category

  • Contract terms, service levels, and exit provisions

  • Application-to-vendor mapping

  • Business criticality designation by function

  • Integration and data-flow dependencies

  • Existing risk register entries

Resulting outputs

  • Concentration view by spend and by critical function

  • Identification of dependencies with no alternative currently in place

  • Summary of contractual protections and exit terms

  • Dependency map showing what would be difficult to unwind

  • Risk items framed for the risk committee or board

  • Assumptions and data-quality disclosures

Scope and limitations

This decision area documents concentration and dependency structure from your contract, spend, and application data. It is not a security assessment, a penetration test, or a vendor financial-health rating, and it does not predict whether a specific vendor will fail.

TekLedger assembles the concentration and dependency view. Risk, security, and procurement owners review it, add context from their own assessments, and decide which items warrant mitigation before anything is presented to a risk committee or board.