Vendor Concentration and Dependency
Understand where the technology estate is concentrated.
Concentration is a structural fact about the estate, not a prediction. This decision area documents where spend and critical capability sit with a small number of vendors, which dependencies lack an alternative, and what the contracts actually provide.
Questions this decision area addresses
Which vendors support business-critical functions?
Where is spend or capability concentrated in a small number of vendors?
Which dependencies have no practical alternative currently in place?
What contractual protections, service levels, and exit terms apply?
Which dependencies would be difficult to unwind, and for what reason?
What does the risk committee or board need to see on this?
Typical inputs
Vendor list with spend and category
Contract terms, service levels, and exit provisions
Application-to-vendor mapping
Business criticality designation by function
Integration and data-flow dependencies
Existing risk register entries
Resulting outputs
Concentration view by spend and by critical function
Identification of dependencies with no alternative currently in place
Summary of contractual protections and exit terms
Dependency map showing what would be difficult to unwind
Risk items framed for the risk committee or board
Assumptions and data-quality disclosures
Scope and limitations
This decision area documents concentration and dependency structure from your contract, spend, and application data. It is not a security assessment, a penetration test, or a vendor financial-health rating, and it does not predict whether a specific vendor will fail.
TekLedger assembles the concentration and dependency view. Risk, security, and procurement owners review it, add context from their own assessments, and decide which items warrant mitigation before anything is presented to a risk committee or board.