Third-Party & Concentration Risk
Too much riding on one supplier or one country? ReportAct calculates concentration risk deterministically from your supplier register — not estimated, but traceably derived and sealed as evidence.
Concentration risk you can actually trace.
The analysis groups your suppliers by service type and country and compares each cluster against configurable thresholds. When a cluster exceeds the threshold — say, too many critical suppliers concentrated in the same country or service category — a finding is created with method-level language: which suppliers are affected, which threshold was breached, what share of the register is involved.
The analysis also detects single points of failure: individual critical suppliers on which a disproportionate share of your core functions depend. The result appears directly in the interactive supply chain graph — with a risk marker on the affected node and an impact path traced back to your own organization.
Every concentration analysis is sealed as evidence and can be applied directly to the DORA Register of Information and to NIS2 and ISO 27001 controls — calculated once, reused across regimes.
What the concentration risk analysis delivers.
Cluster analysis by service type and country
Groups all suppliers automatically and compares each cluster against thresholds — a result with traceable methodology, not a black-box score.
Single-point-of-failure detection
Identifies individual critical suppliers on which a disproportionate share of core functions depend.
Interactive supply chain graph
Risk marker on the affected node, impact path to your own organization, zoomable with a criticality traffic light.
Sealed evidence
Every analysis is cryptographically sealed and remains provable as the state at a given point in time — even after later register changes.
Applies across multiple regimes
Feeds DORA Art. 29, NIS2 Art. 21(2)(d) and ISO 27001 A.5.19 simultaneously — one register, several proofs.
Deterministic, not estimated.
No AI score without a derivation — every finding shows which threshold was breached and why.
Configurable thresholds
Cluster limits by service type and country can be tuned to your own risk tolerance.
Traceable justification
Every finding names the affected suppliers, the threshold breached, and the share of the overall register.
No black-box scoring
The calculation is a deterministic rule evaluation, not an opaque AI model — traceable for auditors and supervisors alike.
Continuous, not point-in-time
The analysis runs on the current register state, not a stale annual snapshot.
How Third-Party & Concentration Risk works.
Maintain the register
Supplier register with service type, country and criticality — synced or entered manually.
Calculate clusters
The analysis groups automatically and compares against thresholds — including single-point-of-failure detection.
Seal the finding
Result sealed as evidence, visible in the supply chain graph, and applicable to DORA, NIS2 and ISO 27001.
A core building block for these regimes.
Concentration risk assessment under Art. 29 — the basis for the third-party register of information.
Regulation in detail →Supply chain security as one of the ten risk-management measures under Art. 21(2).
Regulation in detail →Supplier relationships under A.5.19 — concentration risk as part of the risk assessment.
Regulation in detail →Know where your supply chain is stretched thin.
We'll show you, on your own supplier data, where concentration risk is hiding.