Supply Chain & Risk Features / Third-Party & Concentration Risk

Third-Party & Concentration Risk

Too much riding on one supplier or one country? ReportAct calculates concentration risk deterministically from your supplier register — not estimated, but traceably derived and sealed as evidence.

What is Third-Party & Concentration Risk

Concentration risk you can actually trace.

The analysis groups your suppliers by service type and country and compares each cluster against configurable thresholds. When a cluster exceeds the threshold — say, too many critical suppliers concentrated in the same country or service category — a finding is created with method-level language: which suppliers are affected, which threshold was breached, what share of the register is involved.

The analysis also detects single points of failure: individual critical suppliers on which a disproportionate share of your core functions depend. The result appears directly in the interactive supply chain graph — with a risk marker on the affected node and an impact path traced back to your own organization.

Every concentration analysis is sealed as evidence and can be applied directly to the DORA Register of Information and to NIS2 and ISO 27001 controls — calculated once, reused across regimes.

Core capabilities

What the concentration risk analysis delivers.

Cluster analysis by service type and country

Groups all suppliers automatically and compares each cluster against thresholds — a result with traceable methodology, not a black-box score.

Single-point-of-failure detection

Identifies individual critical suppliers on which a disproportionate share of core functions depend.

Interactive supply chain graph

Risk marker on the affected node, impact path to your own organization, zoomable with a criticality traffic light.

Sealed evidence

Every analysis is cryptographically sealed and remains provable as the state at a given point in time — even after later register changes.

Applies across multiple regimes

Feeds DORA Art. 29, NIS2 Art. 21(2)(d) and ISO 27001 A.5.19 simultaneously — one register, several proofs.

Methodology

Deterministic, not estimated.

No AI score without a derivation — every finding shows which threshold was breached and why.

Configurable thresholds

Cluster limits by service type and country can be tuned to your own risk tolerance.

Traceable justification

Every finding names the affected suppliers, the threshold breached, and the share of the overall register.

No black-box scoring

The calculation is a deterministic rule evaluation, not an opaque AI model — traceable for auditors and supervisors alike.

Continuous, not point-in-time

The analysis runs on the current register state, not a stale annual snapshot.

How it works

How Third-Party & Concentration Risk works.

Maintain the register

Supplier register with service type, country and criticality — synced or entered manually.

Calculate clusters

The analysis groups automatically and compares against thresholds — including single-point-of-failure detection.

Seal the finding

Result sealed as evidence, visible in the supply chain graph, and applicable to DORA, NIS2 and ISO 27001.

Connected regulations

A core building block for these regimes.

DORA

Concentration risk assessment under Art. 29 — the basis for the third-party register of information.

Regulation in detail →
NIS2 / NISG

Supply chain security as one of the ten risk-management measures under Art. 21(2).

Regulation in detail →
ISO/IEC 27001

Supplier relationships under A.5.19 — concentration risk as part of the risk assessment.

Regulation in detail →
Next step

Know where your supply chain is stretched thin.

We'll show you, on your own supplier data, where concentration risk is hiding.