Single-Vendor Risk: When One Relationship Is Doing Too Much Work
Single-vendor concentration rarely happens as one decision — it accumulates through small, individually reasonable expansions until one relationship is quietly load-bearing for the business.
In this review
| Criterion | Score |
|---|---|
| Editorial Score | 0.0 |
| Value for Money | 2.0 |
| Implementation Effort | 2.0 |
| Vendor Trajectory | 2.0 |
| Overall | 1.50 / 5.00 |
There's a particular kind of vendor relationship that grows so gradually it never gets a decision made about it. It starts small and reasonable — one supplier handles a piece of fulfillment, or one contractor writes the code that talks to a critical system, or one agency runs the campaigns that bring in most of the leads. Each expansion afterward makes sense on its own terms: they're already familiar with the account, switching would mean re-explaining everything, and the incremental piece of new work is small enough that adding it to the existing relationship is obviously the path of least resistance. None of those individual decisions is wrong. The sum of them, unnoticed, is a business that has quietly made one relationship load-bearing for something it never explicitly agreed to depend on that heavily.
How concentration accumulates without anyone deciding it should
The mechanism is almost always incremental rather than a single bad decision. A vendor starts with a defined, bounded scope. Over months or years, scope creeps outward in small, individually sensible steps — a new project gets routed to them because onboarding someone new would take longer, a second product line gets added because the first one went smoothly, a piece of work that was supposed to be temporary becomes permanent because nobody circled back to revisit it. At no point did anyone in the business sit down and decide "we are now dependent on this single vendor for a third of our critical operations." It happened as the sum of many decisions, each of which was locally correct and none of which was evaluated against the whole picture.
The question that concentration risk actually asks
Single-vendor risk isn't a judgment about the vendor's quality — a vendor can be excellent, reliable, and fairly priced, and still represent a dangerous concentration simply by being the only place a critical capability lives. The question worth asking isn't "are we happy with them," which is usually yes, or the concentration wouldn't have been allowed to grow this far. It's a different, less comfortable question: if this relationship ended abruptly — the company folded, the key contact left and took the institutional knowledge with them, the vendor got acquired and changed terms — how long would it take the business to recover functionality, and what would that gap cost. A relationship can score perfectly on every quality dimension and still fail this question badly, because quality and dependency risk are simply measuring different things.
Where this shows up most often
A handful of categories are where single-vendor concentration tends to accumulate fastest, mostly because they're areas where switching costs are genuinely high and inertia is genuinely rewarded in the short term. A software vendor deeply integrated into daily operations, where years of custom configuration and trained muscle memory make an alternative feel unthinkable. A single agency or contractor holding most of the institutional knowledge about how a critical, ongoing function actually works, with that knowledge living in their heads rather than in documentation the business owns. A supplier that's become the sole source for something because they were the cheapest or most convenient early on, and nobody has revisited that sourcing decision as the volume has grown to matter far more than it originally did. In each case, the risk isn't the relationship itself — it's the absence of anything else that could step in if it ended.
What reducing concentration doesn't have to mean
The instinctive response to noticing a concentration problem is to assume the fix is splitting the work across multiple vendors immediately, which is often the wrong move — fragmenting a relationship that's working well, purely to diversify, can trade a manageable risk for a real and immediate cost in coordination overhead and lost economies of scale. The more useful first step is smaller and less disruptive: documenting what the business would actually need to do to recover if the relationship ended, even without doing any of it yet. What would the transition period look like. Who else in the market could plausibly do this work. What institutional knowledge currently lives only with this vendor and needs to be captured somewhere the business actually owns it, independent of whether the relationship continues. This exercise alone — done once, refreshed annually — often reveals that the real risk isn't the vendor concentration itself but the missing documentation that would make an eventual transition survivable.
Turning awareness into a habit, not a project
Single-vendor risk isn't solved once. It re-accumulates the same way it built up the first time, through small, individually sensible expansions of scope that nobody evaluates against the whole picture. The businesses that manage this well don't run a heavyweight annual audit — they build a lighter habit into whatever vendor review process already exists: for the handful of relationships doing genuinely critical, hard-to-replace work, ask the recovery question explicitly, at least once a year, before scope quietly grows another notch. It's a smaller commitment than it sounds, and it's the difference between discovering a dependency problem in a calm quarterly review and discovering it the day a vendor relationship ends without warning.
The internal version of the same problem
Vendor concentration gets attention because a vendor is an outside party whose stability the business can't directly control. The same pattern shows up internally, and it's worth watching for the same reason: a single employee who, over time, becomes the only person who fully understands how a critical process actually works, without anyone deciding that was an acceptable level of dependency. The remedy is structurally identical to the vendor version — not immediately spreading the knowledge thin across a team for its own sake, but documenting what would actually happen if that person were unavailable for an extended stretch, and treating any gap that surfaces as something to close deliberately rather than something to notice only in a crisis.
None of this requires a formal risk-management function or a consultant's framework. A short, honest list — the handful of vendors and internal roles where the business would struggle badly and quickly if something changed unexpectedly — reviewed once a quarter alongside whatever other operational review already happens, catches the overwhelming majority of concentration risk before it becomes a crisis. The goal isn't eliminating dependency; some concentration is a reasonable trade for efficiency and a strong working relationship. The goal is simply making sure the concentration that exists is one the business chose with open eyes, rather than one it backed into a decision at a time.
Be the first to add to the record.
The Weekly Briefing
Did this review help?
Get one of these on your desk every Monday morning. Free, opinionated — includes clearly marked offers from our partners.