Concentration Risk: It's All About the Data

Mike Day • 14 September 2026

Third Party Therapy Podcast — featuring Gemma Stewart, Global Head of Vendor Management, Zurich Insurance

Concentration risk has moved from a niche corner of third party risk management (TPRM) to one of the most pressing topics on the regulatory agenda — particularly within financial services. In this episode of Third Party Therapy, host Mike Day is joined by Gemma Stewart, Global Head of Vendor Management at Zurich Insurance, to unpack how a mature TPRM function actually builds a concentration risk capability from the ground up.

What Concentration Risk Really Means

Gemma defines concentration risk simply: the risks in a supply chain where concentration could produce a loss large enough to threaten an organisation's ability to maintain core operations, financially or operationally. It's fundamentally a business resilience issue.

While geographic concentration — suppliers clustered in a single region — is usually the first type organisations tackle (accelerated in recent years by geopolitical shocks), Gemma sets out five recognised categories:

     Geographic concentration — supplier or service delivery clustered in one location

     Service dependency — over-reliance on a single third party for a critical business process

     Reverse concentration — where your organisation represents such a large share of a supplier's revenue that withdrawing your contract could threaten their survival

     Fourth party concentration — hidden dependency on the same subcontractor across multiple of your third parties

     Spend concentration — the proportion of overall spend sitting with a single supplier

Reverse concentration risk is, in Mike's view, one of the most overlooked categories — partly because it typically requires financial statements that can be 12-18 months out of date by the time they're reviewed.

It Starts — and Ends — With Data

The recurring theme of this conversation is that concentration risk is, above all, a data problem. Gemma describes how, in the past, understanding Zurich's exposure to a single event could take weeks or even months simply to locate the relevant information. The starting point was building a global inventory capturing service location, data location, and the recognition that a supplier's contracted location and its actual service delivery location are very often different.

The payoff was tangible: when the Ukraine conflict began, Zurich's team could identify every third party providing services from the affected region "literally within a few minutes" — because the underlying data had already been gathered and structured. From there, the team could assess which of those services were genuinely critical, contact the relevant suppliers to check business continuity plans, and determine whether services could realistically be relocated.

For historical contracts where this data hadn't been captured up front, Zurich used AI to read existing contracts and extract the relevant fields — cutting what would otherwise have been at least a 12-month manual exercise. New contracts now capture this information at the point of due diligence, and ongoing assurance reviews (typically annual, for critical suppliers) proactively ask whether service or data locations — or fourth parties — have changed.

Fourth Parties: Proportionate, Not Exhaustive

Zurich doesn't attempt to map fourth parties across its entire supplier base. The focus is deliberately narrow: high and medium risk-tier third parties are asked about their own critical subcontractors — not, for example, their postal services provider. As Gemma puts it, the team focuses "on the ones that we're actually going to do something about."

Visualising Risk Without Drowning in It

Zurich pushes its concentration data into Power BI, building maps with filters by service type, viewable at global, regional and country level. Gemma notes that a global aggregate view "tends to dilute the picture too much" — the more useful granularity sits at the regional or country level, cross-referenced against service criticality.

Notably, Zurich has deliberately chosen not to set a fixed numerical threshold (e.g. "five critical services in one location triggers a review"), because risk appetite varies too much country to country. Instead, each flagged concentration is investigated directly with the supplier to understand what continuity and resilience measures already exist before deciding whether action is warranted. Gemma suggests this could evolve over time as the organisation matures and identifies clearer trends, but for now, deliberately keeps it open.

Impact and Likelihood — Not Just a Map

Mike draws out an important framing: mapping alone only tells you the impact side of the risk equation. The likelihood side — a supplier's financial strength, their ability to substitute a failed process, geopolitical trajectory, disaster-proneness — still requires deliberate scenario testing. Gemma agrees, and highlights simple scenario walkthroughs ("what actually happens if this takes place?") as a lightweight but effective technique, alongside more structured nine-box risk grids common in insurance.

A Cautionary Tale: Data Without Context Is Dangerous

Gemma shares a candid example of what happens when this goes wrong. One country team, having just gained access to location data, became "very overexcited" and spent around four months pulling apart contracts — moving services, changing suppliers, even terminating contracts early — based purely on geographic location data, without cross-referencing service criticality or existing business continuity arrangements, and without first speaking to the suppliers involved. The result: significant wasted effort, and damaged long-standing supplier relationships that the team is still repairing. The lesson: a single data point is never enough to justify action — always add context, and always talk to the third party before acting.

Fourth Parties, Cloud Concentration, and What Comes Next

The conversation turns to the elephant in the room for most organisations: cloud concentration. With the vast majority of SaaS tools sitting on a small number of hyperscale providers (AWS, Azure, Google Cloud), Mike observes that swapping providers often simply swaps one concentration risk for another. A more realistic mitigation, discussed by both Gemma and Mike, is drilling down a level further — looking at availability zones and data centre diversification within a single cloud provider, since a single zone outage is a far more plausible scenario than the wholesale failure of an entire hyperscaler.

Gemma also flags a genuinely interesting emerging model: at least one organisation she's aware of has opened up its own due diligence platform to its third parties, allowing them to conduct their own supply chain due diligence within the same shared instance — effectively extending visibility into the fourth party layer through shared infrastructure rather than duplicated effort.

Practical Advice for Getting Started

Asked how she'd start with a blank sheet of paper, Gemma is unequivocal: don't change the foundation. Get the data right first — a central inventory (whether that's a GRC platform or even a well-managed SharePoint site), gathered consistently at the point of sourcing, contracting and due diligence — and only then start layering risk lenses on top, beginning with whichever concentration type is most relevant to your organisation. As she puts it: "without that data... you're really just not going to know what's there in the first place."


Listen to the full episode of Third Party Therapy, produced in association with CeFPro, on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit thirdpartytherapy.com to subscribe to the mailing list.


Tags

#ThirdPartyTherapy #TPRM #ConcentrationRisk #VendorRiskManagement #OperationalResilience #FourthPartyRisk #DORA #CloudConcentrationRisk #SupplyChainRisk #DueDiligence #RiskManagement #FinancialServicesRegulation #ThirdPartyRiskManagement #InsuranceRisk #RiskManagementPodcast #WhatIsConcentrationRiskInTPRM #HowToManageFourthPartyRisk #TPRMPodcast

by Mike Day 14 September 2026
Third Party Therapy Podcast — featuring Stephen Boyer, Co-Founder and Chief Innovation Officer, BitSight
by Mike Day 14 September 2026
Third Party Therapy Podcast — featuring Ian Ellis, emerging technology adviser and angel investor
by Mike Day 14 September 2026
Third Party Therapy Podcast — featuring Aki Eldar, co-founder of Mirato
by Mike Day 14 September 2026
Third Party Therapy Podcast — Series 1, Episode 1 — featuring Paul Huggett, Managing Director, Helios For the very first episode of Third Party Therapy, host Mike Day speaks with Paul Huggett, Managing Director at Helios and a former head of third party risk management (TPRM) at Lloyds Banking Group, Bank of Ireland and Nationwide Building Society. Having sat on both sides of the fence — as a buyer of pooled due diligence for over a decade, and now as a provider of it — Paul offers a rare, grounded view of what community due diligence really delivers, and where its limits are. From "Poacher" to "Gamekeeper" to Provider Paul's career path is itself a neat illustration of how TPRM as a discipline emerged almost by accident. Starting in operational and IT project management in the early 1990s, he moved into outsourcing project delivery — describing himself at the time as a "poacher," someone focused purely on moving functions quickly, for whom procurement was simply an obstacle. A move into internal audit at Lloyds Banking Group — auditing the sourcing and property functions — turned him into a "gamekeeper," and from there he spent a decade running third party risk functions across three major financial institutions, all of which were customers of Helios's FSQS scheme, before joining Helios itself roughly 18 months ago. Ten Years of Change in TPRM Paul's account of how far the discipline has moved is stark. His first supplier management audit revealed that "due diligence" at the time amounted to a signed letter from the supplier saying "everything's fine, thank you." The regulatory framework consisted of a handful of bullet points essentially saying "you can't outsource the risk." The period from roughly 2015 to 2018 — driven by GDPR, the growth of cloud outsourcing, and European regulators waking up to the risk — triggered rapid change, followed by growing UK regulatory focus (SS2/21 and PS7/21) on operational resilience, conduct risk, and more recently ESG, which Paul says has moved from "almost at the bottom of the pile" to near the top of the risk league table. What Pooled Due Diligence Actually Is Paul's explanation is refreshingly plain: the traditional model is a "many-to-many mesh" — every buyer individually asking every one of their suppliers largely the same questions, repeatedly. Pooled or community due diligence flips this into a one-to-many model: a supplier answers a shared, standardised question set once, and that data is made available (with the supplier's consent and quality-checked) to every buyer in the community who needs it. The win is symmetric. Suppliers spend less time repeatedly answering near-identical questionnaires from dozens of buyers. Buyers get a faster start, a broader pool of pre-assessed suppliers, and — critically — a question set that reflects a decade of collective input from the buying community, not just their own risk team's best guess. As Paul puts it, being able to tell your board "this is good enough for [named peer firms], therefore we believe it's good enough for us" is valuable air cover for a new entrant to the model. From Niche to Mainstream When Lloyds Banking Group first adopted the model, it was the only buying firm in the community — making it a hard sell to suppliers. Today, Helios's UK community includes just under 70 buying firms, plus roughly 20 more across Europe, spanning tiny building societies through to major international investment banks. Paul attributes the shift to sustained pressure on TPRM budgets and headcount ("you never get, as a TPR person, someone come to you and say... would you like some more people?"), combined with a regulatory turning point around 2018-2019 when European regulation first explicitly acknowledged shared assurance as acceptable — provided the buyer using it still applies its own risk appetite to the results, rather than simply outsourcing the decision. Confidentiality and Competition Law Two objections come up repeatedly with pooled models, and Paul addresses both directly. On confidentiality, where a supplier is unwilling to upload a sensitive document (such as a full cybersecurity policy) directly, Helios instead asks granular, structured yes/no questions about the specific controls contained within that document — meaning a buyer's risk specialist can still assess control coverage without the underlying document ever being shared. On competition law, Helios never discloses which buyers work with which suppliers to other buyers in the community, never comments on individual suppliers as a collective, and never directs buyers to take action against a specific supplier — all of which would risk anti-competitive behaviour. Not a Silver Bullet — Part of an Ecosystem Paul is careful to position pooled due diligence as one part of a wider TPRM toolkit, not a replacement for the buyer's own risk judgement. Helios provides primary, source-verified data (rather than scraped or blended third-party data), but the buyer still has to decide what matters to them and act on it. His framing: "we give you the information, but your job is to decide what to do with it." Real-World Stress Testing: Russia-Ukraine One of the clearest illustrations of the model's value came with the outbreak of the Russia-Ukraine conflict. Because Helios already held country of registration, operating location and fourth party data for its supplier community, buyer firms could establish their exposure "within about half an hour" of the event breaking — rather than manually cross-referencing finance systems to work out who they'd been paying, and where. Helios then issued a bespoke follow-up questionnaire to roughly 10,000 suppliers within about ten days, with an 80% response rate — giving buyers not just a static exposure map, but live intelligence on downstream impact. The same approach was repeated for the Israel-Gaza conflict and rolling energy blackouts. Where AI Fits — and Where Helios Is Deliberately Cautious Asked about AI, Paul draws a pointed comparison to cloud computing circa 2017-2018: a lot of noise, real underlying risk, but limited clarity on exactly where the exposure sits. Helios is building a new question set specifically to assess suppliers' use of AI, aligned to the EU AI Act's risk-based, proportionate approach. But Paul is candid that Helios itself is deliberately slow to deploy AI at scale in its own data pipeline, given its core value proposition rests on primary, verified data rather than scraped or AI-generated content — and flags the emerging industry concern that large language models may increasingly be trained on data that itself originated from other AI systems, creating a quality-degradation risk over time. Editorial note: the discussion of AI training data and model quality reflects Paul Huggett's own views and industry commentary referenced on the podcast, not an independently verified technical claim. Concentration Risk and the Regulator's Blind Spot Paul also touches on Critical Third Party (CTP) regulation and the new, more detailed outsourcing and DORA registers now required by UK and EU regulators — designed to help regulators identify concentration risk across the financial sector. He's candid that Helios, precisely because of the same competition and confidentiality constraints discussed earlier, cannot fill this gap entirely: it knows what a supplier does, but not what each buyer considers critical about that relationship, since criticality varies hugely between an insurer, a reinsurer, a building society and an investment manager. The Direction of Travel: From Data to Assurance Looking ahead, Paul sees the community model extending from data-gathering into genuine assurance — Helios has already introduced ESG benchmarking that lets suppliers see how they compare to peers, and has launched pooled, supplier-funded virtual site visits testing controls across the top operational risk domains. Notably, he observes that resistance to pooled assurance has historically come more from buyers wanting to "do things their way" than from suppliers, who are generally keen to spend less time on duplicate assurance requests. A Practical Starting Point For any organisation considering this path, Paul's advice is to look at your own organisation from the supplier's point of view: how many different, overlapping data requests are you sending out? Are you actually using everything you collect, or gathering data you never act on? And do you genuinely understand your broader (not just your most critical) supplier population — because, as Paul notes pointedly, "Covid did not care that it was taking out your workforce from a whole swathe of your medium risk suppliers." His clearest warning, drawn from watching organisations invest heavily in shiny new source-to-pay platforms: the technology is rarely the problem. "Systems and technology are not going to solve your problems. They're just going to give you a shinier problem to grapple with," unless matched with the cultural change and data discipline to actually populate and use them. Listen to the full episode of Third Party Therapy, produced in association with CeFPro, on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit thirdpartytherapy.com to subscribe to the mailing list. Tags #ThirdPartyTherapy #TPRM #CommunityDueDiligence #PooledDueDiligence #VendorRiskManagement #ThirdPartyRiskManagement #FSQS #SharedAssurance #DueDiligence #FinancialServicesRegulation #ConcentrationRisk #CriticalThirdParty #DORA #SupplierRiskManagement #RiskManagementPodcast #WhatIsPooledDueDiligence #HowDoesCommunityDueDiligenceWork #TPRMPodcast
by Mike Day 14 September 2026
Third Party Therapy Podcast — featuring Shayne Tyler, supply chain modern slavery expert Modern slavery rarely makes the same headlines as a cyber breach or a data leak, yet its human cost is far greater — and, as this episode of Third Party Therapy makes clear, it is far closer to the corporate world than most third party risk management (TPRM) professionals assume. Host Mike Day sat down with Shayne Tyler, a supply chain modern slavery expert with over 20 years of first-hand experience tackling worker exploitation. Shayne's involvement in this space began in the most direct way possible: as an operations manager whose own factory was exposed on the BBC's Panorama in 2000 for the illegal employment of more than 200 staff. That experience — engaging afterwards with the victims themselves — set the course for the rest of his career. What Modern Slavery Actually Is Shayne's central message is that "modern slavery" is a broad umbrella covering forced labour, organ harvesting, forced criminality and prostitution, but that in the corporate world, forced labour driven by human trafficking dominates. Crucially, he stresses that human trafficking does not require crossing a border: moving someone from one field, or one office, to another for the purpose of exploitation is enough. He breaks trafficking down into three legal components that must all be present: • Action — the transportation, harbouring or receipt of a person • Means — control and power exercised over them • Purpose — for financial gain Without all three, it is a different crime entirely — smuggling, or extortion. That distinction is part of why modern slavery is so notoriously difficult to prosecute: the "chains" are usually psychological, built through debt, fear, pride or hope rather than physical restraint. The UK Is Not Immune — and Neither Is Finance A common assumption in TPRM circles is that modern slavery is confined to agriculture, food production or other manual, low-skill sectors overseas. Shayne dismantles this. Citing Pew Research Centre estimates of 800,000 to 1.2 million people in the UK without the right to live and work — roughly one in fifty people — he argues that any organisation interacting with more than fifty people is statistically likely to encounter someone in that position. He points to worker substitution (the person who turns up to do the job is not the person who was vetted) as a pervasive and largely unpoliced gap, and highlights how visa routes — Tier 2 skilled worker sponsorship, the Tier 5 seasonal worker scheme, EU Settled Status, and student visas — all carry their own distinct exploitation risks, from debt bondage arranged in the worker's home country to fee-payment scams tied to fraudulent immigration paperwork. For financial services specifically, Shayne draws a direct parallel to anti-money laundering controls: a pattern such as a victim's bank account being emptied every Friday night at a cash point is exactly the kind of anomaly that existing AML infrastructure could be adapted to flag — if TPRM, fraud and financial crime teams collaborated on it. Why Policies Don't Stop Exploiters — Processes Do Perhaps the sharpest insight in the episode: in 24 years of this work, Shayne says he has "not met an exploiter yet that has cared one iota about a company's policy." Exploiters study and infiltrate processes, not statements. His own audits have generated close to 30 critical non-compliances in a single afternoon by testing a labour provider's systems with deliberately falsified information — precisely the same technique an exploiter would use. This is a direct challenge to the "modern slavery statement" as a compliance artefact. As he puts it, no statement has ever prevented a victim. The Four Ps: A Practical Due Diligence Framework Rather than defaulting to a checklist, Shayne recommends corporates adopt a four-stage approach: 1. Pursue — assume exploitation is present in your supply chain and actively look for it, rather than assuming the absence of evidence means the absence of a problem. 2. Prevent — use what you find to close gaps for the next case, even if you can't undo the last one. 3. Prepare — share learnings across your business, supply chain and even competitors, and train staff to recognise the signs. 4. Protect — not only the victim, but the brand, the business, the systems and the staff. Protecting everyone matters, because "there is no point in being the most ethical business on the planet if you're out of business." Look for the Absence of Normal, Not the Presence of Abnormal One of the episode's most striking reframes: conventional guidance tells people to look for visible signs of exploitation (houses of multiple occupancy, signs of abuse, isolation). But if a sign is visible, Shayne argues, exploiters already know to hide it. The more reliable indicator is the absence of normal — the person who never mentions weekend plans, who never has an ordinary conversation about ordinary life. And when a potential victim is identified, the instinct to escalate immediately can be dangerous. Shayne recounts a case in which acting too fast caused 53 people connected to a single victim to disappear. His guidance: de-escalate, gather information quietly, and hand a complete picture to the authorities rather than attempting to investigate or "rescue" directly. The Takeaway for TPRM Teams This conversation is a reminder that third party risk management's toolkit — due diligence, escalation, ongoing monitoring — has direct relevance to one of the most serious human rights issues in modern business, but only if it moves beyond box-ticking. Real progress means testing processes the way an exploiter would, watching for the absence of the ordinary, and building cross-functional collaboration between TPRM, procurement, HR and financial crime teams. As Shayne puts it, using a health and safety analogy: don't jump straight to the high-vis vest. Eliminate the risk first, substitute it, segregate it, administrate it — and only then rely on the last line of defence. Listen to the full episode of Third Party Therapy on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit thirdpartytherapy.com to subscribe to the mailing list. Tags #ThirdPartyTherapy #TPRM #ModernSlavery #SupplyChainRisk #HumanTrafficking #VendorRiskManagement #DueDiligence #ForcedLabour #EthicalSupplyChain #ESG #FinancialServicesRegulation #SupplierRisk #CorporateResponsibility #RiskManagementPodcast #ModernSlaveryAct #WhatIsModernSlaveryInTheSupplyChain #HowToSpotModernSlaveryInBusiness #TPRMPodcast