Concentration Risk: It's All About the Data
Third Party Therapy Podcast — featuring Gemma Stewart, Global Head of Vendor Management, Zurich Insurance
Concentration risk has moved from a niche corner of third party risk management (TPRM) to one of the most pressing topics on the regulatory agenda — particularly within financial services. In this episode of Third Party Therapy, host Mike Day is joined by Gemma Stewart, Global Head of Vendor Management at Zurich Insurance, to unpack how a mature TPRM function actually builds a concentration risk capability from the ground up.
What Concentration Risk Really Means
Gemma defines concentration risk simply: the risks in a supply chain where concentration could produce a loss large enough to threaten an organisation's ability to maintain core operations, financially or operationally. It's fundamentally a business resilience issue.
While geographic concentration — suppliers clustered in a single region — is usually the first type organisations tackle (accelerated in recent years by geopolitical shocks), Gemma sets out five recognised categories:
• Geographic concentration — supplier or service delivery clustered in one location
• Service dependency — over-reliance on a single third party for a critical business process
• Reverse concentration — where your organisation represents such a large share of a supplier's revenue that withdrawing your contract could threaten their survival
• Fourth party concentration — hidden dependency on the same subcontractor across multiple of your third parties
• Spend concentration — the proportion of overall spend sitting with a single supplier
Reverse concentration risk is, in Mike's view, one of the most overlooked categories — partly because it typically requires financial statements that can be 12-18 months out of date by the time they're reviewed.
It Starts — and Ends — With Data
The recurring theme of this conversation is that concentration risk is, above all, a data problem. Gemma describes how, in the past, understanding Zurich's exposure to a single event could take weeks or even months simply to locate the relevant information. The starting point was building a global inventory capturing service location, data location, and the recognition that a supplier's contracted location and its actual service delivery location are very often different.
The payoff was tangible: when the Ukraine conflict began, Zurich's team could identify every third party providing services from the affected region "literally within a few minutes" — because the underlying data had already been gathered and structured. From there, the team could assess which of those services were genuinely critical, contact the relevant suppliers to check business continuity plans, and determine whether services could realistically be relocated.
For historical contracts where this data hadn't been captured up front, Zurich used AI to read existing contracts and extract the relevant fields — cutting what would otherwise have been at least a 12-month manual exercise. New contracts now capture this information at the point of due diligence, and ongoing assurance reviews (typically annual, for critical suppliers) proactively ask whether service or data locations — or fourth parties — have changed.
Fourth Parties: Proportionate, Not Exhaustive
Zurich doesn't attempt to map fourth parties across its entire supplier base. The focus is deliberately narrow: high and medium risk-tier third parties are asked about their own critical subcontractors — not, for example, their postal services provider. As Gemma puts it, the team focuses "on the ones that we're actually going to do something about."
Visualising Risk Without Drowning in It
Zurich pushes its concentration data into Power BI, building maps with filters by service type, viewable at global, regional and country level. Gemma notes that a global aggregate view "tends to dilute the picture too much" — the more useful granularity sits at the regional or country level, cross-referenced against service criticality.
Notably, Zurich has deliberately chosen not to set a fixed numerical threshold (e.g. "five critical services in one location triggers a review"), because risk appetite varies too much country to country. Instead, each flagged concentration is investigated directly with the supplier to understand what continuity and resilience measures already exist before deciding whether action is warranted. Gemma suggests this could evolve over time as the organisation matures and identifies clearer trends, but for now, deliberately keeps it open.
Impact and Likelihood — Not Just a Map
Mike draws out an important framing: mapping alone only tells you the impact side of the risk equation. The likelihood side — a supplier's financial strength, their ability to substitute a failed process, geopolitical trajectory, disaster-proneness — still requires deliberate scenario testing. Gemma agrees, and highlights simple scenario walkthroughs ("what actually happens if this takes place?") as a lightweight but effective technique, alongside more structured nine-box risk grids common in insurance.
A Cautionary Tale: Data Without Context Is Dangerous
Gemma shares a candid example of what happens when this goes wrong. One country team, having just gained access to location data, became "very overexcited" and spent around four months pulling apart contracts — moving services, changing suppliers, even terminating contracts early — based purely on geographic location data, without cross-referencing service criticality or existing business continuity arrangements, and without first speaking to the suppliers involved. The result: significant wasted effort, and damaged long-standing supplier relationships that the team is still repairing. The lesson: a single data point is never enough to justify action — always add context, and always talk to the third party before acting.
Fourth Parties, Cloud Concentration, and What Comes Next
The conversation turns to the elephant in the room for most organisations: cloud concentration. With the vast majority of SaaS tools sitting on a small number of hyperscale providers (AWS, Azure, Google Cloud), Mike observes that swapping providers often simply swaps one concentration risk for another. A more realistic mitigation, discussed by both Gemma and Mike, is drilling down a level further — looking at availability zones and data centre diversification within a single cloud provider, since a single zone outage is a far more plausible scenario than the wholesale failure of an entire hyperscaler.
Gemma also flags a genuinely interesting emerging model: at least one organisation she's aware of has opened up its own due diligence platform to its third parties, allowing them to conduct their own supply chain due diligence within the same shared instance — effectively extending visibility into the fourth party layer through shared infrastructure rather than duplicated effort.
Practical Advice for Getting Started
Asked how she'd start with a blank sheet of paper, Gemma is unequivocal: don't change the foundation. Get the data right first — a central inventory (whether that's a GRC platform or even a well-managed SharePoint site), gathered consistently at the point of sourcing, contracting and due diligence — and only then start layering risk lenses on top, beginning with whichever concentration type is most relevant to your organisation. As she puts it: "without that data... you're really just not going to know what's there in the first place."
Listen to the full episode of Third Party Therapy, produced in association with CeFPro, on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit thirdpartytherapy.com to subscribe to the mailing list.
Tags
#ThirdPartyTherapy #TPRM #ConcentrationRisk #VendorRiskManagement #OperationalResilience #FourthPartyRisk #DORA #CloudConcentrationRisk #SupplyChainRisk #DueDiligence #RiskManagement #FinancialServicesRegulation #ThirdPartyRiskManagement #InsuranceRisk #RiskManagementPodcast #WhatIsConcentrationRiskInTPRM #HowToManageFourthPartyRisk #TPRMPodcast


