Skip to content

FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector

Third-Party and Cloud Concentration Risk in Finance

Updated 11 October 2026 · Fact-checked

Third-party and concentration risk arises when many financial firms rely on the same few ICT or cloud providers. One outage, cyber attack or failure can hit many firms at once, so it becomes a system-wide threat. Supervisors respond by overseeing critical providers directly and requiring firms to manage exit, substitutability and resilience.

Understand Third-Party and Concentration Risk (Cloud and ICT Providers)

Banks, insurers and market infrastructures now buy core technology from outside firms: cloud hosting, data services, payment software and cybersecurity tools. This lowers cost and speeds up change. It also moves critical functions outside the firm's direct control.

The key point is concentration. A small number of providers serve a large share of the market. If one fails, many firms fail together. Each firm's own risk looks small, but the shared dependency makes the failure systemic. Diversification across your own suppliers does not remove the problem if all your suppliers sit on the same cloud provider.

There are two layers to know. Firm-level concentration means one institution relies heavily on a single provider for important services. Market-level (systemic) concentration means the whole sector relies on the same few providers. Also watch fourth-party risk: your provider's own subcontractors, who you may not see or contract with.

A firm cannot outsource accountability. The board and senior management stay responsible for outsourced functions. Typical controls are due diligence, strong contracts and service level agreements, audit and access rights, tested exit plans, and monitoring.

Supervisors face a gap. Traditionally they regulate the financial firm, not its technology vendors. Newer approaches designate critical third parties and bring them under direct oversight, require incident reporting, and run sector-wide resilience testing. The aim is to keep important business services running within impact tolerances, even when a provider fails.

Key formulas to remember

Concentration share (simple measure)
Provider share = Services or workloads on provider ÷ Total services or workloads
A high share for one provider signals firm-level concentration. Use it as an indicator, not a rule with a fixed threshold.
Herfindahl-Hirschman Index (HHI)
HHI = Σ (sᵢ)², where sᵢ is each provider's market share
With shares as fractions, HHI ranges from 1/N to 1. Higher means more concentrated. Four equal providers give 0.25.
Systemic dependency logic
Systemic impact ≈ Number of firms affected × Criticality of service × Difficulty of substitution
A conceptual rule, not a regulatory formula. It explains why critical providers are singled out.

How to solve Third-Party and Concentration Risk (Cloud and ICT Providers) questions

Use this method for any scenario question on third-party or cloud concentration.

  1. 1Identify the dependency: which function, which provider, and how many firms rely on it.
  2. 2Decide the level: firm-level concentration, market-level systemic concentration, or fourth-party (subcontractor) risk.
  3. 3Judge criticality and substitutability: is the service essential, and how fast could the firm move to another provider or in-house?
  4. 4Name the transmission channel: outage, cyber attack, data loss, contractual or legal failure, or provider insolvency.
  5. 5Match the control or supervisory tool: due diligence, SLAs and audit rights, exit and contingency plans, multi-provider design, or direct oversight of critical third parties.
  6. 6Check accountability: the firm's board stays responsible; outsourcing does not transfer it.
  7. 7Pick the answer that reduces the shared, hard-to-substitute dependency, not one that only adds paperwork.

Quickest way: Spot the shared dependency

When to use it: When a multiple-choice question lists four plausible controls or policy responses and time is short.

  1. Ask: is the risk about one firm or many firms sharing one provider?
  2. If many firms, the answer usually involves direct oversight of critical providers or sector-level coordination.
  3. If one firm, the answer usually involves exit plans, contract terms and multi-provider strategy.
  4. Eliminate any option saying risk is transferred to the provider or that diversification alone solves it.
  5. Prefer options that test recovery and exit in practice, not only on paper.

Common mistakes in Third-Party and Concentration Risk (Cloud and ICT Providers)

  • Saying outsourcing transfers the risk to the provider.

    The contract assigns service duties to the vendor, so it feels like the risk moved.

    Fix: Remember accountability stays with the firm's board and management. Only the activity is outsourced.

  • Treating concentration as only a firm-level issue.

    Students focus on a bank's own vendor list.

    Fix: Also consider the market view: many firms on the same few providers create systemic risk that no single firm can fix.

  • Believing multiple vendors always means diversification.

    Vendor count looks like diversification.

    Fix: Check for common fourth parties, such as the same underlying cloud. Hidden shared dependencies keep the concentration.

  • Assuming a good SLA removes the risk.

    SLAs give service credits and targets.

    Fix: SLAs compensate or set targets; they do not keep services running. Exit plans and resilience testing address continuity.

  • Ignoring substitutability.

    Students rate only the probability of failure.

    Fix: Rate impact too. A rarely failing provider that cannot be replaced quickly can still be a critical concentration risk.

  • Confusing third-party risk with cyber risk in general.

    Both involve technology.

    Fix: Third-party risk is about dependence on external parties. Cyber is one channel through which a provider can fail.

Worked examples

Example 1

Five banks each run core payments on one of four cloud providers. Market shares of the four providers across these workloads are 40%, 30%, 20% and 10%. Calculate the HHI as a fraction and say what it suggests.

Show the solution
  1. Convert shares to fractions: 0.40, 0.30, 0.20, 0.10.
  2. Square each: 0.16, 0.09, 0.04, 0.01.
  3. Sum: 0.16 + 0.09 + 0.04 + 0.01 = 0.30.
  4. Compare with equal shares: four equal providers give 4 × 0.0625 = 0.25.
  5. 0.30 is above 0.25, so the market is more concentrated than an even split.

Answer: HHI = 0.30. This is moderately above the 0.25 of an equal four-way split, so reliance is tilted toward the largest provider. Supervisors would also ask how critical and substitutable the services are.

Example 2

A regional bank uses Cloud Provider X for its core banking and customer apps. Most other banks in the country also use X. X has a 12-hour outage. Which is the best description of the risk, and which supervisory response fits best? (A) Idiosyncratic operational risk; add more insurance. (B) Systemic concentration risk; bring critical providers under direct oversight and require tested exit and resilience plans. (C) Credit risk; raise capital for counterparties. (D) Market risk; tighten VaR limits.

Show the solution
  1. Identify the dependency: core services on one provider.
  2. Note that most other banks use the same provider, so the failure is correlated across firms.
  3. That makes it systemic concentration risk, not idiosyncratic.
  4. Option A treats it as one-firm risk and only transfers cost, not continuity.
  5. Options C and D name the wrong risk types.
  6. Option B targets the shared dependency through critical third-party oversight and tested resilience.

Answer: B. It is systemic concentration risk, best addressed by direct oversight of critical providers plus tested exit and resilience plans.

Exam tips

  • Look for the words 'many firms', 'same provider' or 'sector-wide'. They signal systemic concentration and critical third-party oversight.
  • Expect questions that test accountability: the board remains responsible for outsourced functions.
  • Watch for fourth-party traps, where a second vendor hides the same underlying provider.
  • When asked for the best mitigant, favor tested exit and substitutability over contract language alone.
  • Link the topic to operational resilience: the goal is keeping important services within tolerance during a provider failure.

Practice questions from Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector

Third-Party and Concentration Risk (Cloud and ICT Providers): frequently asked questions

What is concentration risk in cloud services?

It is the risk that many firms, or one firm's critical functions, depend on a few cloud providers. A single failure can then disrupt many services at once. It is both a firm-level and a system-level concern.

What is a critical third-party provider?

It is an ICT or cloud provider whose failure could seriously disrupt financial firms or financial stability. Some regimes designate such providers and oversee them directly, rather than only through their bank customers.

Can a bank transfer risk by outsourcing to the cloud?

No. The bank can outsource the activity, but accountability stays with its board and senior management. It must still manage due diligence, monitoring and exit planning.

Is using multiple cloud providers enough?

Not always. If the providers share the same fourth parties or infrastructure, the concentration remains. Real diversification needs tested ability to switch or run services elsewhere.