Skip to content

FRM Exam Part II · The Financial Stability Implications of Artificial Intelligence

Third-Party Dependencies and Service Provider Concentration in AI

Updated 11 October 2026 · Fact-checked

Third-party concentration risk arises when many financial firms rely on the same few AI model, cloud or data providers. One outage, cyber attack or model flaw can then hit many firms at once. To answer exam questions, identify the shared dependency, the failure channel and the systemic effect, then pick the supervisory response.

Understand Third-Party Dependencies and Service Provider Concentration

Most financial firms do not build AI from scratch. They rent computing power from cloud providers, use foundation models built by a few developers, and buy data and specialised hardware from a small set of vendors. Each link is a third-party dependency.

One firm relying on one vendor is an operational risk. It becomes a financial stability issue when many firms rely on the same vendor. This is service provider concentration. The vendor is then a single point of failure for the system, not only for one client.

The FSB's 2024 work on AI and financial stability names third-party dependencies and service provider concentration as a key vulnerability. Others it names include market correlations from common models and data, cyber risk, and model risk with data quality and governance weaknesses. Treat these as linked. A common model creates correlated behaviour. A common provider creates correlated outages.

There are several channels. Operational resilience: an outage or cyber incident at a provider stops many firms from running critical services. Substitutability: switching provider is slow and costly because of integration, data migration and model retraining, so firms are locked in. Opacity: firms may not see the provider's own sub-contractors, called fourth parties, so hidden concentration builds up. Model and data correlation: if firms use the same foundation model, errors and biases are shared, which can cause herding.

Supervisors face a gap. Providers often sit outside the financial regulatory perimeter, and a bank's contract gives it limited audit and information rights. Responses include mapping dependencies, setting exit and contingency plans, multi-vendor or multi-cloud strategies, stronger contract terms, and direct oversight of critical third parties. Multi-vendor strategies help only if the vendors do not share the same underlying fourth party.

Key formulas to remember

Concentration share
Provider share = firms (or activity) served by provider ÷ total firms (or activity)
A simple way to describe how dependent the system is on one provider. No single threshold is a standard rule.
Herfindahl-Hirschman Index (HHI)
HHI = Σ (sᵢ)², where sᵢ is each provider's market share
With shares in decimals, HHI runs from near 0 to 1. With shares in percent, it runs up to 10,000. Higher means more concentrated. Use it only as an illustration of concentration.
Systemic vulnerability logic
Systemic impact ≈ criticality of service × degree of concentration × low substitutability
A qualitative rule, not a calculation. Risk is highest when all three are high.

How to solve Third-Party Dependencies and Service Provider Concentration questions

Use this sequence for any scenario or conceptual question on AI third-party risk.

  1. 1Identify what is shared: cloud, foundation model, data feed, hardware or a fourth party.
  2. 2Identify the failure channel: outage, cyber attack, model error, data flaw, or provider exit.
  3. 3Ask how many firms and which critical functions are exposed. Concentration plus critical function means systemic.
  4. 4Check substitutability: how fast and at what cost can firms switch or run in-house?
  5. 5Check visibility: do firms know the provider's sub-contractors and have audit rights?
  6. 6Name the stability effect: correlated outages, herding, contagion, or loss of confidence.
  7. 7Pick the mitigant that fits: dependency mapping, exit plans, diversification, contract terms, or oversight of critical providers.
  8. 8Check the answer does not overstate. Diversification across vendors with a common fourth party does not remove concentration.

Quickest way: Shared dependency, failure, spread, fix

When to use it: Use for scenario MCQs where you have about a minute and several plausible options.

  1. Find the word that signals sharing: same, few, dominant, common.
  2. Decide if the risk is one firm's operational risk or a system-wide risk.
  3. Eliminate options that treat the vendor's size as irrelevant or that rely only on a firm's own controls.
  4. Choose the option that addresses visibility, substitutability or oversight of the provider.

Common mistakes in Third-Party Dependencies and Service Provider Concentration

  • Treating third-party risk as only an individual bank's operational risk.

    Outsourcing is usually taught from the bank's own viewpoint.

    Fix: Ask whether many firms share the provider. If yes, it is a financial stability issue as well.

  • Assuming multi-vendor sourcing removes concentration.

    Diversification sounds like a complete cure.

    Fix: Check for common fourth parties, such as the same cloud or chip supplier beneath different vendors. Also note switching costs and integration limits.

  • Confusing model-correlation risk with provider-outage risk.

    Both come from common AI use.

    Fix: Outage and cyber events stop services. Shared models or data cause similar decisions and herding. Name the right channel.

  • Believing a contract fully transfers the risk.

    Service level agreements feel like protection.

    Fix: The firm stays accountable to supervisors and customers. Contracts give remedies, not resilience.

  • Treating HHI as a regulatory threshold or a risk measure that gives a loss figure.

    It looks like a formula to be applied.

    Fix: HHI only describes concentration. It does not give a loss, and the page of rules here sets no cutoff to memorise.

  • Ignoring that providers may sit outside the regulatory perimeter.

    Students assume all critical entities are supervised.

    Fix: Recall the oversight gap. It is why direct oversight of critical third parties is discussed.

Worked examples

Example 1

Three market shares for AI cloud providers serving a country's banks are 50%, 30% and 20%. Compute the HHI using shares in percent and say what it shows.

Show the solution
  1. Square each share: 50² = 2,500; 30² = 900; 20² = 400.
  2. Add them: 2,500 + 900 + 400 = 3,800.
  3. On the 0 to 10,000 scale, 10,000 means a single provider. Equal shares of three providers would give 3 × 33.33² ≈ 3,333.
  4. 3,800 is above 3,333, so the market is more concentrated than three equal providers.

Answer: HHI = 3,800. The market is moderately to highly concentrated relative to an equal three-way split, so a failure at the largest provider would affect about half the banks. HHI describes concentration only and does not give a loss.

Example 2

Ten large banks use different cloud vendors, but each vendor's AI service runs on the same underlying cloud region operated by a fourth party. The banks say they are diversified. Evaluate this claim and recommend actions.

Show the solution
  1. Identify the shared dependency: the common fourth-party cloud region beneath all vendors.
  2. Failure channel: an outage or cyber event at that region would disrupt all ten banks simultaneously.
  3. So vendor diversification is partial. Hidden concentration remains because of low visibility into fourth parties.
  4. Recommend mapping the full dependency chain, including sub-contractors, and requiring disclosure in contracts.
  5. Recommend tested exit and contingency plans, and where feasible genuinely independent infrastructure.
  6. Note that supervisors may need oversight of critical providers because banks alone cannot fix a system-wide dependency.

Answer: The diversification claim is weak. The common fourth party creates a single point of failure across all ten banks. Mitigation is dependency mapping, contract transparency, tested exit plans and independent infrastructure, with supervisory oversight of critical providers.

Exam tips

  • Look for 'same', 'few' or 'common' in the stem. That is the cue for concentration and systemic risk.
  • Prefer answers that mention visibility, substitutability or fourth parties over answers that only mention internal controls.
  • Separate provider-outage risk from shared-model herding risk. Questions often test whether you can tell them apart.
  • Be wary of absolute words such as 'eliminates' or 'fully transfers'. They are usually wrong.
  • Link this topic to operational resilience and outsourcing questions, where exit strategies and concentration are tested in similar ways.

Practice questions from The Financial Stability Implications of Artificial Intelligence

Third-Party Dependencies and Service Provider Concentration: frequently asked questions

How does cloud and AI provider concentration create systemic risk?

Many firms depend on the same few providers for critical services. A single outage, cyber attack or flaw can therefore hit many firms at once. Because switching is slow and costly, firms cannot quickly move, so the shock spreads across the system.

What is a fourth-party risk?

It is the risk from your provider's own sub-contractors, such as the cloud or hardware supplier behind an AI vendor. Firms often cannot see these links. Hidden fourth parties can create concentration even when firms use different vendors.

Does using several AI vendors solve concentration risk?

Not fully. It helps only if the vendors are truly independent. If they share a fourth party, or if switching and integration are hard, concentration remains.

What do supervisors do about AI third-party dependencies?

They push firms to map dependencies, hold exit and contingency plans, and strengthen contracts. They also consider closer oversight of critical third-party providers that sit outside the traditional regulatory perimeter.