Single-Source Dependency: Finding and Fixing Concentration Risk
Single-source dependency is a hidden single point of failure, and the worst of it often sits below Tier 1. What supplier concentration risk is, how to find it, and how to reduce the dependencies that would actually hurt.

Single-source dependency is what you have when a critical input, component or service comes from just one supplier, so if that supplier fails, you have no immediate alternative. It's the purest form of supplier concentration risk: a single point of failure sitting inside your supply chain, often unnoticed until it breaks. Reducing it isn't about blanket diversification, which carries its own costs, but about finding where you're dangerously concentrated and fixing the dependencies that would actually hurt. Here's how to think about it.
Why single-source dependency is so dangerous
A single source is efficient: one relationship, better pricing through volume, simpler quality control, right up until that source stops delivering. Then it becomes the reason your whole line stops. What makes it especially dangerous is that the worst concentration is often invisible. You might deliberately dual-source at Tier 1 and still have both suppliers quietly buying the same component from the same Tier 2 factory. On paper you're diversified; in reality a single failure takes out both. Concentration risk hides below the tier you can see.
Single-sourcing isn't always a mistake
It's worth saying that single-sourcing can be a deliberate, sensible choice: for a specialised component only one supplier makes well, or where a deep single relationship delivers real quality and cost advantages. The problem isn't single-sourcing itself; it's unmanaged or unrecognised single-sourcing, the dependency you didn't consciously choose and haven't mitigated. The goal is to know exactly where you're single-sourced, decide whether that's acceptable, and manage the ones that aren't.
How to find your concentration risk
Start by mapping your dependencies for critical inputs: which suppliers provide them, and crucially, where those suppliers source from beneath the surface. Then look for concentration in three forms: a single supplier providing a critical input; several of your suppliers depending on the same sub-tier source; and geographic concentration, where multiple sources sit in one region exposed to the same shock. Quantify each by the value at risk, what a failure would cost, so you can tell a dependency that's merely tidy from one that's genuinely dangerous.
How to reduce it
Once you know where you're exposed, the fixes are well understood, and you apply them where the value at risk justifies the cost.
Qualify a second source. A pre-approved alternate supplier you can switch to quickly is the most direct fix, even if you don't split volume day to day. Diversify deliberately. Split volume across suppliers or regions for your most critical, highest-value dependencies. Hold targeted buffer. Where a second source isn't practical, a safety stock at that node buys time to respond. Design out the dependency. Sometimes the best fix is upstream: standardising a component or qualifying alternatives so you aren't locked to one source at all.
The common thread is proportion: spend on reducing concentration where a failure would genuinely hurt, and accept the dependencies that wouldn't.
Single-source dependency is one of the most common and most overlooked risks in a supply chain, precisely because it looks efficient until it isn't. Find it, quantify it, and fix what matters. For how it fits the wider discipline, see our guide to supplier risk management, and for seeing the hidden concentration beneath Tier 1, our guide to sub-tier supply chain visibility.
Questions this piece raises
What is single-source dependency risk and how do you reduce it?
Single-source dependency risk is the exposure that comes from relying on one supplier for a critical input, so a single failure has no immediate fallback. You reduce it by first finding where you're single-sourced, including hidden concentration where several suppliers share the same sub-tier source, then applying fixes in proportion to the value at risk: qualifying a second source, diversifying volume, holding targeted buffer stock, or designing the dependency out by standardising components. The aim isn't to eliminate all single-sourcing, but to manage the dependencies that would genuinely hurt.
What is supplier concentration risk?
Supplier concentration risk is the risk created when too much of your supply depends on too few points: one supplier for a critical input, several suppliers sharing the same sub-tier source, or many sources clustered in one region. The more concentrated the dependency, the more a single event can disrupt. Much of it is hidden below Tier 1, which is why mapping sub-tier sources matters.
Is single-sourcing always bad?
No. Single-sourcing can be a deliberate, sensible choice, for a specialised component only one supplier makes well, or where a deep single relationship improves quality and cost. The danger is unrecognised or unmanaged single-sourcing: a dependency you didn't consciously choose and haven't mitigated. The goal is to know where you're single-sourced, decide whether it's acceptable, and manage the ones that aren't.
See Causal AI applied to your supply chain.
A structured, 45-minute session with a senior solutions architect.
Request a Demo
Related insights

Supplier Risk Assessment: Metrics, Scoring and Red Flags
A supplier risk assessment turns a supplier from a name on a contract into a scored, ranked view of how likely they are to disrupt you. Here's how to assess and score supplier risk, the metrics that matter, and the red flags to watch.


