Skip to content

Dependency Concentration & Common-Mode Loss

← Back to Fragility, Failure & Continuity Risk

Nominally plural providers, paths, backups, or pooled exposures share enough concentration or correlation that one cause can remove them together.

48 mechanisms across 6 solution archetypes. This is a recurring problem pattern within Fragility, Failure & Continuity Risk; the mechanisms below inherit it from the primary archetype they instantiate.

Because this set contains more than 30 mechanisms, it is divided by form family—the concrete kind of thing a practitioner deploys, enacts, maintains, or convenes. This is a browsing subdivision only; it does not change the inherited problem classification. Click a form below to jump to its fully visible section.

Form familyMechanismsDescription
Analysis, Modeling & Optimization8A calculation, model, estimator, diagnostic, comparison, simulation, or optimization that transforms inputs into an inference, prediction, recommendation, or formal result.
Assessment, Review & Assurance5A bounded evaluation of existing evidence, work, compliance, or readiness that produces a finding, approval, correction, or disposition.
Control, Automation & Runtime3A state-dependent executable mechanism that senses, triggers, schedules, filters, throttles, routes, or actuates during operation.
Experiment, Test & Rehearsal4An active probe, controlled variation, simulated condition, or practiced execution used to generate evidence or readiness.
Interface, Display & Cue1A user-facing perceptual surface or interactive affordance that presents status, options, warnings, prompts, or controls.
Monitoring, Sensing & Alerting1Ongoing or repeated observation of actual state that emits measurements, indicators, dashboards, surveillance signals, or alerts.
Organization, Role & Governance5An enduring actor, authority, body, program, service, pooled capacity, or institutional arrangement whose mandate, membership, resources, or continuity is operative.
Protocol, Workflow & Routine1A repeatable ordered sequence of actions, handoffs, states, or escalation steps, including procedures, runbooks, routines, recovery sequences, and lifecycle workflows.
Record, Log & Register2A durable, usually accumulating account of actual events, decisions, custody, exceptions, or state transitions whose value depends on history, provenance, or accountability.
Representation, Specification & Plan3A non-executable information artifact that externalizes understood, desired, or future structure, including maps, matrices, templates, checklists, specifications, reports, plans, and schedules.
Rule, Policy & Commitment9A standing constraint, permission, default, threshold, quota, obligation, right, or conditional action rule governing future behavior.
Structure, Architecture & Configuration6An enduring physical, digital, spatial, material, or organizational topology, partition, boundary, component arrangement, or configured state.

Analysis, Modeling & Optimization

A calculation, model, estimator, diagnostic, comparison, simulation, or optimization that transforms inputs into an inference, prediction, recommendation, or formal result.

8 mechanisms · View full form family

  • Common-Cause FMEA — Extends failure mode and effects analysis by asking which single causes could defeat multiple redundant elements or controls at once.
  • Copula Tail-Dependence Check — Models whether extreme losses co-occur more often than average correlation suggests, by fitting the pool's joint tail separately from its individual margins.
  • Diverse Data Source Triangulation — Combines independent data sources with different collection methods or bias profiles so the same informational function is not dependent on one fragile source.
  • Diversification Ratio Calculation — Compares aggregate pool risk with the sum or average of standalone risks, collapsing 'is this pool really diversified?' into one number — and the effective count of independent bets behind it.
  • Effective Independent Provider Count — Collapses a weighted, correlation-adjusted dependency portfolio into a single honest number — how many genuinely independent providers you effectively have, which is usually far fewer than you can name.
  • Exposure Accumulation Map — Maps concentration in geography, technology, supplier, factor, or shock source by tallying total pooled exposure behind each shared feature until hidden single points surface.
  • Fault Tree with Common-Cause Branching — Decomposes a top-level failure through logic gates to its basic causes, then adds shared-cause branches so a single event feeding several 'independent' paths becomes visible.
  • Stress-Correlation Scenario — Re-estimates pooling benefit under crisis-state co-movement by positing a common shock and rewriting the pool's correlations to the ones that shock would impose.

Assessment, Review & Assurance

A bounded evaluation of existing evidence, work, compliance, or readiness that produces a finding, approval, correction, or disposition.

5 mechanisms · View full form family

  • Common-Mode Dependency Audit — Traces whether a system's nominally independent alternatives actually converge on the same upstream provider, region, credential, owner, or trigger — turning "we have three suppliers" into "we have one shared failure point wearing three names."
  • Credential and Infrastructure Dependency Audit — Checks whether backup systems, emergency roles, and alternate channels still depend on the same identity provider, network, power source, cloud region, or access authority.
  • Diverse Vendor Review — Assesses whether vendor diversity is real across ownership, infrastructure, code lineage, hosting, support, credentials, and failure response capability.
  • Portability Checklist — A standing list of the concrete things — data, contracts, interfaces, credentials, skills, runbooks — that must be movable before an alternative provider counts as real rather than nominal.
  • Supply-Chain Dependency Review — Traces whether alternate suppliers, logistics routes, components, or raw materials share sub-tier vendors, regions, infrastructure, labor constraints, or regulatory chokepoints.

Control, Automation & Runtime

A state-dependent executable mechanism that senses, triggers, schedules, filters, throttles, routes, or actuates during operation.

3 mechanisms · View full form family

  • Backup Power System — Provides alternate electrical capacity for critical functions when the primary power source fails.
  • Diverse Implementation Voting — Compares outputs from independently designed implementations so one flawed implementation is less likely to determine the final result alone.
  • Pool Concentration Cap — Limits pool exposure to a dependence source that could undermine pooling, forcing a corrective move — halt, divert, hedge, or transfer — whenever a pre-set limit is breached.

Experiment, Test & Rehearsal

An active probe, controlled variation, simulated condition, or practiced execution used to generate evidence or readiness.

4 mechanisms · View full form family

  • Backup Independence Test — Exercises backup paths under a shared dependency outage or simulated common cause to verify whether they are genuinely independent.
  • Dependency Concentration Stress Test — Simulates the sudden loss, withdrawal, or price shock of the dominant provider or cluster and traces the blast radius — checking whether the substitutes and reserves that look adequate on paper actually absorb it.
  • Substitution Drill — A rehearsed, live cutover from an overweight provider to its alternatives under realistic load and timing, proving a diversification that looks good on paper actually holds when exercised.
  • Tabletop Cascade Exercise — Simulates a shared failure cause and asks how redundant paths, teams, authorities, and recovery plans respond when they are stressed together.

Interface, Display & Cue

A user-facing perceptual surface or interactive affordance that presents status, options, warnings, prompts, or controls.

1 mechanism · View full form family

  • Dependency Concentration Heatmap — Lays weighted dependency exposure onto a coloured grid — provider against function, geography, platform, and criticality band — so the overweight cells announce themselves at a glance.

Monitoring, Sensing & Alerting

Ongoing or repeated observation of actual state that emits measurements, indicators, dashboards, surveillance signals, or alerts.

1 mechanism · View full form family

  • Top-K Exposure Share — Reduces the whole dependency distribution to one governable number — the share of critical exposure carried by the largest one, three, or five providers — and watches it drift over time.

Organization, Role & Governance

An enduring actor, authority, body, program, service, pooled capacity, or institutional arrangement whose mandate, membership, resources, or continuity is operative.

5 mechanisms · View full form family

  • Backup Supplier Contract — Maintains an alternate source for critical inputs when the primary supplier cannot deliver.
  • Deputy Role Assignment — Names a prepared alternate actor who can perform a critical responsibility when the primary actor is absent or impaired.
  • Diverse Supplier Network — Uses suppliers with different geographies, ownership, logistics, technologies, or input sources to reduce correlated supply failure.
  • Mixed-Channel Service Delivery — Offers the same service through different channels such as online, phone, physical office, outreach worker, kiosk, or partner organization.
  • Standby Team Roster — Keeps a prepared group available to cover a critical operation during absence, overload, or incident response.

Protocol, Workflow & Routine

A repeatable ordered sequence of actions, handoffs, states, or escalation steps, including procedures, runbooks, routines, recovery sequences, and lifecycle workflows.

1 mechanism · View full form family

  • Manual Fallback Workflow — Preserves a function through a human or paper-based process when the digital, automated, or centralized path is unavailable.

Record, Log & Register

A durable, usually accumulating account of actual events, decisions, custody, exceptions, or state transitions whose value depends on history, provenance, or accountability.

2 mechanisms · View full form family

  • Correlated Risk Register — Records shared exposures, affected redundant paths, severity, mitigation owner, test evidence, and residual risk acceptance.
  • Residual Concentration Risk Register — The signed record of every concentration the organization has knowingly chosen to keep — who owns it, why it is tolerated, what compensates for it, and when it must be re-justified.

Representation, Specification & Plan

A non-executable information artifact that externalizes understood, desired, or future structure, including maps, matrices, templates, checklists, specifications, reports, plans, and schedules.

3 mechanisms · View full form family

  • Multi-Modal Transport Plan — Uses different transport modes such as road, rail, air, water, walking, or cycling to preserve movement of people or goods when one mode is disrupted.
  • Provider Load Split Table — The concrete allocation sheet that names what share of demand each provider is meant to carry, turning a diversification target into intended percentages and tiers.
  • Weighted Dependency Graph — Represents every dependency as a weighted, directed edge so that overweight providers and shared upstreams stop hiding behind a long, flat list of names.

Rule, Policy & Commitment

A standing constraint, permission, default, threshold, quota, obligation, right, or conditional action rule governing future behavior.

9 mechanisms · View full form family

  • Catastrophe Bond or Parametric Cover — A capital-market or trigger-based cover that pays when a specified catastrophic or parametric condition occurs.
  • Concentration Cap Policy — Sets explicit ceilings on how much of a critical function any single provider or common-mode cluster may carry, and defines the sign-off required to run above them.
  • Contingent Supply or Capacity Contract — A prearranged contract that supplies backup capacity, goods, logistics, or price terms under stress conditions.
  • Excess-of-Loss Reinsurance Contract — A reinsurance contract that pays losses above a specified attachment point up to a limit.
  • Hedging Overlay Contract — A financial or parametric contract that offsets a common driver affecting a pooled exposure.
  • Multi-Sourcing Rule — Requires a dependency class to keep two or more genuinely qualified, switchable providers once its concentration risk crosses a threshold — a floor on independence, not a ceiling on share.
  • N+1 Redundancy Rule — Sizes redundancy by provisioning one spare unit beyond the number needed to carry peak load, so any single unit can fail without dropping the function below its requirement.
  • Quota-Share Reinsurance Arrangement — A proportional reinsurance treaty that cedes a fixed percentage of every premium and loss across the whole book, relieving surplus strain.
  • Stop-Loss Cover — A contract that caps retained losses after an individual or aggregate threshold is reached.

Structure, Architecture & Configuration

An enduring physical, digital, spatial, material, or organizational topology, partition, boundary, component arrangement, or configured state.

6 mechanisms · View full form family

  • Alternate Communication Channels — Maintains distinct channels such as SMS, radio, phone trees, email, in-person notice, or public posting so communication can continue when one medium fails.
  • Emergency Reserve Stock — Stores critical materials, funds, equipment, or supplies for use when ordinary supply is interrupted.
  • Heterogeneous Technology Stack — Uses different technical implementations for critical capability so a single software defect, vendor outage, or platform assumption is less likely to disable all paths.
  • Independent Safety System — Provides a separate safety path using different sensing, control, energy, or actuation logic so one design flaw or dependency is less likely to defeat all protection.
  • Redundant Server — Duplicates computing capacity so a service, application, or data function can continue after one server fails.
  • Spare Part Stock — Keeps replacement parts available so a failed physical component can be replaced without waiting for external procurement.