Skip to content

Concentration Cap Policy

Policy — instantiates Dependency Concentration Control

Sets explicit ceilings on how much of a critical function any single provider or common-mode cluster may carry, and defines the sign-off required to run above them.

Version
v1 · 2026-08-24 · History
Mechanism #
1683
Type
Policy
Form family
Rule, Policy & Commitment
Solution family
Scaling & Capacity
Problem family
Fragility, Failure & Continuity Risk
Problem subfamily
Dependency Concentration & Common-Mode Loss
Origin domain
Economics & Finance
Also from
Logistics & Supply Chain Management
Instantiates
Dependency Concentration Control

Measuring concentration only matters if something forbids it from getting worse. Concentration Cap Policy is the standing rule that fixes a ceiling — no single provider (or correlated cluster) may carry more than a stated share of a given critical function — and, just as importantly, names the exception path: who must sign off, and against what compensating controls, to operate above the cap. Its defining move is turning "too concentrated" from a matter of opinion into a pre-committed limit the organization agreed to before any specific vendor was on the table, so the argument happens at policy-setting time rather than in the middle of a renewal negotiation. It is a ceiling and an escalation rule, not a measurement and not a fix.

Example

A contract manufacturer writes a Concentration Cap Policy for its critical bill of materials: for any component rated production-critical, no single supplier may hold more than ≈40% of annual volume, and no single country of origin more than ≈60%. A key capacitor currently sits at ≈78% with one vendor. Under the policy that is a breach, so it cannot simply persist quietly — it triggers the exception path: the category manager must file a residual-concentration acceptance, time-boxed to the next sourcing cycle, signed by the VP of Operations, and paired with a qualification plan for a second supplier.

The policy doesn't itself find the second supplier or move the volume; it makes the ≈78% visible as a decision someone owns rather than an accident everyone tolerates. A year later the same cap forces the review that catches the number drifting back up after the second source underperforms. The cap is a standard instance of a single-name exposure limit, long used in credit and counterparty risk to bound reliance on any one party.[n1]

How it works

  • Set the ceiling per criticality tier. Attach a maximum allowable share to each class of dependency, tighter for the functions whose loss hurts most; the limit is expressed in the same exposure unit the measurement layer reports.
  • Define the breach response. State what happens automatically when a provider crosses the cap — a required rebalancing plan, a second-source qualification, or a documented exception.
  • Require named acceptance for residuals. Any concentration that stays above the cap must be explicitly accepted by a named owner, time-boxed, and reviewed — never left as a silent default.

Tuning parameters

  • Cap height — the ceiling share itself. A low cap forces diversification hard but can be impossible where the market is genuinely thin; a high cap is easy to meet but leaves real single-point risk.
  • Aggregation unit — whether the cap counts by named provider, by common-mode cluster, by geography, or by criticality tier. Capping by cluster (not by name) is what stops three "different" vendors that share a root from each sitting comfortably under the line.
  • Exception friction — how senior the sign-off and how short the time-box for running over cap. High friction deters convenient over-reliance; too high and teams route around the policy entirely.
  • Review cadence — how often standing exceptions must be re-justified before they expire.

When it helps, and when it misleads

Its strength is that it moves the concentration argument upstream of any particular deal: because the ceiling was agreed in the abstract, no single vendor's charm or discount can quietly push reliance past it without someone signing for the risk. It also converts silent drift into a scheduled, owned decision.

Its failure modes are the failure modes of any limit. A cap set by counting names rather than effective providers is trivially satisfied by correlated alternatives — the policy must cap the cluster, or it caps nothing. The classic misuse is calibrating the cap to wherever exposure already sits so that the policy blesses the status quo and never binds; a cap that has never once triggered an exception is usually a cap set too high on purpose. And a ceiling says nothing about whether a compliant-but-fragile portfolio can actually absorb a loss. The discipline that keeps it honest is to set the cap against criticality and effective independence, to track how often it binds, and to let exceptions genuinely expire rather than rolling forever.

How it implements the components

Concentration Cap Policy fills the governing side of the archetype — it constrains and adjudicates, it does not measure or remediate:

  • concentration_limit_band — its core artifact: the stated ceiling (and any floor) on allowable share, per criticality tier and aggregation unit.
  • residual_concentration_acceptance — the named, time-boxed sign-off that any over-cap concentration requires in order to persist.

It does not measure where concentration currently sits (that's Effective Independent Provider Count and Dependency Concentration Heatmap), mandate a minimum number of sources (that's Multi-Sourcing Rule), or log each accepted breach over time (Residual Concentration Risk Register); the cap sets the line those mechanisms measure against and act on.

  • Instantiates: Dependency Concentration Control — the cap is the pre-committed limit the whole appraisal enforces against.
  • Consumes: Effective Independent Provider Count supplies the current concentration reading the cap is checked against.
  • Sibling mechanisms: Multi-Sourcing Rule · Effective Independent Provider Count · Dependency Concentration Heatmap · Residual Concentration Risk Register · Provider Load Split Table · Common-Mode Dependency Audit

Editorial Notes

Form Classification

Form family: Rule, Policy & Commitment

Rationale: Sets explicit ceilings on how much of a critical function any single provider or common-mode cluster may carry, and defines the sign-off required to run above them, making its operative form a standing rule, threshold, contractual commitment, or policy constraint governing future conduct.

Independent corroboration: The frozen evidence defines Concentration Cap Policy as 'Sets explicit ceilings on how much of a critical function any single provider or common-mode cluster may carry, and defines the sign-off required to run above them', so its operative form is Rule, Policy & Commitment.

Review outcome: Independent reviewer agreement; high confidence.

Origin Attribution

Primary origin: Economics & Finance

Origin pattern: Cross-disciplinary synthesis

Present-day reach: Multi-domain

Rationale: Credit and counterparty-risk practice cohered single-name and large-exposure limits with formal exception authority.

Related originating lineages:

Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.

Review outcome: Independent reviewer agreement; high confidence.

Notes

[n1] A single-name or large-exposure limit caps how much of a portfolio's risk may rest on any one counterparty — a standing feature of credit and counterparty-risk frameworks, where a firm's exposure to a single client is bounded as a fraction of its capital. This policy applies the same logic to operational dependencies rather than credit exposures.