Residual Concentration Risk Register¶
Governance register — instantiates Dependency Concentration Control
The signed record of every concentration the organization has knowingly chosen to keep — who owns it, why it is tolerated, what compensates for it, and when it must be re-justified.
Some concentration cannot be engineered away: only one clearing house exists, the sole qualified supplier is the market, the migration would cost more than the risk it removes. Residual Concentration Risk Register is where such exposure is accepted on the record rather than quietly ignored. Its defining move is to turn tolerated risk from a silent oversight into a dated, owned decision: every concentration left standing after measuring, capping, diversifying, and drilling gets an entry with a named owner, a written rationale, the compensating controls that make it bearable, and an expiry date by which it must be re-justified. It governs the exceptions — the risk you choose to live with — not the limit itself and not the measurement.
Example¶
A bank finds it settles ≈95% of a certain instrument through a single provider, and no alternative exists at scale this year. It cannot diversify that exposure away on any near horizon. Rather than let the concentration sit unspoken, it enters the register: owner = Head of Operations; rationale = no qualified alternative at required scale; compensating controls = a contractual resilience commitment, a manual fallback runbook, and a segmentation firebreak; acceptance valid until the next annual review, with an early-reopen trigger if the provider's own concentration worsens. The exposure does not shrink — but it stops being invisible, acquires an accountable name, and carries a date on which someone must argue for it again.[1]
How it works¶
- Catch what survives the remedies. An exposure exceeds the cap and cannot be rebalanced now, so instead of vanishing from view it earns an entry.
- Attach accountability. Each entry names an owner, a rationale, the compensating controls relied on, and a review/expiry date — no accepted concentration without a name against it and a date on it.
- Time-box the acceptance. Tolerance lapses and must be re-argued, so a "temporary" exception cannot quietly harden into permanent structure.
- Stay a record, not a detector. It documents the human decision to tolerate; the measuring and monitoring that feed it live in other mechanisms.
Tuning parameters¶
- Acceptance authority — how senior the sign-off must be, scaled to the size of the exposure; trivial concentrations need not reach the board, systemic ones must.
- Expiry horizon — how long an acceptance holds before mandatory re-justification; shorter keeps the register honest but costs review effort.
- Compensating-control bar — how much mitigation is required before an exposure may be accepted at all.
- Escalation trigger — what change (a provider merger, measured drift, a failed drill) forces early re-review rather than waiting for expiry.
- Visibility — a private operational log vs. a board-visible register; wider visibility raises the cost of letting entries rot.
When it helps, and when it misleads¶
Its strength is that it makes unavoidable concentration explicit, owned, and revisited, instead of letting exceptions accumulate silently until an incident enumerates them for you. Time-boxing is what stops "temporary" from becoming permanent.
Its failure mode is that the register is the archetype's easiest place to launder risk: an entry can decay into a rubber stamp that quietly converts "we should fix this" into "we accepted this," and a register full of never-expiring acceptances is worse than none because it wears the appearance of control. The classic misuse is writing an acceptance after the fact to retroactively bless a concentration nobody actually intends to reduce. The discipline that keeps it honest is hard expiry dates, a genuinely accountable named owner per entry, and a periodic challenge that forces every open item to re-earn its place.
How it implements the components¶
Residual Concentration Risk Register fills the governance-and-ownership side of the machinery:
residual_concentration_acceptance— the register is the instrument for accepting, owning, and time-boxing the concentration that cannot currently be removed, with its rationale and compensating controls recorded.
It is a deliberately narrow, single-component mechanism. It does not measure the concentration (concentration_measure, concentration_drift_monitor → Top-K Exposure Share), set the limit the exposure breaches (concentration_limit_band → Concentration Cap Policy), or reduce the exposure at all (load_rebalancing_plan → Provider Load Split Table; shadow_capacity_reserve → Substitution Drill); it records the human decision to tolerate whatever survives all of those.
Related¶
- Instantiates: Dependency Concentration Control — it holds the concentration the rest of the archetype could not remove.
- Consumes: Top-K Exposure Share for the measured breach, and the Concentration Cap Policy for the threshold that breach exceeds.
- Sibling mechanisms: Top-K Exposure Share · Concentration Cap Policy · Multi-Sourcing Rule · Substitution Drill · Provider Load Split Table · Portability Checklist · Weighted Dependency Graph · Effective Independent Provider Count · Dependency Concentration Heatmap · Common-Mode Dependency Audit · Dependency Concentration Stress Test
Editorial Notes¶
Form Classification¶
Form family: Record, Log & Register
Rationale: Residual Concentration Risk Register operates as a persistent ledger, log, register, or case record that preserves history and traceability because it the signed record of every concentration the organization has knowingly chosen to keep — who owns it, why it is tolerated, what compensates for it, and when it must be re-justified.
Independent corroboration: The frozen evidence defines Residual Concentration Risk Register as 'The signed record of every concentration the organization has knowingly chosen to keep — who owns it, why it is tolerated, what compensates for it, and when it must be re-justified', so its operative form is Record, Log & Register.
Review outcome: Independent reviewer agreement; high confidence.
Origin Attribution¶
Primary origin: Economics & Finance
Origin pattern: Convergent development
Present-day reach: Multi-domain
Rationale: Concentration risk is a financial portfolio construct requiring identification, board oversight, information systems, limits, stress testing, and ongoing monitoring; audit practice signs and controls the record.
Related originating lineages:
- Accounting & Auditing — accounting_auditing contributes measurement, signed records, and controlled-resource stewardship to the mechanism’s formative or independently convergent form; that contribution does not displace the primary economics_finance lineage.
- Organizational & Management Science — organizational_management contributes ownership, portfolio review, coordination, and operational governance to the mechanism’s formative or independently convergent form; that contribution does not displace the primary economics_finance lineage.
Review resolution: The blind reviewers disagreed on primary lineage; authoritative research supports economics_finance over the competing primary. Concentration risk is a financial portfolio construct requiring identification, board oversight, information systems, limits, stress testing, and ongoing monitoring; audit practice signs and controls the record. The cited OCC: Concentration Risk Management Guidance provides direct evidence for that defining form. Alternates are retained only where they contributed an independent formative tradition, while domain_reach=multi_domain records later transfer separately from historical origin.
Review outcome: Researched adjudication after independent review; high confidence.
Sources consulted:
Notes¶
The register is deliberately the last stop in the archetype: everything upstream — measure, cap, diversify, drill — exists to remove concentration, and the register only holds what genuinely survives all of it. A register growing faster than the rebalancing that is supposed to drain it is a sign the organization is concentrating under the cover of documenting, not controlling.
References¶
[1] European Parliament and Council of the European Union. "Regulation (EU) 2022/2554 … on Digital Operational Resilience for the Financial Sector". Official Journal of the European Union L 333: 1–79 (2022). Requires concentration exposures to be documented, assigned to accountable risk oversight, and revisited through regular review without imposing strict caps. registry ↩