Risks are often assessed one at a time, but organizations experience them as a portfolio. Aggregation occurs when exposures combine. Concentration occurs when several activities depend on the same resource, location, supplier, technology, funding source, or decision-maker.
Common concentrations
- Single or related suppliers
- Shared systems, data, networks, or facilities
- Critical knowledge held by few people
- Several projects competing for the same capacity
- Common contractual or regulatory exposure
- Geographic concentration
Interdependence changes severity
One event can increase the likelihood or impact of another. A supplier delay may compress a schedule, create overtime, reduce testing, and increase quality risk. Static registers often miss this sequence.
Ways to explore combined exposure
- Dependency maps
- Scenario analysis and stress testing
- Common-cause reviews
- Portfolio heat maps with concentration overlays
- Network analysis where justified
- Cross-functional workshops
Avoid simple addition
Risk scores are usually ordinal and should not be added as if they were financial amounts. Use scenarios, ranges, dependency analysis, and measures appropriate to the decision.
Management responses
Diversify dependencies where practical, create contingency capacity, separate failure domains, strengthen recovery, coordinate treatments, and assign ownership for cross-cutting risks.
Look beyond individual entries
Registers often score risks separately even when they share a supplier, system, location, skill, funding source, control, or assumption. Aggregation asks whether several exposures could materialize together or compete for the same response capacity. Concentration may be hidden when risks sit in different departments.
Map dependencies and common causes
Useful methods include tagging common dependencies, reviewing risks by objective or resource, drawing simple network maps, and testing scenarios that affect multiple areas. Quantitative models may help in some settings, but a well-facilitated cross-functional review can reveal important concentrations without complex software.
Questions for portfolio reviews
- Which risks depend on the same third party or technology?
- Could one event trigger several register entries?
- Would treatment actions compete for scarce people or funding?
- Are impacts being counted twice or omitted between owners?
- Does the combined exposure exceed appetite even if each risk does not?