Home / Guides / Risk Aggregation, Concentration, and Interdependence
Guide

Risk Aggregation, Concentration, and Interdependence

How individually manageable risks can combine into larger exposure through shared causes, dependencies, or timing.

By Adrian M. FenwickReviewed August 3, 2026

Risks are often assessed one at a time, but organizations experience them as a portfolio. Aggregation occurs when exposures combine. Concentration occurs when several activities depend on the same resource, location, supplier, technology, funding source, or decision-maker.

Common concentrations

  • Single or related suppliers
  • Shared systems, data, networks, or facilities
  • Critical knowledge held by few people
  • Several projects competing for the same capacity
  • Common contractual or regulatory exposure
  • Geographic concentration

Interdependence changes severity

One event can increase the likelihood or impact of another. A supplier delay may compress a schedule, create overtime, reduce testing, and increase quality risk. Static registers often miss this sequence.

Ways to explore combined exposure

  • Dependency maps
  • Scenario analysis and stress testing
  • Common-cause reviews
  • Portfolio heat maps with concentration overlays
  • Network analysis where justified
  • Cross-functional workshops

Avoid simple addition

Risk scores are usually ordinal and should not be added as if they were financial amounts. Use scenarios, ranges, dependency analysis, and measures appropriate to the decision.

Management responses

Diversify dependencies where practical, create contingency capacity, separate failure domains, strengthen recovery, coordinate treatments, and assign ownership for cross-cutting risks.

Use with judgmentRisk methods support decisions; they do not remove uncertainty. Record assumptions, limits, and acceptance authority.

Look beyond individual entries

Registers often score risks separately even when they share a supplier, system, location, skill, funding source, control, or assumption. Aggregation asks whether several exposures could materialize together or compete for the same response capacity. Concentration may be hidden when risks sit in different departments.

Map dependencies and common causes

Useful methods include tagging common dependencies, reviewing risks by objective or resource, drawing simple network maps, and testing scenarios that affect multiple areas. Quantitative models may help in some settings, but a well-facilitated cross-functional review can reveal important concentrations without complex software.

Questions for portfolio reviews

  • Which risks depend on the same third party or technology?
  • Could one event trigger several register entries?
  • Would treatment actions compete for scarce people or funding?
  • Are impacts being counted twice or omitted between owners?
  • Does the combined exposure exceed appetite even if each risk does not?