ALL INSIGHTS

Mapping Concentration Risk in Your Operations Supply Chain

The risk register entry was complete. Every critical vendor was listed, scored, and reviewed on schedule. The carrier had vendor governance. What it did not have was a concentration map - and when the CPS 230 review arrived, those were not the same thing.

‍

A Vendor List Is Not a Risk Map

‍

Concentration risk in operations supply chains is not a new concept. What changed on 1 July 2025, when CPS 230 came into force, is that APRA now requires carriers to actively manage it - not merely list the vendors involved. The standard requires identification and active management of concentration risk in critical operations, including third-party dependencies. A vendor list satisfies the listing requirement.

‍

Demonstrating you understand what happens if any single provider fails satisfies the management requirement. Most carriers have done the first. Fewer have done the second with enough rigour to survive a formal review.

‍

Where Concentration Risk Actually Lives

‍

A vendor list and a concentration map answer different audit questions. A vendor list records who provides each service. A concentration map records which services share the same provider, geography, technology platform, or key personnel - and what the operational consequences are when that shared dependency fails.

‍

Most carriers have vendor registers that passed previous audit cycles. They have less frequently asked what those vendors have in common. A BPO handling claims assessment and a system integrator managing platform maintenance may appear as two separate entries. If both operate from the same city, or run on the same technology stack, or depend on the same specialist workforce, they represent a single point of failure that the vendor list does not surface.

‍

This is where concentration risk hides: not in the individual entries, but in the relationships between them.

‍

The Three Concentration Vectors Worth Mapping

‍

The instinct when starting a concentration mapping exercise is to focus on geography - what happens if a region goes offline. Geographic exposure matters, but it is one of three vectors that require attention.

‍

The first is geographic: multiple critical vendors operating from the same location. The second is platform: multiple services depending on the same technology stack, so a platform incident disables more than one critical function simultaneously. The third is personnel: key individuals with critical knowledge serving multiple vendor arrangements, creating dependence on specific people rather than institutional capability.

‍

Each vector creates a distinct failure mode. Geographic concentration produces disruption when a location fails. Platform concentration produces cascading failures when a system goes offline. Personnel concentration produces knowledge loss when individuals are unavailable. The carriers with the most defensible CPS 230 position are not those with the fewest vendors - they are the ones who have mapped each failure mode and prepared a response before the event.

‍

What a Useful Concentration Map Looks Like

‍

For each critical operation, the map documents: the primary vendor, any dependencies shared with other critical operations, the geographic and platform footprint of those dependencies, and the maximum tolerable downtime if the shared dependency fails.

‍

That final figure is the test. If no number has been assigned to it, the concentration risk has not been quantified - and a map without that figure is a vendor list with extra columns.

‍

Once the map exists, the question is which concentration points require active management under CPS 230. The standard does not require zero concentration risk. It requires carriers to demonstrate active management: knowing where concentration exists, knowing the failure mode, and having a credible response ready before the event. For many carriers, that response involves a second source on critical operations - one that can carry load without a training runway. A second source that needs ramp time does not resolve the concentration risk. It moves the point of failure forward.

‍

The Conversation Worth Having

‍

ISSI operates as a warm second source on the platforms ANZ carriers already run. Because platform fluency on CyberLife, wmA, and Ingenium already exists, there is no ramp period before load can be carried. ISO 22301-class business continuity protocols and audit-passed credentials provide the governance documentation CPS 230 assessments require. If concentration risk mapping is active in your organisation, it is worth thirty minutes.

‍

‍

‍

‍

‍

Sources: APRA Quarterly Life Insurance Performance Statistics (2025); APRA Quarterly Insurance Performance Statistics (September 2025)

No items found.

Recent Insights

Read more
Culture and Social Responsibility

Celebrating Filipino Language through ISSIng Along: OPM Duets

ISSI Corp celebrates Buwan ng Wika through ISSIng Along: OPM Duets.

September 8, 2026
3 min
Read more
Industry Trends

What Great Claims Leadership Looks Like in 2026

Most claims leader job descriptions still read like they were written for a queue-management environment. Manage the team. Deliver the SLA. Produce the quarterly report. The accountability the role actually carries in 2026 is different in character.

August 27, 2026
5 min
Read more
Industry Trends

Systemic Fixes Have a Cost Dividend

Insurance service expenses grew 7% year-on-year at industry level through September 2025, even as carriers ran efficiency programmes. Other insurance expenses as a proportion of premium rose from 15% to 18% in the twelve months to June 2025. These numbers do not move with efficiency interventions alone, because efficiency programmes address the cost of doing the work - not the cost of doing the wrong work.

August 25, 2026
5 min