Supplier concentration risk is the kind of problem that is completely invisible until the exact day it is not: a single-source component, a single region, a single supplier whose disruption stops a line, discovered only after it happens.
Why it stays hidden
Concentration risk usually is not the result of a decision anyone consciously made. It accumulates: a supplier wins more business over time because they are reliable and competitively priced, which is a reasonable outcome of good sourcing, right up until that same reliability means nobody diversified away from them and a disruption on their end has nowhere to fail gracefully to.
Making it visible without a special project
The usual way concentration risk gets assessed is a dedicated risk review, run periodically, pulling data from wherever it happens to live. That works as a snapshot. It does not catch concentration building up between reviews. The alternative is making supplier concentration a property of the material master itself: every part number carries a visible count of qualified alternate suppliers, so a single-source dependency is flagged as data changes, not discovered eighteen months later in a risk workshop.
What this requires
The same foundation as everything else on this list: a consolidated registry per material, with the approved vendor list connected to it, rather than concentration risk living in a separate spreadsheet someone updates twice a year.

