The same concentration analysis applied to suppliers is almost never applied to the organisation's own internal dependencies.
Why it matters when the plan changes
Organisations examine external dependencies carefully because a supplier failure is visible and contractual; frameworks such as Article 28 of the General Data Protection Regulation formalise this by requiring written authorisation before a processor can engage another processor. Internal dependencies of exactly the same shape, where a plan runs through one team or one person with no alternative, receive nothing comparable, even though they fail more often and are equally capable of stopping delivery, particularly the cross-team commitments a strategy actually depends on.
The tension is that internal dependencies are harder to write down. A supplier relationship has a contract, a service level and a name. An internal dependency on a particular manager's relationships has none of those, which is why it does not appear on any register despite being the same kind of exposure; Harvard Business Review research found only nine per cent of managers say they can rely on colleagues in other functions and units all the time.
In practice
A business maintains a supplier risk register scoring twelve vendors on concentration and switching cost. Its most critical dependency is a single internal team that four workstreams rely on and that has no capacity for a fifth. That appears on no register, because registers are for suppliers.
Evidence
A processor may not engage another processor without written authorisation, which is the kind of control applied to suppliers and not to internal dependencies.
Article 28, General Data Protection Regulation (2016)Cross-unit commitments are the least reliable part of execution, which describes internal dependencies as much as external ones.
Donald Sull, Rebecca Homkes and Charles Sull, Why Strategy Execution Unravels and What to Do About It, Harvard Business Review (2015)
What it cannot tell you
Vendor management assessment covers relationships with a contract, a named counterparty and a service level. It has no method for a dependency that runs through an internal team or a single manager's relationships, since its framework does not recognise a counterparty without those features. Applied only to suppliers, it leaves the largest concentration risks in a plan unexamined.
Questions
Vendor assessment covers financial stability, delivery performance, security and compliance posture, concentration of spend, and the cost of switching away. Contractual protections matter too: Article 28 of the General Data Protection Regulation (2016) requires written authorisation before a processor engages another, the kind of control rarely applied inside the organisation.
Because they have no contract, no named counterparty and no service level, so nothing in the procurement process is able to reach them. They are also nobody's job, since the function that assesses suppliers has no mandate to examine anything inside the organisation itself.
The same questions applied to internal dependencies: what does the plan rely on, who provides it, what happens if they cannot, and is there an alternative. Written down, that is a short list that most organisations could produce in a day and have never produced.
Key person risk is the individual case of the same analysis: any dependency with no alternative is a concentration, whether it sits with a supplier or a person. Research published in Harvard Business Review in 2015 found only nine per cent of managers can rely on colleagues in other functions all the time.
On the same risk register as everything else, owned by the body that owns risk rather than by a function. Keeping it separate is what has allowed the most consequential dependencies in many plans to sit outside every formal review.