Skip to content
       

Blog

The Vendor You Cannot Replace: Concentration Risk in Property Operations

The Vendor You Cannot Replace: Concentration Risk in Property Operations

The short answer

Property companies are accustomed to thinking about concentration on the revenue side: how much income depends on a single tenant or asset. Vendor concentration is a different kind of exposure, because a single vendor failure can disrupt operations across a site or a portfolio.

It also goes unexamined more easily, because vendor dependency does not look like risk. It looks like a good relationship. The contractor who has serviced the plant for fifteen years, knows where the shutoffs are and answers on a Sunday is genuinely valuable, which is exactly why replacing him would be difficult.

Your most dangerous vendor is usually your best one. Dependency in property is earned rather than neglected, and that is what makes it invisible.

Why isn't this on anyone's risk register?

Because the risk is often measured in the wrong currency.

Where vendor risk is assessed at all, it is frequently assessed by spend. That is the number a system can produce without being asked, so it becomes the proxy. But spend measures how much you pay someone, not how much trouble you are in if they disappear.

Third-party risk analysis draws the important distinction here: the question is not simply how much you spend with a supplier, but how critical the dependency is and how difficult it would be to substitute. Concentration can arise from relying on the same provider across multiple services or properties, from difficult-to-replace specialists, or indirectly through subcontractors sitting underneath several vendors. Business continuity guidance for 2026 puts it directly, arguing that the criteria for scrutinising a third party should be the criticality of the dependency and its substitutability, not merely the economic significance of the contract.

Apply that to a property portfolio and the picture inverts. Your largest vendor by spend may be a national supplier with contracts you could re-tender in a quarter. Your riskiest vendor might invoice a fraction of that and be the only person who understands a twenty-year-old building management system.

Spend is visible, but it does not tell you how difficult the dependency would be to replace. Replaceability is the harder question.

Four forms of dependency

Vendor dependency in property can take several forms. Four are particularly important in day-to-day operations, and they are not equally recoverable.

Form

What the vendor holds

What determines recovery

What it costs you

Knowledge

Undocumented understanding of the building

Documentation depth and availability of qualified alternatives

Diagnosis time, repeat visits, wrong repairs

Access

Keys, codes, credentials, system logins

Whether access is controlled by the property and can be transferred

Inability to enter or operate

Continuity

Work in flight, open jobs, part-completed projects

Amount of work in progress and availability of another provider

Stalled work, disputes, safety gaps

Compliance

Certifications tied to a statutory obligation

Qualification requirements, local supplier availability and time remaining before the deadline

Missed inspection deadlines, penalty exposure

Read the third column. The key question is how quickly the dependency can actually be transferred, not simply what another vendor would charge. That makes qualification requirements, documentation, access control and local supplier availability central to the assessment rather than incidental to it.

Form one: knowledge

The hardest to see and the slowest to recover.

Buildings accumulate undocumented knowledge. Which riser feeds which floor when the drawings say otherwise. Which valve was replaced out of sequence during a refurbishment. Which intermittent fault has a workaround nobody wrote down. A vendor who has serviced a building for a decade holds a substantial part of its operating history, and none of it appears in a contract.

When that vendor goes, some of that knowledge may leave with them unless it has been captured in your own records. A replacement arrives at market rate and takes longer on every call while rediscovering things his predecessor knew. That transition can take months, and it can look like poor performance by the new vendor rather than a knowledge transfer failure by you.

The uncomfortable version of this is that the dependency is often something you created. Every time a job is closed with a one-line note rather than a description of what was actually found, the knowledge stays with the vendor instead of moving into your record. Over ten years that compounds into a dependency nobody chose.

The counter is documentation discipline at the work order, which is a configuration decision rather than a vendor management one. We covered why work orders need to carry their full interaction history in where maintenance automation should stop, and knowledge retention is the second reason for it.

Form two: access

The fastest to bite and the easiest to fix.

Keys, alarm codes, gate access, roof hatch keys, plant room access, and increasingly logins to building systems: BMS, access control, lift monitoring, energy management. Vendors accumulate all of these across a relationship, and portfolios frequently have no register of who holds what.

The failure modes are mundane and expensive. A vendor relationship ends acrimoniously and access is not returned. A technician leaves the firm holding keys nobody reclaimed. A building system is administered under a vendor's account, so removing the vendor removes your ability to configure your own equipment.

That last one deserves specific attention as building systems become more connected. When a building system is set up under the vendor's credentials rather than yours, you have outsourced control of an asset you own. Establishing from the outset that administrative accounts are controlled by the property is usually straightforward. Recovering control after the relationship ends can be considerably harder.

Form three: continuity

The exposure that exists right now, whether or not anything has gone wrong.

At any moment a portfolio has work in flight: open work orders, part-completed projects, ordered materials, scheduled preventive maintenance. If a vendor fails suddenly, all of it stops in place.

Construction insolvency practice is instructive here, because that industry has thought hard about it. Guidance on contractor insolvency emphasises establishing direct relationships with key subcontractors through step-in rights, noting that existing subcontractors possess extensive knowledge of the work, which reduces uncertainty during a transition. The same guidance stresses efficient record keeping and management of the contractor's documents throughout, not after.

Property operations rarely apply that thinking to routine vendors, and the exposure is different but real. A site with a failed mechanical contractor mid-way through a plant replacement has an operational problem, a warranty problem and possibly a safety problem simultaneously.

Two practical protections, neither of which requires a new system:

  • Know who is actually doing the work.
    Where a vendor subcontracts, the relationship you depend on may be one you have never contracted with.

  • Keep the record on your side.
    Scope, photographs, part numbers and completion evidence should live in your system, not in the vendor's job sheets.

Form four: compliance

The one with a clock attached.

Some vendor relationships support statutory, regulatory or safety-related obligations: fire safety inspections, water system testing, lift inspections, backflow prevention, emergency lighting, sprinkler systems and similar requirements, depending on the jurisdiction and property type. Many have prescribed inspection, testing or certification intervals, and where applicable the work may need to be performed by a suitably qualified or authorised party.

Losing that vendor does not merely inconvenience you. It can put a deadline at risk that you cannot extend, and the qualified pool in some categories is genuinely limited. We covered the statutory side of this in the three clocks that run commercial property operations: the regulatory clock is the one you do not control, and it keeps running while you re-procure.

The specific question worth asking of every compliance-linked vendor is how many qualified alternatives exist within a reasonable radius, and whether anyone has ever confirmed that. The answer can be comfortable in markets with deep supplier pools and materially different in secondary markets or specialised categories.

What concentration is fine, and what is not

The article would be dishonest if it argued for eliminating dependency. Some concentration is commercially rational, reflecting scale efficiencies, technical qualification limits or a genuinely good relationship. The risk emerges when the organisation would suffer severe cost, service or continuity consequences if that dependency were impaired.

So the test is not how concentrated you are. It is what happens if the concentration breaks.

Situation

Often acceptable

Worth addressing

One landscaping contractor across a region

Yes, easily replaced

If they hold gate access nobody else has

One mechanical contractor per building

Often, given plant familiarity

If no documentation exists outside their head

One fire safety contractor

Depends on the qualified pool locally

If they are the only certified party you can reach

One vendor administering a building system

Rarely

Almost always, if credentials are theirs

One national supplier at high spend

Potentially, if alternatives and transition paths exist

If its failure would affect multiple critical sites simultaneously

Notice the pattern. The acceptability of a dependency has almost nothing to do with its size and almost everything to do with what would be hard to reconstruct.

The portfolio problem

A vendor can be replaceable at one property and still create concentration risk across the portfolio.

If the same contractor services forty buildings, the question is no longer simply whether another contractor could take over one site. It is whether the local market could absorb the entire workload quickly enough, and whether you have enough alternative coverage to avoid a portfolio-wide disruption. Replaceability that holds at building level can fail at scale.

The same applies when several apparently independent vendors rely on the same subcontractor or specialist. The concentration then sits one layer below the vendor relationship and stays invisible until something fails. Third-party risk practice increasingly treats these indirect dependencies as part of concentration analysis, and the property version is easy to miss: three different mechanical contractors across a region may all use the same controls specialist.

Portfolio-level concentration also compounds the other three forms. A vendor across forty buildings holds knowledge of forty buildings, access to forty buildings and work in flight at forty buildings, and the recovery is not forty separate small problems occurring conveniently one after another.

How to run a vendor concentration review

A focused review can produce a list that most organisations do not currently have.

  • Start with criticality, not spend. List the vendors whose disappearance would cause a problem within a week. Then compare that list against your vendor master and your spend data. The comparison is the exercise: it surfaces critical dependencies that a spend report alone would not show, and it also shows which large suppliers are less exposed than their invoices suggest.

  • For each one, ask four questions. What do they know that we do not? What do they hold that we would need? What is in flight right now? What deadline depends on them?

  • Score how long it would realistically take to restore the service, not just what the replacement would cost. A dependency that would take months to restore deserves attention regardless of contract value.

  • Map the blast radius. A vendor supporting one low-criticality site is different from the same vendor supporting dozens of properties or several critical building systems. Assess how many properties, processes and deadlines a single failure would touch.

  • Check the access register exists. If you cannot produce a list of which vendors hold which keys, codes and system credentials, that is the first output of the review.

  • Test one dependency. Ask a critical vendor to provide the documentation, access information and work-in-progress records that someone else would need to take over the service. What comes back tells you more than a questionnaire, and the exercise can be framed as ordinary continuity planning rather than as distrust.

This belongs alongside performance measurement rather than replacing it. A vendor scorecard tells you how well someone is doing the work. A concentration review tells you what happens if they stop, and those are different questions asked of the same vendor. Both depend on vendor records, credentials and work history living in one place, which is a vendor management configuration question as much as an operational discipline.

Where concentration risk shows up

Symptom

Which form

First action

One contractor is always called for a specific building

Knowledge

Audit work order detail for that site

Nobody can produce a list of who holds keys

Access

Build the access register

A building system can only be configured by the vendor

Access

Reclaim administrative accounts

Work order notes are one line long

Knowledge

Change the closure requirement

A compliance deadline slipped when a vendor was unavailable

Compliance

Map the qualified alternatives

You learn who the subcontractor is only when something goes wrong

Continuity

Require disclosure of subcontracted work

The same vendor appears across most of the portfolio

Portfolio

Map the blast radius before renewal

Frequently asked questions

Q1. What is vendor concentration risk in property management?
Dependence on a vendor for work that would be difficult, slow or impossible to transfer to someone else. It combines how critical the dependency is with how substitutable the vendor actually is, and the second factor is often the more revealing.

Q2. Is vendor concentration always a problem?
No. Some concentration is commercially rational, reflecting familiarity, scale or a limited pool of qualified providers. It becomes a problem when losing that vendor would cause severe service, cost or continuity consequences.

Q3. How do you measure vendor concentration risk?
There is no single metric. A useful review combines criticality, time to restore the service, operational impact, portfolio exposure, access, compliance dependencies and the availability of credible alternatives. Spend can be included but should not be the sole measure.

Q4. What should you do before a vendor relationship ends?
Recover access, retrieve documentation for work in flight, confirm administrative credentials for any systems they configured, and establish who else is qualified for anything compliance-linked. Doing this after the relationship sours is considerably harder.

Q5. Why is spend a poor measure of vendor risk on its own?
Because it measures what you pay rather than what you would lose. Large national suppliers are often re-tenderable, while a small specialist holding undocumented knowledge of a building can be far harder to replace.

Q6. What vendor dependency is most often overlooked?
One frequently overlooked dependency is administrative control of building systems. When a BMS, access control or energy management system is configured under the vendor's account rather than the property's, control of an owned asset sits with a third party.

Q7. How does vendor concentration differ from vendor performance?
Performance measures how well the work is done. Concentration measures what happens if it stops. A vendor can score highly on one and represent significant exposure on the other, which is why a scorecard alone does not surface this.

Q8. What should a vendor concentration review produce?
A short list of critical vendors ranked by time to restore, an access register showing who holds what, a documentation gap list, a blast radius assessment across the portfolio, and a map of qualified alternatives for anything tied to a statutory deadline.

The real point about dependency

Vendor management in property is usually framed as getting better value: rates, response times, scorecards, re-tendering. Those are worth doing and they answer a question about performance.

They do not answer the question this article is about, which is what your operation looks like on the morning a vendor stops answering. That scenario is not remote. Firms fail, key people retire, relationships end badly, and specialists move on. When it happens, the loss is not the contract. It is the knowledge, access, work in flight and certification that left with them.

The dependency is not a failure of management. It is what happens when a relationship works well for long enough. But a dependency you have chosen is a different thing from one you discovered, and the distinction is worth an afternoon.

RIOO brings vendor, work order and property operational records together on a platform built on NetSuite, helping property teams keep critical operational information accessible rather than leaving it distributed across vendor relationships. See how vendor management works.