Risk aggregation can reveal concentration

Ten moderate risks that all depend on the same supplier are not ten moderate risks.

Registers list items separately, which conceals common dependencies. Aggregating by what they have in common, the same provider, the same platform, the same credential, frequently reveals a concentration nobody has assessed because no single entry looked serious enough.

More on Governance and risk