CFOSuppliersRisk

Supplier Concentration Audit: Detecting Dependencies Before They Become Costly

30% of spend with a single supplier is an invisible risk — until that supplier raises prices or disappears. Claude detects it in 30 seconds.

The Spendesk MCP Team·9 July 2026·5 min read
Supplier Concentration Audit: Detecting Dependencies Before They Become Costly

The Problem

Supplier concentration is one of the least-monitored financial risks in scale-up finance teams. Everyone knows Salesforce is a big line item — but does anyone know exactly what percentage of total spend it represents? Or whether there are other suppliers that, combined, account for more than 30% of all purchases?

This kind of intelligence doesn't surface in a dashboard. You have to export 12 months of spend, group by supplier, calculate relative shares, and decide on an alert threshold. That's a 3–4 hour task for a finance team — and in practice, it never happens until after an incident: a supplier that suddenly raises prices, gets acquired, or starts experiencing service disruptions.

The risk isn't purely financial. A supplier that represents 25% of your IT spend and suffers an extended outage can bring operations to a halt. Supplier dependency is also operational exposure — and most CFOs don't measure it until it's too late.

What the Spendesk MCP Changes with Claude

With the MCP, Claude analyses the full structure of your supplier spend across any period in seconds. It calculates concentration indices, flags critical dependencies, and proposes concrete actions — no export required.

Claude Code — MCP Spendesk
Vous
Analyse our supplier concentration over the last 12 months. What are our dependency risks?
spendesk_analyze_spendget_suppliers
C

Supplier Concentration Analysis — July 2025 to June 2026

Total spend analysed: 2,847,300 €

Top 10 suppliers by spend share:

RankSupplier12-month spendShare of totalCategory
1Salesforce312,400 €10.9%CRM SaaS
2AWS287,600 €10.1%Infrastructure
3Deloitte198,200 €6.9%Consulting
4Workday156,800 €5.5%HR SaaS
5Stripe143,100 €5.0%Payments
6Google Workspace98,400 €3.4%Productivity
7Datadog87,200 €3.1%Observability
8HubSpot76,300 €2.7%Marketing SaaS
9Legalstart62,100 €2.2%Legal
10Personio58,400 €2.1%HR SaaS

HHI (Herfindahl-Hirschman Index): 412

HHI < 1,000 = low concentration ✅ — your supplier portfolio is relatively diversified.

Dependency alerts:

⚠️Salesforce + AWS combined = 21.0% of total. A disruption to either would have immediate operational impact.
⚠️Top 3 suppliers = 27.9% of total. If Deloitte raises fees by 15%, that's +29,700 € annual impact.
⚠️HR SaaS category: Workday + Personio = 7.6% of total for a single business function — a potential overlap worth investigating.

Would you like a category-level breakdown or a price impact simulation for Salesforce?

Going Further: 2 Additional Use Cases

Identifying SaaS suppliers without annual contracts

Some SaaS suppliers are billed monthly without commitment — which makes them flexible but also vulnerable to immediate price increases. Claude can identify suppliers representing more than 5% of total spend that lack annual contract protection.

Claude Code — MCP Spendesk
Vous
Which SaaS suppliers represent more than 5% of our total spend and don't have an annual contract?
spendesk_analyze_spendget_suppliers
C

I've cross-referenced spend data with the contract information recorded in Spendesk.

SaaS suppliers > 5% of total — contract status:

SupplierAnnual spendShare of totalBilling typeRisk
Salesforce312,400 €10.9%Annual contract — renews Oct 2026✅ Secured
AWS287,600 €10.1%Monthly pay-as-you-go⚠️ No commitment
Workday156,800 €5.5%Annual contract — renews Jan 2027✅ Secured
AWS (287,600 €) is your only major supplier without an annual contract. A price increase from AWS would give you no contractual notice period.
⚠️Recommendation: explore AWS Savings Plans (1-year commitment) — estimated savings: 15–20% on EC2 instances, approximately 40–55k€ per year.

Would you like a savings simulation by instance type based on the last 6 months of AWS usage?

Detecting suppliers with a single point of contact

A supplier relationship managed by only one person internally is a continuity risk. If that employee leaves, the contractual relationship, account access, and institutional knowledge leave with them.

Claude Code — MCP Spendesk
Vous
Identify suppliers where we only have a single point of contact — relationship dependency risk.
get_suppliers
C

I've analysed the contact information recorded in Spendesk for each active supplier.

Suppliers with a single contact (relational dependency risk):

SupplierSingle contactRole12-month spendRisk level
DeloitteSophie MarchandCFO198,200 €🔴 High
LegalstartThomas BrunHead of Legal62,100 €🟡 Medium
PersonioCamille GirardCHRO58,400 €🟡 Medium
DatadogMarc LefebvreCTO87,200 €🔴 High
⚠️Deloitte (198,200 €/year): the relationship is managed exclusively by Sophie Marchand (CFO). If she leaves, the account is at risk.
⚠️Datadog (87,200 €/year): managed solely by the CTO. Portal access and negotiated pricing terms are likely undocumented.
Recommendation: for each high-risk supplier, designate a secondary contact in Spendesk and document current contractual terms.

Would you like me to generate a list of suppliers with no contract documentation recorded in Spendesk?

Key Takeaways

  • Supplier concentration is both a financial and operational risk — often invisible until an incident occurs
  • The HHI index, calculated automatically, gives an objective measure of your portfolio's concentration level
  • SaaS suppliers above 5% of spend with no annual contract represent immediate pricing exposure
  • A single internal contact per supplier is a continuity risk that's easy to document and fix
  • Claude turns a 3–4 hour analysis into a 30-second answer, repeatable every quarter

Related skills