Find where revenue, inputs, permission, geography, or knowledge depends on a small number of relationships—and what the available records still leave unknown.
Can CompanyGraph screen for hidden business vulnerabilities today?
CompanyGraph does not currently have live interpretations for customer concentration, supplier dependency, regulatory dependency, or key-person risk. These conditions cannot be selected as presets, and the screener cannot derive them from a company's leverage, margin, or cash-flow ratios.
The search question remains useful because business dependence often appears in filings before it becomes visible in aggregate financial ratios. The relevant task is to identify what the company needs from a particular customer, supplier, location, licence, platform, or person; how much revenue or operating capacity depends on it; and what work, time, money, and authority would be required to replace it.
How does customer concentration appear in company filings?
Customer concentration is usually recorded as a share of revenue or receivables attached to one counterparty. The IFRS Foundation's IFRS 8 overview describes disclosures about operating segments, geographical areas, and major customers. Those disclosures can show that a material portion of reported revenue came from a small number of customers.
The percentage is a recorded condition, not the complete business relationship. It does not show whether the customer has a long enforceable commitment, can change volume at short notice, owns required tooling, supplies working capital, controls access to an end market, or could be replaced at a comparable margin. Those facts determine whether concentrated revenue also means concentrated authority over the company's feasible actions.
What does supplier dependency require beyond a supplier list?
A critical supplier is not defined only by purchase value. A low-cost component, licence, data feed, mould, chemical, transport route, utility connection, or specialised machine can stop a much larger process when no qualified substitute is available at the required place and time.
Supplier risk therefore depends on replacement lead time, technical qualification, inventory coverage, alternative capacity, logistics, contractual rights, and the buyer's ability to finance a transition. A statement that the company uses multiple suppliers may still hide a common second-tier source or shared infrastructure. A named sole source may be manageable when inventory, tooling, and an approved alternative already exist.
How should regulatory and geographic exposure be read?
Regulation can both permit and constrain a business. A licence, reimbursement rule, spectrum allocation, product approval, concession, tariff, or government contract can enable revenue while limiting who may operate and how prices are set. The dependency is not simply “more regulation means more risk”; it is the specific permission or rule without which the present process cannot continue.
Geographic revenue disclosures identify where customers or assets are recorded, but location labels can hide the operating route. Revenue booked to one country may depend on a factory, port, cloud region, payment network, water source, or regulator elsewhere. The useful map follows the actual input, infrastructure, permission, and cash-collection path rather than stopping at the geographic segment name.
When is key-person dependency observable?
A filing may name dependence on founders, executives, engineers, salespeople, licence holders, or people carrying specialised relationships. The material fact is not their title. It is which knowledge, authority, customer trust, intellectual property, or operating permission remains attached to that person and whether it has been transferred into a team, process, contract, or record.
The SEC's Regulation S-K Items 101, 103, and 105 compliance guide explains that registrants disclose material risk factors under relevant headings. A key-person or supplier risk factor is still a communicated claim prepared by the company. It identifies a stated exposure but does not measure succession readiness, undocumented knowledge, or the practical time needed to transfer a relationship.
How can hidden exposures be compared without a preset?
What evidence belongs in a dependency map?
For each material dependency, record the required function, the named counterparty or authority, the share of revenue or capacity involved, contract duration, termination rights, replacement lead time, qualified alternatives, inventory or cash buffer, and the person who can authorize a change. This separates the physical or organisational dependency from the percentage disclosed in the accounts.
The comparison should remain conditional. A company with one large customer can be less exposed than a company with hundreds of customers if the first relationship is contractually committed and the second group depends on one platform. A regulated licence can restrict the company and protect it from entry at the same time. The presence of concentration names the dependency; its consequences depend on the surrounding rights, resources, and alternatives.
What can filing disclosures still miss?
Where does the evidence stop?
Risk factors and concentration notes are selective records. They can omit second-tier suppliers, shared utilities, informal customer relationships, undisclosed contract terms, operational bottlenecks below a materiality threshold, and dependencies that became important after the reporting date.
A disclosed vulnerability does not predict a loss, disruption, regulatory change, or departure. An undisclosed vulnerability is not proof of diversification. CompanyGraph currently cannot turn these qualitative and contractual facts into a complete live screen, so the honest result is a filing-based map of dependencies and replacement conditions—not a ranked list of companies with “hidden risk.”