Yes, and the risk is concentration. One person is one illness, one bus, one dissolved company. Concentration risk becomes manageable only when written down — verified source escrow, a live handover runbook, professional indemnity cover with contracted run-off, sub-processor disclosure, a tested exit plan. Buying from a large supplier does not remove concentration risk. Buying large hides concentration inside an org chart.
Ross Jones — Founder, The Hopium Lab. Last modified 22 July 2026.
For the enterprise buyer who has to defend a solo vendor to a risk committee, by the solo vendor who fills in the questionnaires.
Where is a solo vendor genuinely worse than an incumbent?
Seven places, and architecture fixes none of them.
No 24/7 rota. An incident at 02:00 gets picked up when the person wakes up. The contracted version — named hours, named response window, penalties — is what I sell as on the hook, and a named window is still not a rota.
No surge capacity. Two parallel workstreams to one deadline is a decline, not a stretch.
Annual leave and illness are real, with real dates. Publish them forward or the buyer meets them during an incident.
Concentration risk is unmitigable by definition. The DORA Article 29 substitutability test asks whether a provider is "not easily substitutable", and for a bespoke build from one person the honest first answer is no.
No accreditation depth. Cyber Essentials is achievable. ISO/IEC 27001 with credible segregation of duties is not, because one person cannot be author and approver of the same release.
No financial covenant strength. A one-person balance sheet cannot absorb a large liability cap, so the professional indemnity limit is the ceiling on recourse.
No second opinion in the room. Nobody catches a bad architectural call on the day it is made.
Why is the incumbent's risk invisible rather than absent?
Because nobody measured it. Avelino, Passos, Hora and Valente automated truck-factor estimation across 133 popular GitHub projects for ICPC 2016 (arXiv:1604.06766, later awarded ICPC Most Influential Paper) and found knowledge concentrated in very small numbers of developers throughout the corpus. Those packages are in the buyer's build today, unassessed.
Team size is not evidence either. Jabrayilzade, Evtikhiev, Tüzün and Kovalenko surveyed 269 engineers and evaluated a multimodal bus-factor algorithm on 13 JetBrains projects for ICSE 2022 (arXiv:2202.01523), showing that estimates built on version-control history alone systematically understate risk — knowledge also lives in reviews, meetings and issue trackers. Name the consequence: the commit-history handover, where a repository is offered as documentation and the successor inherits diffs instead of reasons.
CIO.com's due-diligence evergreen tells buyers to prefer a supplier "actively operating under the same legal name for at least the past five years". Call that the five-year-name rule, a proxy a rebranded agency passes and a solvent specialist fails. The statistic that follows the rule into the room is ONS Business demography, UK: 2024 (released 20 November 2025) — five-year survival for businesses born in 2019 at 38.4%, and a 2024 death rate of 9.8% across 280,000 deaths. Those figures span every registered business in every sector and count voluntary dissolution as death — not a software-vendor failure rate. Cite them honestly, then price the failure anyway.
A supplier with forty engineers has the same knowledge concentration as a supplier with one. Only one of them is obliged to tell you.
What does supplier due diligence actually require?
The Standard Selection Questionnaire, not a "supplier quality assessment" — that is ISO 9001 language. PPN 03/24 sets three parts, the third covering economic and financial standing plus technical and professional ability.
| Requirement | Solo? | The honest answer | What an agency gives you |
|---|---|---|---|
| Entity and financial standing | Yes | Companies House filings, accounts, PSC register, no strike-off — free, public, same day | Group accounts that consolidate the delivery entity away |
| Professional indemnity | Qualified | £1m–£5m band, claims-made, useless post-dissolution without contracted run-off | Higher limit, identical claims-made basis |
| Cyber Essentials / CE Plus | Yes | No headcount minimum; evidenced pre-award under PPN 014, in force 24 February 2025 | Usually held |
| ISO 27001, clean segregation of duties | No | Needs a named external release approver as compensating control | Yes, and legitimately |
| DPA, Art 28(3)(a)–(h) | Yes | All eight; (g) return or deletion and (h) demonstrating compliance are easier at this size | Yes, longer chain behind it |
| Sub-processor disclosure | Yes | Short named list, change notice, right to object — ICO guidance applies identically | Long list; delivery subcontractors often missing |
| Tested exit plan | Yes | Verified deposit, live runbook, named successor | Rare; drafted at handover |
Two traps. The dissolved-policy gap: professional indemnity responds only to claims notified while the policy is live, so the remedy evaporates the day the company is struck off. Contract a run-off period of six years, matching the Limitation Act 1980 limitation period, and put the number in the order form. The policy that pays the wrong company: key person insurance pays the vendor's own business, which by hypothesis has nobody left to spend it.
Professional indemnity written on a claims-made basis dies with the company that bought it. The remedy disappears in exactly the scenario the buyer is insuring against.
Does source escrow solve continuity?
No, and the escrow industry says so in its own marketing. Escode — formerly NCC Group Escrow, mid-divestment to TDR Capital affiliates at £275m enterprise value with completion expected no earlier than 30 April 2026, so retire the old name — publishes three verification tiers: deposit validation, build verification, deployment verification. Deposit validation proves a file exists and is virus-free. Nothing further.
The unverified deposit is the named failure mode: a stale, uncompiled archive sitting behind release conditions that almost never trigger. For a hosted product, source alone is close to worthless, because the beneficiary cannot stand up the environment. The deposit has to carry infrastructure-as-code, build instructions, the secrets-handling procedure, the event catalogue and the runbook — and indicative vendor pricing of $1,500–$7,500 a year makes cost a non-objection.
Does event sourcing mean the handover artefact exists on day one?
No — the narrower claim is the true one. Event sourcing means the system's full state history is portable and reconstructible from the deposit, so a successor inherits auditable truth rather than a snapshot. Unusual, valuable, and not the same as a handover being done.
Three concessions, because a hostile reviewer finds them anyway. Martin Fowler's page on the pattern warns that replaying events which send updates to external systems goes wrong, since those systems cannot tell a replay from real processing. Greg Young wrote a book on versioning because upcaster chains and wrong aggregate boundaries are the genuinely hard part — the upcaster nobody wrote down is tacit knowledge no event log self-documents. And a bespoke event-sourced system has a smaller pool of engineers able to pick it up than a boring CRUD application would.
Proof answers all three; assertion does not. A documented event catalogue with upcaster history, plus a scheduled cold-start rebuild from the deposit alone — my standing commitment is monthly deposits and a quarterly rebuild by someone other than me. The Replay Test points the same question at any vendor. Can you rebuild the answer without calling the model? If not, you don't have a system. You have a demo with a try/except around it.
What should the contract say about exit?
Exit-readiness is a baseline legal expectation now, not a concession extracted from small suppliers. The EU Data Act Chapter VI, Articles 23–31, applicable from 12 September 2025, imposes switching obligations across IaaS, PaaS and SaaS, with Article 25 capping customer switching notice at two months. Large incumbents were legislated into that bar. A solo vendor with a live handover runbook — maintained throughout the engagement and rehearsed on a schedule, not written at the end — clears that bar by construction.
Transposing the identifiers is the tell. In DORA, exit strategies are Article 28(8), requiring plans that are comprehensive, documented, tested and periodically reviewed; concentration risk is Article 29; contractual clauses are Article 30. In UK financial services the obligation sits on the buyer: FCA SYSC 8.1 leaves the firm fully responsible for discharging its own obligations when outsourcing critical or important functions, with PRA SS2/21 applying equivalent expectations since 31 March 2022. The critical-third-parties regime of 12 November 2024 (PS16/24 to the Bank and PRA, PS24/16 to the FCA — one policy) binds only HM Treasury designations, never a solo vendor.
A blanket public-sector ban on solo suppliers sits on thin ice. Procurement Act 2023 s.22(1) permits conditions of participation only where they are "a proportionate means" of testing capacity or technical ability, and s.12(4) requires authorities to have regard to SME barriers. One caveat kills the overclaim: s.100(5) makes that duty unenforceable in civil proceedings — a duty to consider, not a supplier right.
What goes in the risk committee paper?
Evidence with dates on it. Legible risk is risk the buyer can name, price and write into a contract before signing — the only claim a solo vendor should make.
THE SOLO-VENDOR RISK PAPER — the committee's one page
The Hopium Lab · v1.0 · 22 July 2026 · take it, fork it, argue with it
1. ENTITY (free, public, same day)
[ ] Companies House: filing history, last accounts, confirmation statement
[ ] PSC register matches the person you have been dealing with
[ ] No proposal to strike off. Check the date, not just the status
[ ] Trading name = contracting entity = entity on the invoice
[ ] Registered address is not a mail drop shared with 400 other companies
2. RECOURSE
[ ] PI limit in the order form, not the brochure. A cap below it is theatre
[ ] RUN-OFF: contracted, named, minimum 6 years. Without it the policy dies
with the company, in the exact scenario you are underwriting
[ ] Key person insurance offered? Reject it. It pays the vendor's company
3. DATA
[ ] DPA covering Art 28(3)(a)-(h). All eight. Check (g) and (h) by name
[ ] Sub-processor list: named, dated, change notice, right to object
[ ] Cyber Essentials or CE Plus evidenced BEFORE award (PPN 014)
[ ] ISO 27001 claimed? Ask who approves a release, and get the compensating
control in writing if the answer is the person who wrote it
4. CONTINUITY — the section that decides it
[ ] Escrow at BUILD VERIFICATION tier minimum
[ ] Deposit monthly, contractually. Not "on material change"
[ ] Deposit holds source, IaC, build instructions, secrets procedure,
event catalogue, runbook
[ ] Named successor engineer, under contract, who has done a cold rebuild
[ ] Release triggers: dissolution, prolonged incapacity, missed deposit
5. EXIT
[ ] Exit plan documented, tested, periodically reviewed (DORA Art 28(8))
[ ] One rebuild from the deposit during the term, by someone else
FAIL — any single one ends the assessment
Escrow with no verification tier named
PI cover with no contracted run-off period
A runbook that will be "written at handover"
No named successor, or one who has never built the system
No supplier has zero concentration risk. Find the one whose risk is written down, dated, insured and rehearsed — then send the same checklist to the incumbent and watch what comes back.
Ross Jones, Founder, The Hopium Lab. Last modified 22 July 2026. Procurement and engineering commentary, not legal advice. My tooling is first-party; nothing here is independent assurance.