Risk Management
Risk Concentration Heatmap
Where multiple high risks cluster on shared objectives, processes or vendors, signalling concentration.
Why clustered risk is more dangerous than isolated risk
Risk registers are usually read line by line, which masks the more serious problem of concentration: several high risks all bearing on the same objective, process or vendor. When that single point fails, the institution suffers a correlated loss rather than an isolated one, a dynamic King IV expects the governing body to understand. AuditPro Core plots where high risks cluster so the audit committee can see systemic fragility that a flat register would never reveal.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Concentration nodes
15
Critical nodes
4
>4 risks each
Single-vendor nodes
3
Diversified this year
2
Linked risks per node
Concentration nodes
| Node | Risks | Max score | Treatment |
|---|---|---|---|
| Core ERP platform | 7 | 21 | Resilience plan |
| Primary bank | 5 | 16 | Diversify |
| Revenue objective | 6 | 19 | Monitor |
| Single fuel supplier | 4 | 17 | Diversify |
| Data centre | 5 | 18 | Resilience plan |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Concentration versus aggregation
Aggregation sums exposure; concentration shows where it pools. Two unrelated high risks are tolerable, but two high risks on the same vendor create a single failure point.
Shared dependencies
Objectives, processes and vendors are the connective tissue between risks. Mapping risks to these shared nodes exposes the dependencies that turn separate events into a cascade.
Heatmap intensity
Intensity on the heatmap reflects both the number of high risks on a node and their severity. A bright cell is an early warning that contingency planning is thin.
Correlated failure
Diversified risk is survivable; correlated risk is not. Concentration analysis identifies where a single disruption would breach multiple objectives at once.
How AuditPro Core Bridges the Gap
- Dependency mapping: each risk is linked to the objectives, processes and vendors it touches, building the network behind the heatmap.
- Cluster detection: the platform highlights nodes carrying multiple high residual risks so concentration surfaces automatically.
- Continuous monitoring: as ratings change, clusters re-form live, alerting management before a hotspot hardens.
- Traceability to source: every cell drills through to the underlying risks and their owners for direct follow-up.
Key Takeaways
- Line-by-line review hides concentration; only mapping shared nodes reveals it.
- A single vendor or process carrying several high risks is a systemic vulnerability.
- Use concentration to target contingency and continuity planning where it matters most.
- Reassess clusters whenever residual ratings move, not just at year-end.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
