SourcingConcentration

Blog

How to calculate an HHI for supplier concentration, with a worked example

The Herfindahl-Hirschman Index showed up in antitrust economics decades before anyone in procurement started borrowing it, but the math translates cleanly to supplier risk. If you've ever been asked "how concentrated is this category" and answered with a gut feel or a pivot table sorted by spend, HHI gives you a single number to put next to that question instead.

The formula

HHI is the sum of the squared market shares of every supplier in the category, expressed as whole numbers rather than decimals. For each supplier, take their share of total category spend, multiply it by 100, square it, then add up every supplier's result.

So for a category with suppliers at 40%, 30%, 20% and 10% of spend:

40² + 30² + 20² + 10² = 1600 + 900 + 400 + 100 = 3000

That 3000 is your HHI. The index sits on a 0 to 10,000 scale: a category spread across hundreds of small suppliers scores down near zero, and a category where one supplier bills every dollar of spend scores the full 10,000. The antitrust world treats anything above 2500 as highly concentrated, 1500 to 2500 as moderately concentrated, and under 1500 as unconcentrated. Those thresholds were built for merger review, not vendor risk, but category managers use them as a rough yardstick because nobody's published a better one yet.

Compare that to a plain concentration ratio, the CR4 or CR3 you might already track, which just sums the top few suppliers' shares (40 + 30 + 20 = 90% in the example above). A concentration ratio tells you what the big players control. HHI punishes a single dominant supplier more heavily than a few mid-sized ones, because squaring amplifies the gap. A category split 85/5/5/5 and one split 40/30/20/10 can show similar CR4s but very different HHIs, and the first one is usually the riskier shape.

Where this breaks down for supplier risk

Here's the part that trips people up when they bring HHI over from finance: it only ever sees spend. It has no idea that your three "different" suppliers all subcontract final assembly to the same two factories in the same industrial park, or that your 40% supplier and your 20% supplier both draw from a single port for inbound components. You can run the spend numbers, get a comfortable HHI of 1800, and still have every unit flowing through one flood-prone river crossing.

That's the gap between spend concentration and geographic concentration, and it's a distinction a spend-based index can't make on its own. A clean HHI tells you who you're buying from in dollar terms. It doesn't tell you where those suppliers physically sit, or whether "diversified" on paper means three loading docks on the same stretch of coastline.

Running the calculation is worth doing regardless. It's the cheapest first flag you have, and if a category comes back above 2500 you already know to dig further before a single-source outage catches finance by surprise. The second pass most teams skip is plotting those same suppliers against the ground they sit on, the facilities and ports standing behind the ledger they bill through.

That's the piece Sourcing Concentration was built to add. It plots your category spend against supplier geography once a year and flags the clusters, the industrial park, the flood plain, the port catchment, that a spend-only HHI has no way to see.

A quick worked example

Say a category manager runs the numbers on a six-supplier electronics category:

  • Supplier A: 35% share, squared = 1225
  • Supplier B: 25% share, squared = 625
  • Supplier C: 15% share, squared = 225
  • Supplier D: 10% share, squared = 100
  • Supplier E: 10% share, squared = 100
  • Supplier F: 5% share, squared = 25

Sum: 2300. That lands in the moderately concentrated band, nothing alarming on its own. But if suppliers A and C both source their boards from the same contract manufacturer's single facility, the real single-point-of-failure exposure is closer to 50% sitting in one building, a number no HHI calculation will ever surface because it only sees the invoice, not the address on the loading dock.

If your last supplier review stopped at the spend number, it's worth asking what a map of the same vendor list would show.

← Back to the blog