What counts as a single-source supplier on a risk register
Most procurement teams know the textbook definition of single-source: one supplier is currently providing a part, material, or service, even though other qualified suppliers exist in the market. That's different from sole-source, where only one supplier can provide it, because of a patent, a proprietary process, or a regulatory requirement. The distinction matters because it changes what you do next. A single-source situation is a sourcing decision you made, or inherited, and can unwind. A sole-source situation is a market condition you're stuck with until a patent lapses or a competitor gets qualified.
On paper that split sounds clean. In practice most risk registers lump both under one flag and move on, and that's where the category starts to lose its usefulness.
What belongs in the single-source category
A supplier counts as single-source on a risk register when:
- Only one approved vendor is currently buying or supplying for a given part number, SKU, or service line
- No qualified second source exists on your approved vendor list, even if one could theoretically be qualified
- Switching would require a requalification cycle, not just a purchase order to someone else
Notice what's missing from that list: geography. A line item can be single-sourced in your ERP and still be produced by three different legal entities that all happen to run out of the same industrial park, the same river delta, or the same port catchment. Most registers never catch that, because they're built off the vendor master, not off a map. You can have twelve approved suppliers for a category and still have one point of failure if nine of them sit inside the same flood zone or draw power from the same substation.
That gap is where single-source risk quietly becomes concentration risk, and the single/sole-source split alone doesn't describe it.
Sole source vs single source, and why the register needs both
Sole source is contractual, technical, or regulatory lock-in. It usually sits with engineering or legal as much as procurement, and the fix is qualification work with a known owner and a slow timeline.
Single source is a buying pattern, not a market constraint. The fix, in theory, is adding a second vendor. In practice teams delay it because qualifying a second supplier costs money and the first one hasn't failed yet.
A register that treats these the same way misallocates mitigation effort. Sole-source risk needs an engineering plan. Single-source risk needs a sourcing plan, plus visibility into where the current supplier, and its own sub-tier, sits. A supplier flagged as "dual-sourced" because two different company names appear on the PO can still fail that test if both companies are twenty minutes apart on the same road.
Supplier risk register categories that hold up
A register that separates these properly usually ends up closer to this:
- Sole-source: risk dictated by IP, regulation, or technical lock-in, not by sourcing choices
- Single-source: approved-vendor risk, correctable through requalification
- Geographic concentration: risk that exists regardless of vendor count, because approved suppliers share a physical footprint, a port, a substation, or a flood plain
That third category is the one most registers skip, because it can't be built from the vendor master alone. It needs an address for every approved supplier, ideally their known manufacturing sites and not just HQ, checked against actual terrain and infrastructure rather than a city name in a spreadsheet. That's a different exercise than updating the sole/single flag at the next audit cycle.
If your register has never had that third category added, it's worth running a concentration pass before the next audit instead of during one. The industrial park nobody flagged usually turns up spend from more approved suppliers than anyone expected, once someone actually plots it against the ground.
Sourcing Concentration runs that pass once a year, plotting category spend against where suppliers physically sit so the cluster shows up before the audit finds it for you.