{"id":120,"date":"2026-09-18T01:30:10","date_gmt":"2026-09-18T01:30:10","guid":{"rendered":"https:\/\/bayrisk.com.au\/blog\/?p=120"},"modified":"2026-09-18T01:30:10","modified_gmt":"2026-09-18T01:30:10","slug":"150-on-the-register-thousands-beneath-a-handful-that-everyone-shares","status":"publish","type":"post","link":"https:\/\/bayrisk.com.au\/blog\/2026\/09\/18\/150-on-the-register-thousands-beneath-a-handful-that-everyone-shares\/","title":{"rendered":"150 on the register. Thousands beneath. A handful that everyone shares."},"content":{"rendered":"<body>\n<p class=\"wp-block-paragraph\"><em>What really sits under a financial institution\u2019s material service providers, and why the tools most teams still use cannot cope.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>TL;DR<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The largest APRA-regulated entities average about 150 material service providers on their CPS 230 register. Model the software beneath each one and you reach roughly 3,600 to 7,200 fourth-party relationships. That is a number no team manages by hand.<\/li>\n\n\n\n<li>Trace those relationships down and they collapse onto a shared few. Three clouds, one edge provider, one certificate authority. That is not reassuring. It means your 150 suppliers are not 150 independent risks. They fail together.<\/li>\n\n\n\n<li>For the components underneath, you can usually buy support, but the contract binds the vendor who packages the code, not the project that owns it. For a few, including the encryption behind much of the internet, there is no commercial party to contract with at all.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">We undertook this research for a client, a large APRA-regulated institution, to answer one question. What actually sits beneath the material service providers on its CPS 230 register?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not a problem of under-investment. A large regulated firm today will usually hold several platforms aimed at the supply chain already. One for third-party risk. One for supplier and spend management. Often one for operational resilience as well. All sensible purchases, all doing what they were built to do.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">None of them was built to do this job. A third-party risk platform manages the vendors you know you have. A supplier and spend management platform runs the procurement, contracts and spend behind the vendors you have chosen. An operational resilience platform maps your critical operations and their tolerances. Not one of them looks down through a material supplier to the software it is itself assembled from, and asks who is really underneath. That is the layer we set out to map.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The anchor<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">APRA\u2019s System Risk Outlook, published in November 2025, records that the largest entities it supervises carry around 150 material service providers on average, supporting critical operations. That is the number on the CPS 230 register. It is a count of names, not a count of dependencies. Everything in this article sits beneath those 150.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How we built the picture<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We took the software that sits under a typical material service provider and traced it down, layer by layer, from cloud infrastructure to containers, databases, identity, observability, edge, payments and the AI now embedded in ordinary business tools. Every adoption figure carries a primary source and a date. Where no primary figure existed, the cell was left unverified rather than guessed. One column mattered more than the rest: whether the thing at the bottom has a counterparty. A company you can contract with, a foundation that exists but sells nothing, or nothing at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The full inventory sits behind this article. Every layer, every vendor, every ultimate parent and counterparty status, with a primary source and a date on each figure. Email <strong>hello@bayrisk.com.au<\/strong> and we will send you the csv.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Finding one: each supplier is itself a software company<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every name on your register is itself a business running on software. The median organisation uses 240 applications. Okta, which sees only federated logins, counts 101. BetterCloud counts 118. Behind each of your suppliers sit hundreds of tools, and each tool is a vendor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not all of those tools sit in the path of the service you buy. Assume 10 to 20 per cent do. That is 24 to 48 pieces of software, each with a vendor behind it, under a single supplier. Those vendors are your fourth parties.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You have about 150 material suppliers. Multiply it out and you are looking at 3,600 to 7,200 fourth-party relationships beneath a register that names 150 things. The only soft number in that chain is the 10 to 20 per cent. Change it and the total moves, but it never gets small. This is why the work cannot be done by hand, and no annual questionnaire cycle survives contact with it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Finding two: it all rests on the same handful<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Two numbers describe this supply chain, and they answer different questions. The gross number is the workload, the reason it cannot be done by hand. The unique number is the exposure, the reason it should worry you. Here is the second one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those thousands of relationships do not fan out to thousands of different companies. They collapse onto a tiny shared substrate, because everyone builds on the same things.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three hyperscalers carry about 63 per cent of global cloud infrastructure. One provider sits in front of a quarter of all websites and about 85 per cent of the reverse proxy market. Kubernetes runs in production for 82 per cent of container users. One non-profit issues around 10 million certificates a day and now underwrites close to a billion active sites. One un-incorporated database project is used by more than half of all developers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So when you dig two or three tiers beneath your 150 diversified suppliers, you do not find 150 diversified foundations. You find the same dozen names, again and again. The diversification on the register is largely an illusion. A single outage or compromise at one of those shared points does not touch one of your suppliers. It touches most of them at once.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"478\" src=\"https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/09\/BayRisk_article_substrate_table-1-1024x478.png\" alt=\"\" class=\"wp-image-124\" loading=\"lazy\" srcset=\"https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/09\/BayRisk_article_substrate_table-1-1024x478.png 1024w, https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/09\/BayRisk_article_substrate_table-1-300x140.png 300w, https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/09\/BayRisk_article_substrate_table-1-766x358.png 766w, https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/09\/BayRisk_article_substrate_table-1-2048x957.png 2048w, https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/09\/BayRisk_article_substrate_table-1-1536x718.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Finding three: the counterparty you can buy is not the one that matters<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here I have to be precise, because a bank will rightly say it never runs raw open source off the internet. It buys a support subscription, or it consumes the component through a managed service. That is true, and it matters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But look at what the contract actually binds. Managed PostgreSQL from a hyperscaler, or a support subscription from a specialist vendor, gives you a service level on their packaging and their hosting. None of them owns the upstream project, and none can compel it to fix anything. The most used database among developers is maintained by a group that is not incorporated and has no legal personality. Your support vendor cannot bind it, because there is nothing to bind. You have a counterparty for the service, and none for the code itself. The assurance covers the wrapper, not the core.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For a few components there is no support to buy at all. The service that underwrites encryption for a large share of the internet is a non-profit with no paid tier. Some libraries found in almost everything are maintained by a single unpaid person. There, the contract does not exist. There is only goodwill.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the accountability you can obtain is real, but partial and one step removed. Your remediation obligation ends at a party who cannot pull the levers that matter, and the entity that actually carries the risk appears nowhere on a register. That is the gap the third and fourth party model does not anticipate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Low vendor count is not low risk either. A managed IT provider might run only five client-facing tools, but each one holds standing privileged access into every client estate at once. That is how a single compromise reached 1,500 organisations through 60 providers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Finding four: the answer is stale the moment you write it<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Even where a counterparty exists, the answer moves. The AI now embedded in tools you already own routes between model providers dynamically. One collaboration platform states plainly that it switches between models on current performance, which means a point-in-time answer is wrong by design. One support tool changed its primary model provider outright, so the due diligence captured at contract signature now describes an arrangement that no longer exists. A register is a photograph of something that will not hold still.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Where the rule is heading<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Today, CPS 230 requires you to manage the risk of the fourth parties your material providers rely on. Full disclosure of that chain to APRA is not yet mandated, and fourth-party visibility is, in practice, still largely voluntary. Do not read that as breathing room. APRA\u2019s own System Risk Outlook names concentration as a systemic concern, and the direction of travel is one way. The institutions that wait for the mandate will be the ones assembling this under deadline, from a standing start, by hand. The ones that move now will already have it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The point<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here is the lunacy in one line. You cannot questionnaire your way through a supply chain that runs to thousands of relationships, collapses onto a handful of shared points of failure, and ends in components with no one to answer for them. The tools most institutions still use for this, the spreadsheet and the annual attestation, were built for a world of a few dozen named vendors. That world is gone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What the problem needs is the opposite of a point-in-time form. A current, evidence-based view of what actually sits beneath your suppliers, assembled from the outside, and kept alive as it changes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Sources<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-small-font-size\">APRA, System Risk Outlook, November 2025; Prudential Standard CPS 230 Operational Risk Management.<\/li>\n\n\n\n<li class=\"has-small-font-size\">Synergy Research Group, global cloud infrastructure market, 30 July 2026.<\/li>\n\n\n\n<li class=\"has-small-font-size\">Cloud Native Computing Foundation, Annual Survey 2025.<\/li>\n\n\n\n<li class=\"has-small-font-size\">Stack Overflow, Developer Survey 2025.<\/li>\n\n\n\n<li class=\"has-small-font-size\">W3Techs, web technology surveys, 17 September 2026; Cloudflare Radar, December 2025.<\/li>\n\n\n\n<li class=\"has-small-font-size\">Let\u2019s Encrypt \/ Internet Security Research Group, December 2025.<\/li>\n\n\n\n<li class=\"has-small-font-size\">Sonatype, State of the Software Supply Chain 2026.<\/li>\n\n\n\n<li class=\"has-small-font-size\">Okta, Businesses at Work 2025; BetterCloud, State of SaaS 2026; Zylo, SaaS Management Index 2026.<\/li>\n\n\n\n<li class=\"has-small-font-size\">Stripe annual letter, February 2026; Twilio, October 2025; Snowflake, February 2026; Confluent and IBM, March 2026.<\/li>\n\n\n\n<li class=\"has-small-font-size\">Datadog, container and real-time reports, November 2025; Grafana Observability Survey 2026; GitHub Octoverse, October 2025; DB-Engines, 2025.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Modelled figures are identified as such. Where a primary figure could not be verified it has been omitted rather than estimated. As at September 2026.<\/em><\/p>\n<\/body>","protected":false},"excerpt":{"rendered":"<p>What really sits under a financial institution\u2019s material service providers, and why the tools most teams still use cannot cope. TL;DR We undertook this research for&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"pagelayer_contact_templates":[],"_pagelayer_content":"","footnotes":""},"categories":[15],"tags":[50,24,26,49,51,40],"class_list":["post-120","post","type-post","status-publish","format-standard","hentry","category-regulation-compliance","tag-concentration-risk","tag-cps-230","tag-financial-services","tag-fourth-party","tag-sovereignty","tag-supply-chain-risk"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/comments?post=120"}],"version-history":[{"count":4,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/120\/revisions"}],"predecessor-version":[{"id":126,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/120\/revisions\/126"}],"wp:attachment":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/media?parent=120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/categories?post=120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/tags?post=120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}