Three customers, three contracts, three separate credit decisions. Each one is inside your limit. Two of them are funded by the same donor programme and the third sells to both.
You approved three positions. You are holding one, at three times the size you signed off, and no single approval could have shown you that.
Why these three models
The decision is how much to expose yourself to something, and the prior question of what counts as one something. The features that fire are an outcome that can end the company rather than merely hurt it, a channel along which one failure reaches the others, and a dependency that is invisible from the position of anyone doing the individual assessments.
Three lenses. Ruin sizing produces a random answer about what the cap should be applied to. Contagion produces a cycle answer about how the failures reach each other. Feedback misperception produces a complex answer about why nobody in your company can see the connection from where they sit. The third is the one that explains why this keeps happening to careful people.
1. Size the exposure, not the decision
Start with the rule that outranks the others. Where an outcome can remove you from the game, the expected value across outcomes is no longer the decision-relevant quantity, and the size of the worst case becomes the only one that matters. A positive expected value does not licence a bet you cannot survive losing.
That principle is not in dispute.3 What breaks is the unit it gets applied to. Founders accept it and then apply it one decision at a time, and a cap on any single exposure does nothing if three exposures fail together, because the thing that can end you is the sum rather than the largest member.
So the operational unit is not the contract. It is the set of positions that would move together. Two customers who pay from the same budget line are one exposure. A supplier and a distributor who both route through the same port are one exposure. Your revenue and your bank facility are one exposure if the facility is secured against receivables from the same customers.
Where you draw that boundary is a choice you are making whether or not you notice making it, and drawing it around a single contract is the most common version of the choice.4 The limit you already have is probably fine, and you are applying it to the wrong object.
The instruction that follows is a change of accounting rather than of appetite. Before sizing anything, ask what else in the business fails if this fails, then size the group. Founders who do this the first time routinely find that their stated concentration limit, which every individual position respects, is exceeded several times over by the group.
Work one through. A logistics firm in Kampala holds three contracts: two agencies moving supplies upcountry and one agro-processor. Each runs around UGX 90 million a year, comfortably inside a stated limit of one quarter of revenue per customer. Both agencies draw from the same donor programme, and the agro-processor sells most of its output to those same two agencies. When that programme’s disbursement slipped by a quarter, all three stopped paying in the same month. The exposure was never UGX 90 million. It was UGX 270 million against a limit set at 90, and on paper the limit was never breached.
Grouping has a consequence founders meet about a week later. Once you count the group, the deal in front of you is over limit and you still need the revenue. Refusing it is rarely right, and pretending the group does not exist is never right. The third option is to take the position and buy down the channel: shorter payment terms on the new contract than on the two you already hold, a deposit, or a written arrears figure at which you stop work. That does not shrink the group. It shortens the time you are exposed to it, which is the part you control.
There is a cheaper partial version for a company with no time to build a grid. Ask one question before signing anything: if this customer stops paying next month, name every other line of our revenue that stops with it. If the answer is none, sign. If the answer is a name, you have found the group without building anything.
2. The channel is the thing to look for
Grouping requires knowing what connects to what, and the useful discipline is to hunt for the channel rather than to reason about the category.
Failures propagate along specific paths: a shared funder, a shared input, a shared customer, a shared platform, a shared currency, a shared regulator, a shared key person. What makes a set of positions one position is not that they look similar. It is that a named channel exists along which trouble in one reaches the others.1
That test is more useful than it sounds because it is falsifiable and category reasoning is not. Two customers in different industries look diversified. If both are grant-funded by the same agency, they are not, and no amount of industry classification will reveal it. Conversely, two customers in the same industry with entirely different funding, suppliers and geography may be genuinely independent despite looking concentrated.
Diversification is a property of the channels, not of the labels.
One distinction is worth sharpening, because the channel test blurs it. A shared thing is a channel only if trouble travels along it. Two customers banking at the same commercial bank share a name and little else, since one customer running short does not touch the other’s account. Two customers whose payments both clear through the same mobile money aggregator do share a channel, because when that aggregator’s float or licence is interrupted both payments stop on the same day for a reason that has nothing to do with either customer. The question is not whether they share something. It is whether a problem here would show up there.
The practical version fits on one page. List your five largest exposures. For each, write the funder, the critical input, the platform it runs on, the currency it settles in and the one person who cannot be replaced this quarter. Then read down the columns rather than across the rows. Anything appearing twice is a channel, and the positions it touches are one position.
When a customer tells you their funding is diversified, treat that as a claim to check rather than an answer. Ask two things: what share of their income comes from their largest single source, and what month their current funding cycle ends. A customer who knows both numbers is managing the risk. A customer who can answer neither is describing an impression, and the impression is what propagates when it turns out to be wrong.
Reading down the columns is the whole trick, and it is why this cannot be delegated to the people who own the individual relationships. Each of them sees one row.
3. Why you could not see it
The third lens explains the persistence, and it is the reason to treat this as a structural fix rather than as a lapse in diligence.
People reason poorly about systems whose structure they cannot observe from their own position, and the failure survives experience, financial incentives and market pressure. It is not corrected by trying harder or by hiring people who care more, because it is a property of the information available at each node rather than of the people occupying them.2
Your account manager knows their customer’s funding source and does not know the other two accounts’ funding sources. Your finance lead sees three receivables and no funding sources at all. Nobody is careless. The connection exists in the union of what several people know and in no individual’s view, so it is discoverable only by an exercise that deliberately assembles those views.
That is why the remedy is a scheduled exercise rather than a standard. Once a quarter, in one room, with the five largest exposures on one page and each column read aloud. It takes under an hour and it is the only mechanism that puts the union of the knowledge in one place.
The failure mode of a scheduled exercise is that it becomes a ritual. By the third quarter the same grid is copied forward, the same names appear, nobody argues, and the session reports no findings because it is no longer looking. One test tells you which version you are running: a real session changes at least one cell from last quarter’s page. If nothing at all changed across a full quarter of trading, the grid was filled in from memory rather than from the contracts, and it should be refilled from the source documents with everyone watching.
Decide beforehand what you will do when it does find something, because the finding always arrives at the worst moment. The group is already live and the revenue is already budgeted, so the honest options are narrow: shorten terms on the newest member of the group, decline the next renewal inside it, or add a position that sits outside every channel on the page. Founders who have not decided this in advance reach for a fourth option, which is to record the finding and carry on, and the record is what gets read after the failure.
The corollary is worth stating plainly because it contradicts a common instinct: adding an approval step will not catch this. A second approver sees the same single row as the first. What is missing is not scrutiny, it is a view that spans positions.
What the three say together
- Group before you size. The unit is the set of positions that move together, not the contract.
- Find the channel. Funder, input, platform, currency, regulator, key person. Anything appearing twice is a channel.
- Read down the columns, not across the rows. The connection is never visible from inside one row.
- Schedule it quarterly. Nobody discovers this in the ordinary course of their job, because nobody’s job spans the positions.
Where they disagree
The ruin argument and the contagion argument disagree about how far to take the grouping.
Ruin logic says be conservative: when in doubt treat positions as correlated, because the cost of wrongly assuming independence is the company and the cost of wrongly assuming correlation is a smaller pipeline. Contagion logic says correlation is a claim about a specific channel, and if you cannot name the channel you have not established the correlation, only a resemblance. Group everything that looks alike and you end up with one enormous exposure called our business, which contains no information and blocks decisions you should be making.
The reconciliation is asymmetric and deliberate. Require a named channel before grouping, which keeps the analysis honest. But when a channel is plausible and you cannot check it, group anyway, because the two errors are not the same size. In practice that means the burden of proof sits on independence rather than on correlation, and the way to discharge it is to check the funding source rather than to assert that the customers are in different sectors.
What none of them contain
None of the three prices the correlation that only appears under stress. Positions can be genuinely independent in normal conditions and move together in a crisis, because the crisis itself is the channel: everyone delays payment in the same month, every lender tightens at once. A channel search conducted in a calm quarter will not find those, and they are the ones that matter most.
None of them handles your own behaviour as a channel. If losing one large customer causes you to cut the marketing that was generating the pipeline for the others, you are the transmission mechanism. Every model here treats the positions as connected to each other and none treats them as connected through you.
And one property the ensemble will not produce: concentration is often correct. A company with one customer that it serves extremely well is a normal and frequently successful shape, particularly early. All three lenses will tell you the exposure is large and none of them will tell you whether the alternative, spreading thin across five relationships you serve adequately, is better. That is a judgement about your business, and the analysis here bounds it rather than making it.
The one action that survives the ignorance: put your five largest exposures on one page this week with a column each for funder, critical input, platform, currency and irreplaceable person. Read down the columns. If nothing appears twice you have bought real information cheaply. If something appears twice, you have just found a position you never approved.
Who has to move
The founder has to run it, because it is the only role that spans the rows, and it cannot be handed to the people who own the relationships without defeating the purpose. The instinct after a concentration scare is to add an approval threshold, which puts a second pair of eyes on the same single row and catches nothing. The cheapest first test is the one-page grid, which uses only information the company already holds and typically takes an hour of assembling rather than any new analysis.
Sources and notes
- Albert-László Barabási, Network Science, Cambridge University Press, on spreading processes and on the role of specific topology in whether and how far a disturbance propagates. Used in section 2 for the claim that propagation requires a channel and that the structure of connections, rather than the similarity of the nodes, determines what moves together. Note the deliberate restraint: no claim is made here about the shape of any real business network’s degree distribution, and none is needed, because the argument only requires that named channels exist and can be enumerated.
- John D. Sterman, Business Dynamics: Systems Thinking and Modeling for a Complex World, McGraw-Hill, and The Beer Distribution Game, MIT, https://web.mit.edu/jsterman/www/SDG/beergame.html. Participants with good local information and limited global information produce large systemic failures, average costs about ten times the optimum available from the information they hold, and afterwards attribute the outcome to external causes that did not occur. The result holds for graduate students and business executives alike. Used in section 3 for the claim that this is a property of the information at each position rather than of the people occupying it, and therefore that the remedy is structural.
- Michael J. Mauboussin, The Success Equation: Untangling Skill and Luck in Business, Sports, and Investing, Harvard Business Review Press, together with the standard treatment of absorbing barriers. The principle used in section 1 is that where one outcome removes you from the game, expected value across outcomes ceases to be the decision-relevant quantity. No probability of joint failure is estimated here, because estimating one would require the very independence assumption the article is questioning.
- Donella H. Meadows, Thinking in Systems: A Primer, Chelsea Green Publishing. The treatment of system boundaries, and the argument that a boundary drawn around a single decision is a choice rather than a discovery, underpins the framing in section 1 that the unit of analysis is the group of positions rather than the contract. Also the source for the closing observation that the analyst can be part of the system being analysed.
A note on a number this article does not give. There is no concentration limit that transfers between companies. What one business can survive depends on its margins, its runway and how fast it can replace a lost relationship. What transfers is the accounting change: apply whatever limit you already have to the group rather than to the contract, and the limit you already have will usually turn out to be breached.
Joshua Agonya Pi’Rwot, Founder.