The finding: tested against real companies, only about one in seven had customer concentration as their true binding dependency. The rest were exposed to something else entirely — a platform, a distributor network, one hero product, a channel’s take-rate, or a lender. Most risk tools measure only the first one.
Nearly every fragility score, lender checklist, and buyer’s diligence framework opens with the same assumption: the dangerous dependency is customer concentration. Top-five share of revenue. Largest single account. It’s the number every dashboard can produce, so it became the number every tool measures.
When Fulcrum tested that assumption against the real companies in its diagnostic work, it held up about one time in seven. For the other six, the exposure that could actually end the business lived somewhere else: the marketplace platform that owns the customer relationship, the distributor network that owns the shelf, the one hero product carrying the margin, the sales channel whose take-rate resets, the referral source nobody has mapped, or the lender whose covenant nobody re-reads.
The implication is uncomfortable for standardized tools: if you assume the dependency, you will measure the wrong one six times out of seven. The only defensible first step is to ask what the company actually depends on — and only then to measure it.
A dependency is the external relationship your economics actually run on — the thing that, if it went away or changed its terms, would genuinely hurt. It can be a customer. It is just as often a platform, a supplier, a channel, a product, a referral source, or a lender. A defensible read identifies the dependency first, then joins it to the calendar: when does it renew, reprice, or mature? Concentration is on your dashboard. Concentration multiplied by the renewal calendar isn’t — and that’s the one that ends you.
The same standardized tools make a mirror-image mistake on revenue durability. A project-based business — a contractor, an agency, an installer — has no recurring revenue because that is its business model, not because something is broken. Most scoring tools will fail that company for being what it is. A defensible diagnostic evaluates durability inside the company’s actual model: re-win rates, pipeline coverage, referral machinery — not a subscription metric the model was never built to produce.
The one-in-seven figure comes from Fulcrum & Co.’s diagnostic fieldwork: dependency identification performed company-by-company across its client and analysis work, rather than inferred from a survey. It is stated as an approximate rate, not a precise coefficient, and this note is updated as the diagnostic base grows. Client identities are confidential, always. Fulcrum’s standard for every published figure: demonstrated, not claimed.
What’s the one thing that, if it went away, would genuinely hurt — and when does it come up for renewal?
START A CONVERSATION SEE THE FRAGILITY DIAGNOSTIC →