Correlated failures and the assumption of independence
Risks are assessed one at a time and arrive together.
A register lists items separately and rates them separately, which implicitly treats them as independent. Real disruptions do not respect that: a single cause produces supplier failure, staff absence, system unavailability and reputational exposure simultaneously, and controls that each assumed the others were working fail together.
The common version is a control that depends on people. Several treatments across a register may all assume that a particular team is available to respond, and the scenario that triggers them is precisely the one that team cannot cover.
Identifying this requires reading the register for shared dependencies rather than item by item: which controls rely on the same system, the same supplier, the same building, the same handful of people. That analysis is not part of standard practice and it consistently finds concentrations nobody intended.
The remedy is usually not more controls but different ones, chosen so that they do not fail for the same reason. Two independent weak controls frequently beat one strong one that shares a dependency with everything else.
There is a specific concentration worth checking in any register, which is how many treatments assume the availability of the same small group of people. In most organisations a handful of individuals appear as the control for a surprising number of exposures, and the scenarios that trigger those controls are frequently the ones in which those individuals are unavailable.