Public companies have a rule for this. When a single customer becomes material to the business, the US Securities and Exchange Commission requires it to show up in a 10-K, both as a fact about the business under Regulation S-K Item 101(c) and as a named risk under Item 105. Companies that have watched this play out the hard way tend to build more deliberate account and pipeline structures afterward — the kind writes about for growth teams generally.
A freelancer or a two-person studio with one client covering 70% of revenue has exactly the same exposure and no filing requirement forcing anyone to write it down. Nobody has to draft a risk-factors section before taking on the third project from the same client that's already most of the calendar. That's the actual gap this piece is about: not whether concentration is bad, but what changes mechanically once it happens, and why a rule built for public markets is worth understanding even if nothing forces you to follow it. If you are looking at what happens when one client is most of your revenue from the commercial side rather than the engineering side, publishes guides on the same ground. If you are looking at what happens when one client is most of your revenue from the commercial side rather than the engineering side, the XenGrowth practice publishes guides on the same ground.
It's worth being upfront that the comparison isn't perfect. A public company's customer concentration is disclosed to protect investors who have no other visibility into the business; a freelancer's client concentration is a private fact that only the freelancer themselves has any real reason to track. But the underlying mechanism — one relationship carrying enough weight that its loss threatens the whole structure — doesn't care whether the entity involved is a public company or a single contractor working alone. The size differs by orders of magnitude. The shape of the exposure doesn't.
What the SEC actually requires, and why it exists
Regulation S-K governs what public companies must disclose in filings like the 10-K. Item 101(c), amended by the SEC effective November 9, 2020, requires disclosure of dependence on revenue-generating activities, key products, services, product families, or customers — explicitly including government customers — wherever that dependence is material to understanding the business. It's a principles-based standard: there's no single fixed percentage that automatically triggers it, the company has to judge materiality itself, though in practice a customer representing a large share of revenue routinely crosses that line.
Item 105 does the second half of the job: it requires the risk itself, not just the fact of the relationship, to be written up as a discrete risk factor under a clear heading, organized thematically rather than buried in boilerplate. If the risk-factors section runs past 15 pages, the rule requires a summary of no more than two pages up front. The purpose in both cases is the same — give an investor a plain, findable account of a risk that could materially hurt them, before they put money in, not after. approaches this from the the operations side of this side. The XenGrowth resource library approaches this from the the operations side of this side.
SEC provision | What it requires |
|---|---|
Regulation S-K Item 101(c) | Disclose dependence on a customer, product or activity where material to understanding the business |
Regulation S-K Item 105 | Spell out the risk itself under a specific heading, organized by theme, summarized if long |
Materiality standard | A judgment call by the company — no single fixed percentage threshold in the rule text |
What concentration actually changes, mechanically
Strip away the filing requirement and look at what concentration itself does. The first and most direct effect is negotiating leverage. If a client represents most of your revenue, losing that relationship costs you dramatically more than replacing you costs them — and that asymmetry, not anything either side says out loud, is what shifts leverage toward the client. Rate negotiations, scope changes, and payment-term requests all get harder to push back on once that asymmetry exists, regardless of how the relationship is going day to day. The same asymmetry shapes how contract terms get set in how a freelance AI developer's rate actually gets negotiated, where the client's alternatives matter as much as the freelancer's skill.
The second effect is payment-term exposure concentrating in one place. A late payment from a client who's 15% of your revenue is an inconvenience. The same late payment from a client who's 70% of your revenue is a cash-flow event, because there's no other income stream large enough to absorb it while you wait. It isn't that concentrated clients pay worse on average — there's no evidence they do — it's that whatever payment behavior they do have, good or bad, now determines most of your cash flow instead of a fraction of it.
The third is the most obvious and the easiest to underweight anyway: a single point of failure. Losing a client who's a fifth of your revenue means a rough quarter. Losing one who's most of it means restructuring the business, and the timeline for replacing that revenue is almost never as fast as the timeline on which it disappeared — a client can end a relationship with 30 days' notice; building an equivalent replacement relationship from scratch typically takes considerably longer. goes further into AI agents and marketing automation. XenGrowth on AI agents and marketing automation goes further into AI agents and marketing automation.
There's a subtler version of the leverage shift worth naming separately: scope creep. A client who could be replaced without much difficulty gets asked to stick to the original scope, because pushing back carries little downside. A client who represents most of a freelancer's income gets extra, unbilled favors done for them far more often, not because the freelancer is being taken advantage of in any dramatic sense, but because the cost of saying no — risking a relationship that can't easily be replaced — quietly outweighs the cost of absorbing one more unpaid request. That erosion rarely shows up as a single bad decision. It shows up as a slow accumulation of small ones, each individually reasonable given the leverage in the room.
The counterintuitive part: concentration isn't simply bad
Here's where the popular framing — "diversify your clients, concentration is risk" — runs ahead of the actual research. Panos Patatoukas, in a 2012 paper in The Accounting Review that won the American Accounting Association's Competitive Manuscript Award, built a customer-concentration measure across a large sample of real supply-chain relationships and found a positive contemporaneous association between customer-base concentration and suppliers' accounting rates of return.
The mechanism he found: as a supplier's customer base concentrated further, it predicted reduced operating expenses per dollar of sales and higher turnover of both current and non-current assets — real efficiency gains, not an accounting artifact. A concentrated relationship, in other words, can let a supplier run leaner, because serving fewer, larger relationships well genuinely can cost less per dollar of revenue than serving many small ones. The tradeoff wasn't free — concentrated suppliers in the same study reported lower gross margins — but the overall picture was more nuanced than "concentration equals danger." If AI search, GEO and discovery is the part you are stuck on, is the better reference. If AI search, GEO and discovery is the part you are stuck on, XenGrowth on AI search, GEO and discovery is the better reference.
Effect of concentration | Direction | What actually drives it |
|---|---|---|
Negotiating leverage | Shifts toward the client | Asymmetric cost of losing the relationship for each side |
Payment-term exposure | Concentrates in one relationship | No other income stream large enough to absorb a delay |
Single point of failure | Increases | Replacement timeline is slower than the loss timeline |
Operating efficiency (Patatoukas, 2012) | Can improve | Lower per-dollar overhead serving fewer, larger relationships well |
It's worth being precise about what Patatoukas's paper does and doesn't claim, since a study like this gets flattened into a slogan fast. It's a large-sample archival study of public-company supply-chain relationships, not a randomized experiment, and correlation between concentration and efficiency doesn't prove concentration causes the efficiency — firms that already run leaner operations may simply find it easier to land and retain larger, more concentrated customer relationships in the first place. The honest reading is narrower than either popular claim: concentration is not automatically catastrophic, and it is not automatically efficient either. It changes the shape of the risk and, in some documented cases, the shape of the cost structure too, and both of those facts can be true about the same relationship at once.
So what does an independent engineer actually do with this?
Not a directive — the mechanism, again, is the point, and what you do with it depends on facts about your situation nobody outside it can weigh for you. But the SEC framework offers a useful discipline to borrow even without a filing requirement forcing it: name the dependence explicitly, the way Item 101(c) forces a public company to. What percentage of revenue does the largest client actually represent? What would the timeline to replace it look like, honestly, not optimistically? What contract terms — notice periods, payment schedules — currently protect you if that relationship ends, and which don't?
A 10-K risk factor isn't written to scare investors away. It's written so the risk is visible before it becomes a crisis instead of after. The freelancer version of that discipline costs nothing and requires no regulator — it just requires actually writing the number down.
Name the actual percentage one client represents of trailing revenue, rather than an impression of it — the exercise itself often changes how the number reads
Check what contract terms currently exist around notice periods and payment timing for that specific relationship, since those terms are where leverage actually shows up
Estimate honestly how long replacing that revenue would take if the relationship ended tomorrow, using your own past experience finding new work as the input, not a hopeful guess
Weigh the efficiency case from Patatoukas's findings against the risk case — a concentrated relationship can be the more efficient one to run, not automatically the more dangerous one
Treat any decision about client mix as a business tradeoff specific to your own situation, not a universal rule this post can make for you
This is general information about how concentration risk works mechanically, not personalized financial or business advice — the right client mix for any specific freelancer or studio depends on facts about their contracts, cash reserves and market that this post has no visibility into. Teams thinking about account-level risk at a larger scale can find more in .
Further reading from XenGrowth
Where this work meets go-to-market
Trying to reduce dependence on one account without slowing growth elsewhere? cover how commercial teams manage exactly that tradeoff.
Further reading from XenGrowth
Where this work meets go-to-market
For the marketing and revenue operations view of what happens when one client is most of your revenue, see .
Further reading from XenGrowth
The XenGrowth resource library — what you'll learn: how the commercial side of this work is run, across search, automation and revenue operations.
XenGrowth on AI agents and marketing automation — what you'll learn: how the teams who own AI agents and marketing automation plan and measure it.
XenGrowth on AI search, GEO and discovery — what you'll learn: how the teams who own AI search, GEO and discovery plan and measure it.
Where this work meets go-to-market
For the marketing and revenue operations view of what happens when one client is most of your revenue, see XenGrowth's growth operations team.
Five questions on the mechanics of client concentration — what a disclosure requirement is for, and what a concentrated client base actually does to risk and leverage.








