Vendor Dependency
Vendor dependency refers to the risk that an institution becomes overly reliant on external technology providers, platforms, systems, consultants, or proprietary infrastructure in ways that limit autonomy, flexibility, security, or negotiating power.
Foreign ministries handle sensitive information and operate in politically complex environments. If a ministry cannot audit, adapt, replace, or control critical systems, it may face sovereignty, security, continuity, and cost risks. Vendor dependency becomes especially serious when tools process sensitive data, support crisis response, or shape institutional knowledge.
It appears in cloud contracts, AI tools, analytics platforms, communication systems, consular software, digital identity providers, proprietary dashboards, and outsourced digital transformation programs. It also appears when ministries lack internal capability to evaluate or govern the systems they use.
Closely related entries kept separate because each carries a distinct institutional meaning.
- Vendor Lock-in
Vendor lock-in is a condition in which switching barriers make changing or leaving a provider unusually costly, risky, slow, or operationally difficult. These barriers may arise from proprietary formats, closed interfaces, restrictive contracts, concentrated expertise, data-transfer obstacles, integrated dependencies, or a lack of viable alternatives. Vendor lock-in is therefore more restrictive than ordinary vendor dependency, which is reliance on an external provider.
- Exit Capacity
Exit capacity is the institutional ability to leave or replace a system, technology, platform, AI model, or provider while preserving data, operational continuity, knowledge, security, legal compliance, and authority. An exit plan is documentary; exit capacity must be operational, adequately resourced, and testable.
- Retained Authority
Retained authority is Diplomats.Digital's institutional test for whether an organization that uses AI or digital systems remains able to define objectives, set boundaries, authenticate actors, approve consequential action, verify outputs, intervene or override, trace decisions, maintain continuity, and exit dependencies. Authority is retained only when these powers remain operationally executable, not merely stated in policy or contract.

