Glossary · Vendor Lock-in

Vendor Lock-in

Vendor lock-in is a condition in which switching barriers make changing or leaving a provider unusually costly, risky, slow, or operationally difficult. These barriers may arise from proprietary formats, closed interfaces, restrictive contracts, concentrated expertise, data-transfer obstacles, integrated dependencies, or a lack of viable alternatives. Vendor lock-in is therefore more restrictive than ordinary vendor dependency, which is reliance on an external provider.

Context

Using an external provider does not automatically create lock-in. Lock-in emerges when the institution loses practical freedom to switch, negotiate, adapt, or discontinue the service. It can develop gradually as more data, workflows, integrations, skills, and institutional knowledge accumulate around a provider without an actively maintained exit path.

Why it matters for foreign affairs

Foreign ministries require stable, secure, and trusted systems, which can make long-term supplier relationships necessary. The risk arises when continuity depends on a provider the institution cannot adequately govern, replace, or negotiate with. Lock-in can affect costs, security response, policy independence, data control, resilience, and the ability to comply with changing national or international requirements.

Where it appears in practice

Vendor lock-in appears in proprietary data formats, non-portable records, closed APIs, bundled cloud services, exclusive licensing, inaccessible logs, vendor-controlled encryption or identity layers, undocumented integrations, scarce replacement skills, high migration costs, and contracts that omit transition support or usable exit provisions.

See also

Closely related entries kept separate because each carries a distinct institutional meaning.

  • Vendor Dependency

    Vendor dependency refers to the risk that an institution becomes overly reliant on external technology providers, platforms, systems, consultants, or proprietary infrastructure in ways that limit autonomy, flexibility, security, or negotiating power.

  • Exit Capacity

    Exit capacity is the institutional ability to leave or replace a system, technology, platform, AI model, or provider while preserving data, operational continuity, knowledge, security, legal compliance, and authority. An exit plan is documentary; exit capacity must be operational, adequately resourced, and testable.

Related Articles

No articles assigned yet. Browse the archive.