Device Risk Exposure: How Much of Your Rental Fleet Is Actually Uncontrolled?

Published 2026-09-02 · LuckyMDM Blog

In short: device rental operators almost always track default rate, and default rate is a lagging indicator. By the time an account shows as past due, the device has usually been out of effective control for weeks. The number that decides whether a bad quarter is survivable is device risk exposure: fleet net book value × (1 − controlled-fleet ratio), where the controlled ratio is the product of four multipliers — enrolment coverage, command reachability, recovery rate, and redeployability. At realistic baselines (95%, 90%, 65%, 90%) the controlled ratio comes out near 50%, which means roughly half of a USD 5M fleet is genuinely exposed. This page shows how to measure each multiplier, which one to fix first, and when scaling makes things worse rather than better.

People entering device-as-a-service ask two questions before anything else: is this still profitable, and what is the margin per unit. Both are reasonable. Both skip a step.

The step they skip is this: of the fleet I have already placed, how much can I actually control if a customer stops cooperating?

It sounds philosophical. It is not. It reduces to a number, and until you have that number, growth does something dangerous — it scales the part of your balance sheet you cannot defend, at the same rate it scales revenue.

1. Default rate is a lagging indicator

Default rate has a structural blind spot: it only counts accounts where money failed to arrive on schedule. It says nothing about units that have already slipped out of effective control but have not yet missed a payment.

In practice there is a lag of weeks to months between a device going dark — resold, disassembled, wiped, or simply switched off — and the account turning delinquent. During that window the unit is still carried as a performing asset. Default rate tells you what already happened. Exposure tells you what is happening now.

Two other facts belong next to it. A premium handset costs several hundred to over a thousand dollars, so a fleet of a thousand units is several million dollars of assets sitting in other people’s hands. And a meaningful share of smaller operators each year lose channel access or face regulatory contact because their systems and compliance were not up to standard. Both point the same way: failures in this category are usually not slow bleeds. They are asset-side events.

2. The formula: one ratio, four multipliers

Controlled-fleet ratio = enrolment coverage × command reachability × recovery rate × redeployability

Device risk exposure = fleet net book value × (1 − controlled-fleet ratio)

MultiplierQuestion it answersRealistic baselineWhat drives it
Enrolment coverageOf units in the field, how many are genuinely enrolled and visible?85–95%Whether enrolment is mandatory at issue and tied to serial number, not to a purchase order
Command reachabilityWhen you send a command, how many units receive and execute it in time?80–92%Connectivity, push-channel health, certificate validity
Recovery rateOf units entering recovery, how many physically come back within the target window?50–70%Whether a recovery clock runs, and how early intervention happens
RedeployabilityOf recovered units, how many return to rentable or cleanly saleable condition?80–95%Decommissioning hygiene: management release order, account removal, verification by serial

Substitute the baselines: 0.95 × 0.90 × 0.65 × 0.90 ≈ 0.50.

So on a fleet carried at USD 5M, roughly USD 2.5M is exposed. That is not an accounting writedown. It is the portion that, if it goes wrong at once, you cannot retrieve and cannot stop losing.

Why multiply rather than average? Because the four stages are serial. A unit that was never enrolled is lost regardless of how good the other three stages are. A unit that comes back still carrying a management profile is worth a fraction of a clean one. Each multiplier gates the next.

3. How to measure each one

Enrolment coverage: count in the system, not on the spreadsheet

Enrolled and reporting units ÷ units currently on rent. The denominator matters: use on-rent, not purchased. Sold, written-off and returned stock must be excluded or the ratio is meaningless.

The most common error here is treating licences purchased as units enrolled. Buying a thousand seats and enrolling eight hundred is an ordinary gap. This is the one multiplier that has to be reconciled serial by serial.

Command reachability: sample-test on a schedule

Units acknowledging a test command within 24 hours ÷ units targeted.

Run it monthly against the whole fleet, not only during incidents. Two failures dominate: push-channel certificates expire on a fixed cycle, and when one goes the entire fleet goes quiet at once; and units that stay offline simply never receive anything. Both share one property — if you are not testing, you will not find out until you need it.

Recovery rate: cohort, not cumulative

Units recovered within the target window from a cohort entering recovery ÷ units in that cohort.

Cohorts rather than cumulative because capability changes over time. A blended lifetime number hides the fact that last quarter was bad and this quarter improved, which is exactly the signal you need.

Redeployability: the most underestimated multiplier

Recovered units reaching rentable or cleanly saleable condition ÷ units recovered.

Its economic weight is routinely misjudged. In secondary markets the spread between a clean, fully released device and one still flagged as managed, locked to a previous account, or carrying a hidden profile is measured in hundreds of dollars per unit — frequently more than the entire gross margin on that rental. A recovered device you cannot redeploy is a recovery you paid for and did not get.

4. Six things outside the formula that move it anyway

Exposure is the core metric, not the whole picture. Each of the following, if neglected, pushes one of the four multipliers down:

  1. Contract specificity. State the trigger in days, the ladder of measures, and the release timeline after cure. Catch-all language like “we may take all necessary measures” reads strong and performs badly, because it specifies neither what happens nor when it stops.
  2. Deposits sized to the asset. A meaningful deposit at issue is among the highest-return pre-emptive controls available, because it lowers the expected payoff of a fraud-first application.
  3. Identity beyond a score. Document verification, liveness checks, carrier or utility matching, plus relationship graphing for clusters — many applications from one network in a short window, delivery addresses associated with resale, device and account reused across identities.
  4. Evidence assembled at onboarding. Contract, identity verification, delivery confirmation, payment history, notice log. If the account ever reaches a court or a regulator, this file is the whole case.
  5. Vendor concentration. Your device control is outsourced. If that vendor disappears, your controlled ratio collapses fast. Verify credentials, response commitments, and whether enrolment relationships and data are portable on exit.
  6. Total cost, not unit price. Per-unit pricing and perpetual licensing have completely different long-run shapes, and perpetual licensing still carries upgrade, maintenance and incident-response cost that rarely appears in the comparison.

5. Three misreadings

Treating exposure as default rate

Default is an outcome; exposure is a state. By the time the default number moves, the exposure behind it has usually been open for months.

Treating locking as risk control

Locking happens after the fact. Risk control happens before issue: verification, deposit, clustering, enrolment discipline. Budgets weighted entirely toward enforcement convert a risk function into a cleanup function.

Treating unit margin as profit

A per-unit model has four lines: rental income, cost of capital, depreciation against residual value, and recovery cost. The line most often wrong is residual value, and it depends directly on the fourth multiplier.

6. Fix the shortest multiplier first

Because the ratio is a product, the shortest multiplier carries the most leverage. At 95 / 90 / 65 / 90, lifting the 65 to 75 moves the controlled ratio from 0.50 to about 0.58. Lifting the 95 to 99 moves it from 0.50 to about 0.52. Same effort, four times the return, purely because of where you applied it.

For most operators the shortest multiplier is recovery rate, and the lever on recovery rate is not intensity. It is whether a clock runs — graded action at defined days past due, with classification and triage completed while the device is still worth something and the customer is still reachable.

Second shortest is usually redeployability, which is a process problem rather than a tooling problem: release the management relationship in the right order, remove the previous account, then verify by serial number or IMEI that nothing remains. Low cost, and the benefit lands straight on residual value.

7. When not to grow

A usable rule: below a controlled ratio of roughly 60%, adding units scales exposure faster than it scales profit.

Concretely, a fleet carried at USD 5M with a controlled ratio of 50% carries about USD 2.5M of exposure. Double the fleet without fixing the ratio and exposure doubles with it — while the probability that exposure converts rises, because recovery capacity, verification capacity and vendor support do not scale linearly with unit count.

The sequence that works is ratio first, volume second. Reversed, it produces the most common failure pattern in this category: revenue rising every quarter, cash tightening every quarter, until one cohort lands badly all at once.

8. A note on portfolio accounting

Under IFRS 16 and its US equivalent, operating-lease treatment depends on the substance of the arrangement, not its label. If the economics are principal plus interest with a balloon transfer at the end, most regulators and auditors will classify the instrument as credit, which brings authorisation, disclosure and cost-cap requirements with it — and takes the device-control clause down with it.

The durable construction is rent plus residual value, not principal plus interest. The first secures an asset you own. The second attempts to secure someone else’s obligation, and only one of those gives you standing over the hardware.

FAQ

What is a healthy controlled-fleet ratio?

Above about 70% you can scale with reasonable confidence. Below 60%, fix the shortest multiplier first. Remember it is a product: a strong number on one multiplier says nothing about the ratio.

We are small. Is this level of measurement worth it?

Small fleets have the least capacity to absorb a single bad cohort, so they benefit most. The first pass needs no software — fill in the four multipliers in a spreadsheet and the conclusion appears.

Which improvement pays back fastest?

Usually recovery rate, because it is typically the lowest multiplier and products reward fixing the shortest one. Second is standardising the decommissioning run, which lifts redeployability and pays out directly in residual value.

If our default rate falls, does exposure fall with it?

Not necessarily. Default is lagging. Enrolment coverage can be falling in the same quarter that default improves, because the first has not reached the ledger yet.

Does deploying MDM make the ratio good enough on its own?

It moves the first two multipliers, and only partly the third and fourth. Capability depends on enrolment state, connectivity, OS version and the authorisation relationship; it reduces risk and shortens detection time rather than guaranteeing an outcome.

What happens if our management vendor goes offline?

Your controlled ratio degrades toward zero quickly, which is why vendor continuity belongs on the risk register and why enrolment portability should be a selection criterion rather than an afterthought.

All Articles