Fourth-party risk is the risk your organization takes on from your vendors’ own vendors: the cloud hosts, data centers, software components, payment processors, support subcontractors and other suppliers that sit behind a service you buy. You usually have no contract with these companies and may not know they exist, yet their outage, breach or failure can reach your data and operations through the vendor you do contract with.
At a glance
- Third parties are vendors you contract with; fourth parties are their suppliers, one step further away.
- You rarely have direct rights over fourth parties, so visibility and control come through your contracts with third parties.
- Common sources include subprocessors that handle your data, shared cloud providers and embedded software components.
- Concentration risk, many vendors relying on the same provider, is often the biggest finding once fourth parties are mapped.
What problem it solves
A typical mid-sized company buys dozens or hundreds of SaaS tools and services. Each relies on its own stack of providers, and those dependencies overlap. When a widely used hosting provider, file-transfer tool or identity service has an incident, it can hit many organizations at once, including companies that never bought from it directly.
Classic third-party risk management (TPRM) asks whether each vendor is secure. Fourth-party thinking asks what each vendor depends on, whether it manages those suppliers properly, and where several of your vendors quietly share the same point of failure. It turns “a vendor’s supplier had a breach” from a surprise into a scenario you planned for.
How it works
Discovery. Start with your critical vendors and ask who they depend on to deliver the service and handle your data. Sources include published subprocessor lists, the subservice organizations named in SOC 2 reports, data processing agreements (DPAs), security questionnaire answers and, for software, a software bill of materials (SBOM). Some security rating and TPRM tools also infer fourth parties from public signals, with varying accuracy.
Assessment. Check how each vendor manages its own suppliers: does it assess them, require certifications, and flow down security and notification obligations? Where a fourth party is critical, ask for its audit reports through the vendor.
Contract controls. Common clauses require vendors to disclose material subcontractors, notify you before adding or changing them, hold them to equivalent security terms, and report their incidents to you within a set time.
Concentration analysis. Map which fourth parties appear behind several of your vendors. Heavy reliance on one provider, one region or one software component shows where a single event could affect many services.
Monitoring. Keep the map current through annual reviews, vendor change notices and news of incidents at major providers.
When it matters for buyers
- When a critical vendor processes sensitive data. Personal, financial or health data often passes through several subprocessors, and privacy laws in many jurisdictions expect you to know who they are.
- In regulated industries. Financial services rules such as the EU’s Digital Operational Resilience Act (DORA) put weight on subcontracting chains for important services; requirements vary by sector and country, so check with counsel.
- During a major provider outage or breach. Knowing which vendors depend on the affected provider speeds up your response.
- When consolidating or choosing vendors. Two vendors on the same underlying provider may offer less diversity than they appear to.
Our governance, risk and compliance advisors can help structure vendor reviews that include fourth parties.
Questions to ask vendors
- Which subcontractors and subprocessors are involved in delivering this service or handling our data?
- How do you assess and monitor those suppliers, and how often?
- Will you notify us before adding or replacing a material subcontractor, and can we object?
- Do your contracts with suppliers flow down security, confidentiality and breach-notification terms equivalent to ours?
- Which of your providers would cause an outage for us if they failed, and what is your fallback?
- Can you share the audit reports or certifications of your key suppliers?
How it differs from third-party risk management
Third-party risk management (TPRM) is the overall program for assessing and monitoring the vendors you contract with, and vendor management covers the commercial relationship with them. Fourth-party risk is one category of risk that program should cover: the dependencies one level further out, where you have no contract and must work through the vendor. It is not a separate discipline so much as the part of TPRM that many programs skip. Some people extend the idea to “nth-party” risk for every link further down the supply chain.
