What Is Fourth-Party Risk?

Related problems: A vendor's supplier had a breach and we had no idea they were involved; Don't know which cloud providers and subcontractors sit behind our SaaS tools; Many of our critical vendors depend on the same provider; Regulators or customers asking about our vendors' subcontractors

Fourth-party risk is the risk your organization takes on from your vendors’ own vendors: the cloud hosts, data centers, software components, payment processors, support subcontractors and other suppliers that sit behind a service you buy. You usually have no contract with these companies and may not know they exist, yet their outage, breach or failure can reach your data and operations through the vendor you do contract with.

At a glance

  • Third parties are vendors you contract with; fourth parties are their suppliers, one step further away.
  • You rarely have direct rights over fourth parties, so visibility and control come through your contracts with third parties.
  • Common sources include subprocessors that handle your data, shared cloud providers and embedded software components.
  • Concentration risk, many vendors relying on the same provider, is often the biggest finding once fourth parties are mapped.

What problem it solves

A typical mid-sized company buys dozens or hundreds of SaaS tools and services. Each relies on its own stack of providers, and those dependencies overlap. When a widely used hosting provider, file-transfer tool or identity service has an incident, it can hit many organizations at once, including companies that never bought from it directly.

Classic third-party risk management (TPRM) asks whether each vendor is secure. Fourth-party thinking asks what each vendor depends on, whether it manages those suppliers properly, and where several of your vendors quietly share the same point of failure. It turns “a vendor’s supplier had a breach” from a surprise into a scenario you planned for.

How it works

Discovery. Start with your critical vendors and ask who they depend on to deliver the service and handle your data. Sources include published subprocessor lists, the subservice organizations named in SOC 2 reports, data processing agreements (DPAs), security questionnaire answers and, for software, a software bill of materials (SBOM). Some security rating and TPRM tools also infer fourth parties from public signals, with varying accuracy.

Assessment. Check how each vendor manages its own suppliers: does it assess them, require certifications, and flow down security and notification obligations? Where a fourth party is critical, ask for its audit reports through the vendor.

Contract controls. Common clauses require vendors to disclose material subcontractors, notify you before adding or changing them, hold them to equivalent security terms, and report their incidents to you within a set time.

Concentration analysis. Map which fourth parties appear behind several of your vendors. Heavy reliance on one provider, one region or one software component shows where a single event could affect many services.

Monitoring. Keep the map current through annual reviews, vendor change notices and news of incidents at major providers.

When it matters for buyers

  • When a critical vendor processes sensitive data. Personal, financial or health data often passes through several subprocessors, and privacy laws in many jurisdictions expect you to know who they are.
  • In regulated industries. Financial services rules such as the EU’s Digital Operational Resilience Act (DORA) put weight on subcontracting chains for important services; requirements vary by sector and country, so check with counsel.
  • During a major provider outage or breach. Knowing which vendors depend on the affected provider speeds up your response.
  • When consolidating or choosing vendors. Two vendors on the same underlying provider may offer less diversity than they appear to.

Our governance, risk and compliance advisors can help structure vendor reviews that include fourth parties.

Questions to ask vendors

  • Which subcontractors and subprocessors are involved in delivering this service or handling our data?
  • How do you assess and monitor those suppliers, and how often?
  • Will you notify us before adding or replacing a material subcontractor, and can we object?
  • Do your contracts with suppliers flow down security, confidentiality and breach-notification terms equivalent to ours?
  • Which of your providers would cause an outage for us if they failed, and what is your fallback?
  • Can you share the audit reports or certifications of your key suppliers?

How it differs from third-party risk management

Third-party risk management (TPRM) is the overall program for assessing and monitoring the vendors you contract with, and vendor management covers the commercial relationship with them. Fourth-party risk is one category of risk that program should cover: the dependencies one level further out, where you have no contract and must work through the vendor. It is not a separate discipline so much as the part of TPRM that many programs skip. Some people extend the idea to “nth-party” risk for every link further down the supply chain.

Frequently Asked Questions

What is the difference between third-party and fourth-party risk?
Third parties are the vendors you contract with directly. Fourth parties are the suppliers those vendors rely on, such as their hosting provider, payment processor or support subcontractor. You have a contract with the first group but usually not with the second.
How do we find out who our fourth parties are?
Ask. Many SaaS providers publish a list of subprocessors that handle customer data, and SOC 2 reports often name carved-out subservice organizations. Questionnaires and contract clauses can require vendors to disclose and update the rest.
Can we assess fourth parties directly?
Rarely. You usually have no contract with them, so you rely on your vendor to manage them and on evidence they pass along, such as the fourth party's certifications or audit reports. Your leverage is in your contract with the vendor.
What is concentration risk?
It is the risk that many of your vendors depend on the same fourth party, such as a single cloud region or identity service, so one outage or breach affects several services at once. Mapping fourth parties is how you see it.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.