Fourth-Party Risk
Fourth-party risk is the risk your organization faces from the suppliers and partners that your own direct vendors rely on—in other words, your vendors' vendors. Even though you have no direct contract with these entities, problems they experience can flow up the chain and affect the services your organization depends on. Because the relationship is indirect, this risk is often harder to see and manage than the risk from your direct suppliers.
Fourth-party risk refers to the risk introduced by the subcontractors, suppliers, and service providers engaged by an organization's third parties—that is, the third party's own third parties—with whom the organization typically has no direct contractual relationship. In many risk management practices it is treated as an extension of third-party risk that requires visibility into downstream dependencies, since disruptions, security weaknesses, or failures at the fourth-party level can propagate through a third party to affect the organization. Fourth-party risk management (FPRM), as commonly described, is the process of identifying, assessing, and mitigating these risks. Note that the sources in this packet frame fourth-party risk primarily in cyber and vendor supply-chain terms; the concept is not defined here with respect to AI-specific model or governance risk, and its scope may vary by sector and by an organization's contractual and monitoring arrangements.
Why it matters
Fourth-party risk matters because organizations increasingly depend on services that are ultimately delivered through layered chains of suppliers, yet their visibility and contractual leverage typically end at their direct third parties. A disruption, security weakness, or failure at the fourth-party level can propagate upward through a third party and affect the services an organization relies on, even though the organization has no direct relationship with the entity at the root of the problem. Because the exposure is indirect, it is often harder to identify, assess, and monitor than risk from direct suppliers.
Who it's relevant to
Inside Fourth-Party Risk
Common questions
Answers to the questions practitioners most commonly ask about Fourth-Party Risk.