Skip to main content
Category: Third-Party & Supply Chain

Fourth-Party Risk

Also known as: 4th party risk, vendors' vendors risk, subcontractor risk
Simply put

Fourth-party risk is the risk your organization faces from the suppliers and partners that your own direct vendors rely on—in other words, your vendors' vendors. Even though you have no direct contract with these entities, problems they experience can flow up the chain and affect the services your organization depends on. Because the relationship is indirect, this risk is often harder to see and manage than the risk from your direct suppliers.

Formal definition

Fourth-party risk refers to the risk introduced by the subcontractors, suppliers, and service providers engaged by an organization's third parties—that is, the third party's own third parties—with whom the organization typically has no direct contractual relationship. In many risk management practices it is treated as an extension of third-party risk that requires visibility into downstream dependencies, since disruptions, security weaknesses, or failures at the fourth-party level can propagate through a third party to affect the organization. Fourth-party risk management (FPRM), as commonly described, is the process of identifying, assessing, and mitigating these risks. Note that the sources in this packet frame fourth-party risk primarily in cyber and vendor supply-chain terms; the concept is not defined here with respect to AI-specific model or governance risk, and its scope may vary by sector and by an organization's contractual and monitoring arrangements.

Why it matters

Fourth-party risk matters because organizations increasingly depend on services that are ultimately delivered through layered chains of suppliers, yet their visibility and contractual leverage typically end at their direct third parties. A disruption, security weakness, or failure at the fourth-party level can propagate upward through a third party and affect the services an organization relies on, even though the organization has no direct relationship with the entity at the root of the problem. Because the exposure is indirect, it is often harder to identify, assess, and monitor than risk from direct suppliers.

Who it's relevant to

Third-party and vendor risk managers
Professionals responsible for supplier oversight need to consider whether their programs extend beyond direct third parties to the downstream subcontractors and service providers those vendors rely on. Because direct contractual leverage typically stops at the third party, they generally depend on the third party's own disclosures and monitoring to gain visibility into fourth-party dependencies.
Cybersecurity and information security teams
The sources frame fourth-party risk largely in cyber terms, so security teams may treat it as an extension of supply-chain threat exposure—recognizing that a security weakness at a vendor's supplier can propagate upward and affect services the organization depends on.
Compliance and procurement functions
Those negotiating and administering vendor agreements may use contractual terms and due-diligence requirements to seek visibility into a third party's own suppliers. The extent to which this is achievable varies by sector and by the specific contractual and monitoring arrangements an organization is able to put in place.
AI governance and model risk practitioners (with a caveat)
Practitioners concerned with AI supply chains may find the concept relevant when direct AI vendors themselves rely on downstream providers. However, the sources in this packet do not define fourth-party risk in terms of AI-specific model or governance risk, so applying the concept to those contexts requires additional, appropriately scoped analysis beyond what this entry supports.

Inside Fourth-Party Risk

Nth-party or downstream dependency
Fourth-party risk refers to the risk arising from a vendor's own vendors—the subcontractors, service providers, and dependencies that an organization does not contract with directly but that support the third parties it does contract with. In an AI context, this often includes upstream model providers, cloud infrastructure, data suppliers, or fine-tuning services relied upon by a direct vendor.
Indirect contractual relationship
A defining feature is the absence of a direct contractual relationship between the organization and the fourth party. Because oversight and enforcement rights typically flow only to the immediate third party, the organization's ability to impose controls, obtain assurances, or audit the fourth party is generally indirect and depends on flow-down terms in the third-party contract.
Concentration and dependency exposure
Fourth-party risk can create concentration exposure where multiple third parties rely on the same underlying provider (for example, a common foundation model or cloud region). This can amplify the impact of a single point of failure across an organization's vendor portfolio, though the degree of concentration is often difficult to observe from the organization's vantage point.
Visibility and transparency limitation
A core element is limited visibility. Organizations frequently cannot fully enumerate their fourth parties, and information about those parties is typically mediated through the direct vendor. This limits the reliability of risk assessment and is a recognized constraint rather than a solvable gap in most programs.
Relationship to third-party risk management
Fourth-party risk is commonly treated as an extension of third-party risk management rather than a wholly separate discipline. It typically overlaps with vendor governance and supply-chain risk practices, and its treatment can vary by sector, with more formalized expectations in regulated industries such as banking.

Common questions

Answers to the questions practitioners most commonly ask about Fourth-Party Risk.

Is fourth-party risk the same as third-party risk?
No. Third-party risk typically refers to risks arising from an organization's direct vendors, suppliers, or service providers with whom it has a contractual relationship. Fourth-party risk, as commonly defined, refers to risks arising from the subcontractors, sub-processors, or downstream suppliers that your third parties themselves rely on—parties with whom your organization usually has no direct contract. Blurring the two obscures a key practical challenge: your visibility and contractual leverage over fourth parties are typically indirect, exercised through the third party rather than exercised directly.
Does mapping fourth parties eliminate the risk they introduce?
No. Identifying and mapping fourth-party dependencies is a measure that helps you understand and manage risk, not one that removes it. Even with a complete inventory, you generally retain limited direct control over a fourth party's practices, and concentration or dependency risks can persist. Governance controls in this area reduce and help monitor exposure rather than eliminate it, and residual risk typically remains after controls are applied.
How can an organization gain visibility into fourth parties when it has no direct contract with them?
Visibility is usually obtained indirectly through the third party. Common approaches include contractual clauses requiring third parties to disclose their material subcontractors or sub-processors, requesting the third party's own supply-chain and due-diligence documentation, and seeking notification rights when a third party adds or changes a critical fourth party. The depth of visibility achievable typically depends on the third party's willingness and ability to disclose, and may vary by sector and by the criticality of the service.
How should fourth-party risk be prioritized given the potentially large number of downstream dependencies?
Because a complete downstream map can be impractical to maintain, organizations commonly apply a risk-based approach, focusing attention on fourth parties that support critical services, hold or process sensitive data, or represent concentration points where many third parties rely on the same underlying provider. Lower-criticality dependencies may receive lighter or periodic review. Prioritization criteria should be documented so the scope and its limitations are transparent.
What contractual mechanisms are typically used to manage fourth-party risk?
Organizations frequently rely on provisions in their agreements with third parties, since they generally cannot contract directly with fourth parties. These may include flow-down requirements obliging the third party to impose comparable obligations on its subcontractors, disclosure and notification requirements for material subcontractors, audit or assessment rights that extend to the supply chain, and clauses governing the third party's responsibility for the performance of parties it engages. The enforceability and reach of such provisions can vary by jurisdiction and by the third party's own contractual arrangements.
How does fourth-party dependency mapping relate to concentration risk?
Fourth-party mapping can surface concentration risk that is not visible at the third-party level—for example, when multiple third parties independently depend on the same underlying provider. Identifying these shared dependencies helps an organization understand where a single point of failure could affect several services at once. This is an analytical input to risk assessment; identifying a concentration does not by itself resolve it, and mitigation options may be limited where alternative providers are scarce.

Common misconceptions

Fourth-party risk can be managed with the same direct controls used for third parties.
Because there is generally no direct contractual relationship with a fourth party, organizations usually cannot impose or enforce controls directly. Assurance typically depends on flow-down obligations, disclosures, and warranties obtained through the immediate third party, which are indirect and may be incomplete.
Assessing and monitoring fourth parties eliminates the associated risk.
Governance and monitoring measures reduce or manage fourth-party risk; they do not eliminate it. Limited visibility, mediated information, and concentration exposure mean residual risk typically remains even in mature programs.
Fourth-party risk is a distinct discipline separate from third-party or supply-chain risk management.
It is more commonly treated as an extension of third-party risk management and vendor governance. The concept overlaps substantially with supply-chain risk practices, and its formality and terminology vary by sector and organization.

Best practices

Negotiate flow-down provisions in third-party contracts that require vendors to disclose material fourth parties, obtain equivalent assurances from them, and notify the organization of significant changes.
Map, where feasible, the key downstream dependencies supporting critical AI vendors—such as foundation model providers, cloud infrastructure, and data suppliers—while acknowledging that full enumeration is often not achievable.
Assess concentration exposure across the vendor portfolio to identify shared underlying providers that could represent a single point of failure, and factor this into contingency planning.
Calibrate the depth of fourth-party scrutiny to the criticality of the direct vendor relationship, focusing limited assurance resources on the dependencies with the greatest potential impact.
Document known limitations in fourth-party visibility explicitly, and treat the residual risk from those gaps as a factor in risk acceptance and oversight decisions.
Align fourth-party practices with existing third-party risk management and vendor governance processes rather than building a parallel program, adjusting for sector-specific expectations where applicable.