Fourth-Party Risk

Fourth-party risk is the exposure an organization inherits from its vendors' vendors, one layer deeper in the supply chain than traditional third-party risk, becoming increasingly important as cloud and SaaS dependencies proliferate.

Why Fourth-Party Risk Is a Growing Concern

Modern enterprise vendors depend heavily on their own vendors. A SaaS provider runs on a hyperscale cloud. A payment processor depends on a KYC provider. A managed service provider integrates with several downstream tools. Each layer of dependency creates fourth-party exposure for the enterprise sourcing the primary service.

When a fourth party has an incident, the impact often reaches the enterprise regardless of contractual relationships. Contractual protections do not always extend downstream, and even where they do, the operational impact may not be preventable.

Regulatory Attention to Fourth-Party Risk

Financial regulators, particularly under DORA, are increasingly asking for visibility into subcontracting arrangements and downstream dependencies. The Register of Information under DORA explicitly captures subcontracting relationships as part of its ICT third-party mapping.

Managing Fourth-Party Risk in Practice

Most organizations cannot audit their vendors' vendors directly. Practical fourth-party risk management typically relies on contractual flow-downs (requiring vendors to impose equivalent obligations on their vendors), transparency requirements (mandating disclosure of critical subcontractors), continuity planning (contingencies for known critical fourth parties), and quantified analysis of the concentration risk fourth parties represent.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.