Fourth-Party Risk
Definition
The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's data or operations may depend on a party it has never assessed. Fourth-party risk is a growing focus in mature third-party risk programmes.
- Definition scope
- A vendor's own subcontractors and suppliers
- Key issue
- Never directly assessed by the organisation
- Domain
- Third-party/vendor risk management
- Trend
- Growing focus in mature TPRM programmes
Common questions
How can an organisation get visibility into fourth-party risk it has never directly contracted with?+
Organisations typically require critical vendors to disclose their key subcontractors, review the vendor's own subcontractor due-diligence process, and use commercial risk-intelligence services that map supply chain dependencies rather than assessing every subcontractor directly.
Why does fourth-party risk matter more for critical vendors than for minor ones?+
If a critical vendor's own outsourced process fails or is breached, that failure flows through to the organisation's data or operations regardless of how well the primary vendor itself was assessed, so the depth of subcontracting matters most where dependency is highest.
What contractual mechanism helps an organisation manage fourth-party exposure?+
Flow-down clauses requiring the primary vendor to impose equivalent security and notification obligations on its own subcontractors, combined with a right to audit or receive disclosure of material subcontracting relationships.
Related terms
- Audit Rights Clause
- A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
- CAIQ (Consensus Assessments Initiative Questionnaire)
- A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix...
- Inherent Risk
- The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be:...
- SIG (Standardised Information Gathering)
- A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business...
- SOC 2 Type II Report
- An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover...