Skip to content

Fourth-Party Risk

Definition

The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's data or operations may depend on a party it has never assessed. Fourth-party risk is a growing focus in mature third-party risk programmes.

Definition scope
A vendor's own subcontractors and suppliers
Key issue
Never directly assessed by the organisation
Domain
Third-party/vendor risk management
Trend
Growing focus in mature TPRM programmes

Common questions

How can an organisation get visibility into fourth-party risk it has never directly contracted with?+

Organisations typically require critical vendors to disclose their key subcontractors, review the vendor's own subcontractor due-diligence process, and use commercial risk-intelligence services that map supply chain dependencies rather than assessing every subcontractor directly.

Why does fourth-party risk matter more for critical vendors than for minor ones?+

If a critical vendor's own outsourced process fails or is breached, that failure flows through to the organisation's data or operations regardless of how well the primary vendor itself was assessed, so the depth of subcontracting matters most where dependency is highest.

What contractual mechanism helps an organisation manage fourth-party exposure?+

Flow-down clauses requiring the primary vendor to impose equivalent security and notification obligations on its own subcontractors, combined with a right to audit or receive disclosure of material subcontracting relationships.

Related terms

Audit Rights Clause
A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
CAIQ (Consensus Assessments Initiative Questionnaire)
A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix...
Inherent Risk
The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be:...
SIG (Standardised Information Gathering)
A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business...
SOC 2 Type II Report
An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.