Fourth-Party Risk
Fourth-party risk is the risk your organization inherits from your vendors' vendors, that is, the subcontractors and suppliers your direct suppliers rely on to deliver their services. Even though you have no direct relationship or contract with these fourth parties, a failure or security incident on their side can still disrupt or harm your organization. Managing it is generally treated as an extension of a broader third-party risk management program.
Fourth-party risk refers to the exposure an organization faces from entities that its direct third-party vendors depend upon, including subcontractors, service providers, and downstream suppliers with which the organization typically has no contractual privity. It is distinct from third-party risk, which arises from vendors the organization engages directly; fourth-party risk sits one tier further along the supply chain and, when extended to additional tiers, is often generalized as 'nth-party risk.' The sources emphasize cyber threat as a principal concern, though the concept extends to operational, service-delivery, and concentration risks as well. Because organizations generally lack a direct oversight relationship with fourth parties, practitioners typically address this risk indirectly through the maturity of their third-party risk management (TPRM) program, including vendor due diligence, contractual flow-down requirements, and mapping of subcontractor dependencies. The specific obligations and effective controls are fact-specific and depend on sector, jurisdiction, and the risk profile of the underlying data or service; readers should verify applicable regulatory or contractual requirements against current authoritative sources.
Why it matters
As organizations increasingly rely on complex supply chains, the failure of an entity you have never contracted with, and may not even know exists, can still disrupt your operations or expose your data. Fourth-party risk matters because the subcontractors and downstream suppliers your direct vendors depend on can become the weak link that undermines an otherwise sound vendor relationship. A security incident or service outage several tiers removed from your organization can still reach you through the chain of dependencies, and you generally have no direct contractual leverage to compel remediation.
Cyber threat is a principal concern in this area, but the exposure is broader than security alone. Fourth parties can introduce operational, service-delivery, and concentration risks, for example when many of your vendors quietly rely on the same underlying provider, creating a single point of failure that is invisible unless subcontractor dependencies are mapped. Because privity of contract typically stops at your direct third party, the practical challenge is that visibility and control diminish sharply the further along the supply chain the risk sits.
The common thread across practitioner sources is that fourth-party risk is best addressed not as a separate discipline but as an extension of a mature third-party risk management program. The specific obligations and effective controls are fact-specific and depend on sector, jurisdiction, and the risk profile of the underlying data or service, so readers should verify applicable regulatory or contractual requirements against current authoritative sources rather than treating any single approach as universally sufficient.
Who it's relevant to
Inside Fourth-Party Risk
Common questions
Answers to the questions practitioners most commonly ask about Fourth-Party Risk.

