TPRM glossary

Fourth-party risk, the suppliers your suppliers depend on

Fourth-party risk is the risk carried by your vendors’ own vendors — the hosting, payment, identity and support providers your suppliers depend on. You have no contract with them and usually no visibility of them, but their failure reaches you through the supplier you do have a contract with. Also called Vendor’s vendors.

Why it is not somebody else’s problem

Contractually, your vendor's suppliers are your vendor's business. Operationally, they are yours: when a hosting provider two steps down the chain goes offline, the service you bought stops, and the fact that you had no relationship with the party that failed changes nothing about the outage, regulatory obligation or customer impact.

It is also where concentration hides. A register of forty independent-looking vendors can resolve to a handful of underlying providers, so a portfolio that is diversified on paper fails together in practice. That pattern is not visible from any single vendor assessment; it only appears when the chain is mapped across the whole register.

How to get visibility

Three routes, and they work best together. Ask: a well-drafted contract requires disclosure of material sub-contractors and notice of changes, and DPAs already list authorised sub-processors. Observe: a vendor's external estate reveals its hosting, DNS, email and edge providers without anyone filling in a form. Read: trust centres and sub-processor pages are public and usually current.

Ambition should be proportionate. Mapping the fourth parties of every supplier is not achievable and not useful; mapping them for the vendors supporting critical business services is both. At RiskXchange, REX's fourth-party discovery works the observation route, which is what makes it possible on suppliers who will never complete a form about their own supply chain.

Common questions

What is the difference between third-party and fourth-party risk?
A third party is an organisation you have a direct relationship with. A fourth party is one your third party depends on and you do not contract with. The risk transmits the same way; the difference is that you can require things of a third party and can only ask about a fourth.
How do you identify fourth parties?
Contractual disclosure of sub-contractors, sub-processor lists in data processing agreements and trust centres, and outside-in observation of a vendor’s external estate, which reveals hosting, DNS, email and CDN providers directly. Each route is partial; together they cover most of what matters.
What is nth-party risk?
The same idea taken further down the chain — the fifth, sixth and subsequent parties beyond your fourth. In practice, nth-party work concentrates on identifying shared dependencies rather than enumerating every link.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.