Fourth-party risk, the suppliers your suppliers depend on
Fourth-party risk is the risk carried by your vendors’ own vendors — the hosting, payment, identity and support providers your suppliers depend on. You have no contract with them and usually no visibility of them, but their failure reaches you through the supplier you do have a contract with. Also called Vendor’s vendors.
Why it is not somebody else’s problem
Contractually, your vendor's suppliers are your vendor's business. Operationally, they are yours: when a hosting provider two steps down the chain goes offline, the service you bought stops, and the fact that you had no relationship with the party that failed changes nothing about the outage, regulatory obligation or customer impact.
It is also where concentration hides. A register of forty independent-looking vendors can resolve to a handful of underlying providers, so a portfolio that is diversified on paper fails together in practice. That pattern is not visible from any single vendor assessment; it only appears when the chain is mapped across the whole register.
How to get visibility
Three routes, and they work best together. Ask: a well-drafted contract requires disclosure of material sub-contractors and notice of changes, and DPAs already list authorised sub-processors. Observe: a vendor's external estate reveals its hosting, DNS, email and edge providers without anyone filling in a form. Read: trust centres and sub-processor pages are public and usually current.
Ambition should be proportionate. Mapping the fourth parties of every supplier is not achievable and not useful; mapping them for the vendors supporting critical business services is both. At RiskXchange, REX's fourth-party discovery works the observation route, which is what makes it possible on suppliers who will never complete a form about their own supply chain.
Common questions
What is the difference between third-party and fourth-party risk?
How do you identify fourth parties?
What is nth-party risk?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.