Nth-party risk, the chain past the point you can enumerate it
Nth-party risk is exposure arriving from anywhere in the supply chain beyond your fourth parties — the fifth, sixth and further links you neither contract with nor can list. Because full enumeration is impossible, nth-party work concentrates on finding shared dependencies that many of your suppliers rely on at once.
Why enumeration fails
Each step down the supply chain multiplies. Forty vendors with ten suppliers each is four hundred fourth parties; the layer below that runs to thousands, most of them irrelevant and none of them under any obligation to tell you they exist. Programmes that set out to map the whole chain do not finish, and the effort spent trying is taken from work that would have changed a decision.
What is achievable is depth on the paths that matter. Take the business services you could not lose, follow only the vendors supporting them, and go down until you reach the infrastructure the chain converges on — which, in practice, is two or three layers and a short list of providers.
What to do instead
Look for convergence rather than coverage. The finding that changes behaviour is not "here are 3,000 nth parties", it is "nine of our twelve critical vendors terminate at the same identity provider". That is a concentration statement, it is actionable, and it can be reached without a complete map.
Contract terms help at the margin — requiring notice of material sub-contracting changes pushes disclosure one layer further — but the practical route is observation of the chain your fourth-party mapping already produced, extended only where the business impact justifies it.
Common questions
What is the difference between fourth-party and nth-party risk?
How far down the supply chain should we go?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.