Fourth Party Risk
Definition
Fourth Party Risk
Fourth party risk is the exposure an organisation carries through its suppliers’ own suppliers, one step beyond the relationships it contracts with directly. You cannot see it from your contract — it appears only when you ask your provider who it depends on.
The concentration problem is the reason it matters — four independent-looking providers may all sit on one hosting platform, one payment gateway or one identity service.
Contractual reach runs out quickly. You have rights against your provider, weaker rights through flow-down terms, and usually none at all against the party two steps away.
Visibility is the whole remedy — a provider that can name its critical dependencies lets you model a failure, and one that cannot leaves you carrying an exposure you never priced.
Key takeaways
- Fourth party risk sits beyond your direct supplier, in the chain it depends on.
- Concentration is the main danger, because separate providers often share one platform.
- Flow-down clauses give indirect reach but no direct claim against the fourth party.
- Mapping critical dependencies matters more than extending contractual rights.
How it works
The method is dependency mapping. For each critical service you list your provider’s critical inputs, then look for the same name appearing behind several apparently unrelated suppliers.
The core problem is visibility rather than negligence. Organisations face risks tied to their “decreased visibility into and understanding of how the technology they acquire is developed, integrated, and deployed” within the supply chain.
| Layer | Who it is | Your rights | Your visibility |
|---|---|---|---|
| Second party | Your direct provider | Full contractual | Complete |
| Third party | Provider’s subcontractor | Flow-down terms | Usually named |
| Fourth party | That subcontractor’s supplier | None directly | Rarely disclosed |
| Shared platform | A common dependency | None | Visible only by mapping |
| Concentration | Several chains, one input | None | Requires cross-analysis |
The bottom two rows are where the real exposure lives. A dependency that four suppliers share turns a single outage into a simultaneous failure across services you deliberately diversified.
National guidance frames this as a control problem. Published principles are designed “to help you establish effective control and oversight of your supply chain”, rather than to extend legal rights downward.
Supervisors take the same view of proportionality. Guidance “clarifies that not all third-party relationships present the same level of risk”, which applies equally to the layer below them.
Examples
Fourth party exposure surfaces during outages far more often than during diligence. The four cases below show it being found early and being found late.
A buyer maps its four contact-centre providers and finds all four route voice traffic through one carrier. The disaster recovery clause is rewritten around a single point of failure nobody had priced.
A financial buyer requires each provider to disclose its critical dependencies annually. Two suppliers share a fraud-screening service, which changes the continuity design for both.
A retailer loses three digital services in one morning when a shared hosting region fails. Each contract was with a different company, and each company used the same platform.
A multisourcing buyer discovers a subcontractor two layers down handles personal data. Nobody had assessed it, because nobody knew it existed.
Related terms
Supplier layers, oversight programmes and contractual reach are easily confused with one another. The entries below separate each layer from the tools that apply to it.
- Sub-processor clause: the provision that makes the third layer visible, and sometimes the fourth.
- OCC third-party guidance: supervisory expectations that increasingly reach past direct suppliers.
- Vendor management outsourcing: the function that should be running dependency mapping.
- Multi-vendor outsourcing: a model that multiplies chains and hides shared dependencies inside them.
- Business continuity clause: the obligation that must account for dependencies you do not contract with.
FAQ
What exactly is a fourth party?
A supplier to your supplier’s supplier. If you contract with A, who uses B, and B uses C, then C is your fourth party.
Can contracts reach that far?
Not directly. Flow-down clauses oblige your provider to impose equivalent terms downward, but you normally have no claim against the fourth party itself.
How is the exposure found?
By dependency mapping. Ask each critical provider to name its critical inputs, then compare the lists across suppliers to find shared names.
Why does concentration matter so much?
Because it defeats diversification. Buying the same service from four suppliers offers no protection if all four depend on one platform underneath.
What should a contract require?
Annual disclosure of critical dependencies, notification of material changes, and flow-down of continuity and security obligations to each layer below.
Is this the same as third-party risk?
No. Third-party risk covers the suppliers you contract with, while fourth party risk covers the layer beyond them, where you usually have neither rights nor reliable visibility.
Map your supplier chain from a verified base in the Outsource Accelerator directory.







Independent




