Fourth-party risk is the operational risk exposure stemming from subcontractors hired by an organization’s primary (third-party) vendors to execute elements of a core service. While an organization has no direct contract with these fourth-party entities, their operational failures can impact the enterprise’s critical business lines.
  ┌────────────────────────────────────────────────────────┐
  │                 PRIMARY CORPORATE ENTITY               │
  └───────────────────────────┬────────────────────────────┘
                              ▼ (Direct Agreement)
  ┌────────────────────────────────────────────────────────┐
  │                THIRD-PARTY VENDOR BASE                 │
  └───────────────────────────┬────────────────────────────┘
                              ▼ (Indirect Reliance)
  ┌────────────────────────────────────────────────────────┐
  │                FOURTH-PARTY SUBCONTRACTORS             │
  │   • Niche Data Aggregators                             │
  │   • Specialized Hosting Nodes                          │
  └────────────────────────────────────────────────────────┘

To manage this extended supply chain, corporate policies must require primary vendors to obtain written approval before outsourcing any component of a critical service. The vendor must demonstrate that they apply due diligence and monitoring standards to their subcontractors that match the organization’s internal third-party risk management expectations.