Fourth-party risk is the operational risk exposure stemming from subcontractors hired by an organization’s primary (third-party) vendors to execute elements of a core service. While an organization has no direct contract with these fourth-party entities, their operational failures can impact the enterprise’s critical business lines.
┌────────────────────────────────────────────────────────┐
│ PRIMARY CORPORATE ENTITY │
└───────────────────────────┬────────────────────────────┘
▼ (Direct Agreement)
┌────────────────────────────────────────────────────────┐
│ THIRD-PARTY VENDOR BASE │
└───────────────────────────┬────────────────────────────┘
▼ (Indirect Reliance)
┌────────────────────────────────────────────────────────┐
│ FOURTH-PARTY SUBCONTRACTORS │
│ • Niche Data Aggregators │
│ • Specialized Hosting Nodes │
└────────────────────────────────────────────────────────┘
To manage this extended supply chain, corporate policies must require primary vendors to obtain written approval before outsourcing any component of a critical service. The vendor must demonstrate that they apply due diligence and monitoring standards to their subcontractors that match the organization’s internal third-party risk management expectations.