Glossary
Fourth-party risk
Fourth-party risk is the risk an organisation carries because of its vendors' own subcontractors — entities it has no direct contract with, yet on which the security or availability of the service it buys depends.
Why classic due diligence misses it
Vendor assessment stops by default at the first tier: the party that signed a contract. That vendor in turn relies on a hosting provider, a payment processor, an outsourced support desk. These second-tier entities owe nothing to the end buyer, who has no contractual leverage, no audit right and usually no knowledge that they exist.
The consequence is a detection lag: an incident at tier 2 must reach the direct vendor before it can be notified, adding delay at every link.
How to treat it without a contract
Three realistic levers, detailed in the fourth-party risk guide:
- Declaration: require critical vendors to list their significant dependencies (hosting, payment, infrastructure), without aiming for exhaustiveness.
- Contract clause: require notification of any change of subcontractor and an alert when an incident hits one of them — a principle already set by Article 28 of the GDPR for sub-processors.
- Aggregation: consolidate declared dependencies to spot a subcontractor shared by several vendors, a concentration invisible at tier 1.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours