[{"data":1,"prerenderedAt":402},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"guide-en-fourth-party-risk":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":69,"entities":343,"extension":346,"faq":347,"keywords":365,"meta":371,"navigation":372,"ogImage":373,"path":374,"persona":375,"publishedAt":376,"regulation":373,"relatedFeatures":377,"relatedPages":381,"seo":385,"shortTitle":67,"slug":386,"sources":387,"stem":398,"tldr":399,"updatedAt":400,"__hash__":401},"guides_en\u002Fen\u002Fguides\u002Ffourth-party-risk.md","Fourth-Party Risk: The Blind Spot in Vendor Management | CISAPP","CISAPP",{"type":108,"value":109,"toc":335},"minimark",[110,115,124,127,130,159,163,169,175,181,187,191,194,200,206,212,218,224,296,300,303,309,320,326,332],[111,112,114],"h2",{"id":113},"what-is-fourth-party-risk","What is fourth-party risk?",[116,117,118,119,123],"p",{},"Your due diligence covers your direct vendors — the ones you've signed a contract with, sent a questionnaire to, and track criticality for. But each of these vendors in turn depends on its own providers: a cloud host, a payment subcontractor, an outsourced customer support platform, an IT maintenance firm. These entities — ",[120,121,122],"strong",{},"fourth parties"," — have no contractual relationship with you, and yet their failure or compromise can directly affect the service your vendor provides you, or the security of the data you've entrusted to it.",[116,125,126],{},"Fourth-party risk is structurally harder to manage than direct vendor risk, for a simple reason: you have no contractual relationship, no negotiating leverage, and no direct access to that entity. Your only path of action runs through your direct vendor, who must be asked to make its own subcontracting chain visible — a step that is neither systematic nor always commercially welcomed.",[116,128,129],{},"This risk has played out dramatically in several major incidents in recent years: massive breaches where the ultimate victim organization wasn't even aware of the existence of the technical subcontractor at the root of the failure, several tiers upstream of its direct contractual relationship.",[131,132,133],"key-takeaways",{},[134,135,136,140,149,156],"ul",{},[137,138,139],"li",{},"No direct contract: visibility necessarily runs through the tier-1 vendor.",[137,141,142,143,148],{},"GDPR Article 28 requires authorisation and control of ",[144,145,147],"a",{"href":146},"\u002Fen\u002Fglossary\u002Fsub-processor","sub-processors",".",[137,150,151,152,148],{},"The extended chain is the main source of invisible ",[144,153,155],{"href":154},"\u002Fen\u002Fglossary\u002Fconcentration-risk","concentration risk",[137,157,158],{},"Going deeper than the tier supporting a critical activity produces an unmanageable inventory.",[111,160,162],{"id":161},"why-does-this-risk-stay-structurally-underrated","Why does this risk stay structurally underrated?",[116,164,165,168],{},[120,166,167],{},"Due diligence effort stops, by default, at the first tier."," Most vendor management processes, even mature ones, stop at assessing the direct vendor. Systematically questioning every vendor about its own subcontracting chain requires additional effort that few organizations formalize — for lack of time, method, or simply because the question doesn't come up until an incident reveals it.",[116,170,171,174],{},[120,172,173],{},"Vendors themselves don't always have that visibility internally."," A vendor may itself have limited knowledge of the full extent of its own technical subcontracting chain, particularly for cloud services built from multiple infrastructure layers. Demanding transparency from a third party that doesn't have it internally is an uphill battle.",[116,176,177,180],{},[120,178,179],{},"There's no automatic contractual lever."," Without an explicit clause requiring the vendor to declare and govern its own subcontractors — with equivalent security guarantees passed down — nothing structurally forces this transparency. GDPR enforces this principle for personal-data subprocessors (Article 28), but its application remains uneven in practice.",[116,182,183,186],{},[120,184,185],{},"An incident at a tier-2 subcontractor is rarely notified in time."," Even where a contractual clause exists, information flowing up from the tier-2 subcontractor to the direct vendor, then to the end organization, adds delay — every extra link in the chain slows detection and response.",[111,188,190],{"id":189},"how-do-you-extend-the-map-without-extending-the-contract","How do you extend the map without extending the contract?",[116,192,193],{},"Managing fourth-party risk can't rely on the same mechanisms as direct vendor risk — it requires an approach adapted to the absence of a direct contractual relationship.",[116,195,196,199],{},[120,197,198],{},"1. Document the declared chain, even without direct contractual leverage."," The realistic goal isn't to audit every tier-2 subcontractor like a direct vendor, but to obtain from each critical vendor a structured declaration of its own significant dependencies — hosting, payments, support, critical infrastructure.",[116,201,202,205],{},[120,203,204],{},"2. Prioritize by the direct vendor's criticality, not exhaustively."," Documenting the subcontracting chain for every vendor indiscriminately is neither realistic nor useful. Effort should concentrate on vendors already classified as critical, where a tier-2 failure would directly impact an essential activity.",[116,207,208,211],{},[120,209,210],{},"3. Contractually mandate transparency and notification."," For the most sensitive relationships, the contractual clause should require not just declaration of significant subcontractors, but also notification of changes and an obligation to alert in case of an incident affecting one of them — a principle already enshrined in GDPR for further subprocessors.",[116,213,214,217],{},[120,215,216],{},"4. Treat every incident reported by a vendor as potentially originating from its own chain."," Operationally, it's often more effective to systematically ask, for every incident reported by a vendor, \"is this at them, or at one of their own providers?\" rather than waiting for an exhaustive prior mapping — vigilance about the incident's real origin is often the most concrete trigger for the whole effort.",[116,219,220,223],{},[120,221,222],{},"5. Feed the declared chain back into existing concentration mapping."," If several direct vendors declare depending on the same upstream subcontractor, that information should flow into the overall concentration analysis — a tier-2 SPOF can be more dangerous than a tier-1 one, precisely because it stays invisible longer.",[225,226,228],"comparison-table",{"caption":227},"What can be required at each tier of the subcontracting chain",[229,230,231,250],"table",{},[232,233,234],"thead",{},[235,236,237,241,244,247],"tr",{},[238,239,240],"th",{},"Tier",[238,242,243],{},"Relationship",[238,245,246],{},"What can be required",[238,248,249],{},"Applicable framework",[251,252,253,268,282],"tbody",{},[235,254,255,259,262,265],{},[256,257,258],"td",{},"Tier 1 (direct vendor)",[256,260,261],{},"Signed contract",[256,263,264],{},"Questionnaire, evidence, audit, remediation",[256,266,267],{},"NIS2 Art. 21, ISO A.5.19-A.5.23, GDPR Art. 28",[235,269,270,273,276,279],{},[256,271,272],{},"Tier 2 (vendor's subcontractor)",[256,274,275],{},"No direct link",[256,277,278],{},"Disclosure, prior authorisation, flow-down of clauses",[256,280,281],{},"GDPR Art. 28, ISO A.5.21",[235,283,284,287,290,293],{},[256,285,286],{},"Tier 3 and beyond",[256,288,289],{},"No link, often undisclosed",[256,291,292],{},"Case-by-case visibility on critical activities",[256,294,295],{},"Concentration analysis",[111,297,299],{"id":298},"how-does-cisapp-give-visibility-into-this-extended-chain","How does CISAPP give visibility into this extended chain?",[116,301,302],{},"CISAPP doesn't claim to eliminate fourth-party risk — no tool can, without a direct contractual relationship — but it structures the mechanisms that let you document it and react to it.",[116,304,305,308],{},[120,306,307],{},"A vendor record that captures declared context, not just the contract."," Every vendor record in CISAPP keeps a history and context notes that let you document significant dependencies declared by the vendor — host, critical technical subcontractor — in the same place as the rest of its due diligence file, rather than in a lost email.",[116,310,311,314,315,319],{},[120,312,313],{},"The GDPR registry for personal-data subprocessors."," The GDPR processing registries module (",[316,317,318],"code",{},"\u002Fgdpr\u002Fregistries",") explicitly documents subprocessors and their own onward transfers, in line with Article 28 — the personal-data subcontracting chain is therefore natively tracked, with recipients and transfers attached to each processing activity.",[116,321,322,325],{},[120,323,324],{},"Incoming incidents that reveal the real chain at the moment it matters."," The incoming-incidents feature (cross-organization propagation) lets you receive notification of an incident declared by a vendor — including when the root cause traces back to one of its own providers. This is often the moment the fourth-party chain becomes concrete and actionable, rather than a theoretical mapping exercise.",[116,327,328,331],{},[120,329,330],{},"A concentration map that absorbs the information as it emerges."," When a tier-2 dependency shared across several direct vendors is identified — through due diligence, an incident, or a contractual declaration — it can be documented at the activity or risk level concerned, feeding the overall concentration map instead of staying an isolated data point.",[116,333,334],{},"Fourth-party risk isn't solved with an audit — it's managed through continuous documentation, prioritization, and fast reaction the moment it materializes. CISAPP gives risk and security teams a single place to capture this extended context, instead of leaving it scattered across emails, contracts, and individual memory.",{"title":336,"searchDepth":337,"depth":337,"links":338},"",2,[339,340,341,342],{"id":113,"depth":337,"text":114},{"id":161,"depth":337,"text":162},{"id":189,"depth":337,"text":190},{"id":298,"depth":337,"text":299},[67,344,345],"Sub-processor","Concentration risk","md",[348,350,353,356,359,362],{"q":114,"a":349},"It's the risk carried by your own vendors' subcontractors (third parties) — entities you have no direct contractual relationship with, yet on which the security or continuity of the service your vendor provides still depends.",{"q":351,"a":352},"Why can't we just assess those subcontractors directly?","Because you have neither a contractual relationship nor direct leverage over them. The assessment necessarily goes through your direct vendor, who must be asked for visibility into its own subcontracting chain.",{"q":354,"a":355},"Does GDPR require visibility into tier-2 subprocessors?","It requires the data controller to know and govern the further subprocessors of its own processor (Article 28), with prior authorization and the transfer of equivalent contractual safeguards — visibility into tier 2 is therefore an obligation, not an option.",{"q":357,"a":358},"How does CISAPP help cover this risk without a direct contract?","By documenting, through the GDPR registry and vendor record notes, the subcontracting chain declared by each third party, and by linking incidents received from a vendor — including those caused by its own subcontractors — to the risk register and dependency map.",{"q":360,"a":361},"Which contract clauses make the chain visible?","Three at minimum: an obligation to disclose the list of sub-processors, an obligation to give prior notice of any change with a right to object, and the flow-down of the same security and incident notification commitments along the chain.",{"q":363,"a":364},"How far down the chain should you go?","In practice, down to the tier that actually supports a critical activity or hosts sensitive data. Going deeper produces an unmanageable inventory; stopping at the direct vendor leaves the most common concentration — shared hosting providers — invisible.",[366,367,368,369,370],"fourth party risk","fourth-party risk management","vendor subcontracting risk","extended supply chain risk","nth-party risk",{},true,null,"\u002Fen\u002Fguides\u002Ffourth-party-risk","entreprise","2026-07-11",[378,379,380],"Vendors","Mapping & exposure","GDPR — registries & breaches",[382,383,384],"cybersecurite-supply-chain","gestion-risque-fournisseur","rgpd",{"title":105,"description":69},"fourth-party-risk",[388,393],{"label":389,"url":390,"publisher":391,"date":392},"Regulation (EU) 2016\u002F679 (GDPR), Article 28 — sub-processors","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2016\u002F679\u002Foj","EUR-Lex","2016-04-27",{"label":394,"url":395,"publisher":396,"date":397},"ISO\u002FIEC 27001:2022, control A.5.21 — ICT supply chain security","https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F27001","ISO","2022-10-25","en\u002Fguides\u002Ffourth-party-risk","Fourth-party risk is the risk carried by your vendors' own subcontractors, with whom you have no contractual relationship. It cannot be assessed directly: it is made visible through contractual disclosure of the subcontracting chain, mandatory under GDPR Article 28 for personal data and expected by ISO\u002FIEC 27001 (A.5.21) and NIS2.","2026-08-16","yYyGBPfV4xGXc2Q90ZvVHxPvx34y_YAoI_OWLggEtK8",1791391139254]