Skip to main content
Category: Third-Party Risk

Fourth Party

Also known as: Fourth-Party Vendor, Fourth-Party Provider, Subcontractor of a Third Party
Simply put

A fourth party is a vendor or subcontractor that one of your own vendors relies on to deliver its services. In other words, if a third party is a company you contract with directly, a fourth party is a company that third party contracts with, meaning you have no direct relationship with them. These indirect relationships can still introduce security, compliance, and business risks to your organization.

Formal definition

In third-party risk management, a fourth party is an entity engaged by a third-party provider, commonly a subcontractor, downstream service provider, or strategic partner, that supports the delivery of goods or services to an organization without holding a direct contractual relationship with that organization. Fourth-party risk refers to the security, compliance, and business risks introduced through these indirect dependencies within an organization's supply chain. Because the organization typically lacks direct oversight or contractual leverage over fourth parties, exposure is generally assessed indirectly through the due diligence, contractual provisions, and monitoring applied to the intermediary third party. This entry addresses the GRC usage of the term and does not cover unrelated meanings such as mediation practice-management software or the political-science 'Fourth Party System.'

Why it matters

Fourth-party relationships extend an organization's risk exposure beyond the vendors it directly contracts with, into a tier of the supply chain where it has no direct contractual relationship and typically limited visibility. When a third party depends on a subcontractor or downstream provider to deliver its services, disruptions, security failures, or compliance breaches at that fourth party can flow through to the organization even though it never engaged that entity. This indirect nature is precisely what makes fourth-party risk difficult to govern: the organization generally cannot exercise direct oversight or contractual leverage over a party it has no agreement with.

The practical significance lies in the concentration and cascade effects that can arise deep in a supply chain. A single fourth party supporting multiple of an organization's third parties can become a hidden single point of failure, and because the dependency is indirect, it may not be surfaced during standard vendor onboarding. Left unmapped, these relationships can undermine assumptions about resilience, data protection, and regulatory adherence that an organization believes it has addressed through its direct third-party controls.

Because exposure to fourth parties is generally assessed indirectly, the quality of an organization's third-party due diligence, contractual provisions, and ongoing monitoring largely determines how well fourth-party risk is contained. Where those intermediary controls are weak, downstream risks may go unidentified until they materialize.

Who it's relevant to

Third-Party Risk Managers
Professionals responsible for vendor oversight need to account for the indirect dependencies their direct vendors rely on, since fourth-party exposure is generally assessed through the due diligence and monitoring applied to the intermediary third party rather than directly.
Compliance Officers
Those managing adherence to laws, regulations, and internal policies should consider whether compliance obligations extend into the vendor supply chain, as security and compliance risks can be introduced through vendors that an organization's own vendors depend on.
Procurement and Vendor Management Teams
Teams negotiating and administering vendor contracts may use contractual provisions with direct third parties to flow expectations down to subcontractors and downstream providers, since the organization typically lacks direct contractual leverage over fourth parties.
Risk and Resilience Professionals
Those assessing operational and business continuity risk should map indirect dependencies, because a fourth party supporting the delivery of a third party's services can introduce business risks that are not visible when only direct relationships are examined.

Inside Fourth Party

Fourth Party
An entity that provides goods or services to an organization's direct third-party supplier or vendor, rather than to the organization itself. The organization typically has no direct contractual relationship with the fourth party, whose services reach the organization indirectly through the third party.
Indirect Relationship
The defining characteristic that distinguishes a fourth party from a third party. A third party contracts directly with the organization; a fourth party is a subcontractor or supplier to that third party. This indirect chain complicates visibility and oversight.
Concentration and Dependency Risk
The exposure created when multiple third parties rely on the same underlying fourth party, or when critical services depend on a fourth party the organization cannot directly monitor. Such dependencies may aggregate risk that is not visible from the third-party layer alone.
Contractual Flow-Down
Provisions in the organization's contract with its third party that seek to impose obligations, such as security, confidentiality, or right-to-audit requirements, on the third party's own subcontractors (the fourth parties). This is a common mechanism for extending expectations down the supply chain, though its effectiveness varies.
Supply Chain Visibility
The extent to which an organization can identify and assess the fourth parties within its extended supply or service chain. Visibility is typically obtained indirectly, through disclosures by the third party rather than direct engagement with the fourth party.

Common questions

Answers to the questions practitioners most commonly ask about Fourth Party.

Is a fourth party just another name for a subcontractor that the organization can manage directly?
No. A fourth party is typically a subcontractor or supplier engaged by the organization's third party, not by the organization itself. In most cases the organization has no direct contractual relationship with the fourth party, which means it commonly cannot manage or instruct that entity directly. Influence over fourth parties is usually exercised indirectly, through contractual obligations, flow-down requirements, and oversight expectations placed on the third party. This distinction matters because it affects the organization's visibility, rights of audit, and ability to enforce controls.
Does mapping fourth parties transfer responsibility for their failures away from the organization?
Not necessarily. While the organization does not typically hold a direct contract with the fourth party, accountability for outcomes affecting the organization's objectives, customers, or regulatory obligations often remains with the organization. In many jurisdictions and sectors, regulators expect an organization to understand and manage risks arising throughout its supply chain, including beyond the immediate third party. Identifying fourth parties supports risk visibility and due diligence; it does not by itself discharge the organization's own responsibility or any applicable regulatory obligations.
How can an organization identify its fourth parties when it has no direct relationship with them?
Identification commonly relies on information obtained from the third party, because the organization typically lacks a direct contractual channel to the fourth party. Approaches may include contractual clauses requiring third parties to disclose material subcontractors, questionnaires and due diligence responses, and periodic reporting. The depth of visibility often varies by the criticality of the service, the third party's willingness to disclose, and applicable jurisdictional or sectoral expectations. Completeness of fourth-party mapping is frequently limited by the quality of information the third party provides.
What contractual mechanisms are commonly used to address fourth-party risk?
Organizations often rely on flow-down provisions in the contract with the third party, requiring that party to impose equivalent or comparable obligations on its own subcontractors. Common mechanisms may include disclosure and notification requirements for material subcontractors, rights of audit or assessment that extend through the chain, minimum control or security standards, and consent or objection rights over the use of particular subcontractors. The enforceability and scope of these provisions depend on the contract, negotiating position, and applicable law, and they do not create a direct relationship with the fourth party.
How should fourth-party risk assessment be prioritized given limited visibility?
Because visibility and resources are typically constrained, many organizations apply a risk-based approach focused on criticality rather than attempting to assess every fourth party equally. Factors commonly considered include the fourth party's role in delivering a critical service, concentration risk where many providers depend on the same underlying entity, and the potential impact of a disruption or failure on the organization's objectives and obligations. This prioritization is a management judgment and should be documented; specific thresholds and methods vary by organization and sector.
Which functions are typically responsible for managing fourth-party risk within an organization?
Responsibilities are commonly distributed. Business or procurement functions that own the third-party relationship often carry first-line responsibility for identifying and managing associated fourth-party exposure. Risk management, compliance, or vendor risk functions frequently provide oversight, policy, and challenge in a second-line capacity. Internal audit or other assurance functions may independently evaluate the effectiveness of these arrangements. The precise allocation varies by organization; the key distinction is that management activities and independent assurance over them should remain separate.

Common misconceptions

A fourth party is simply another term for a third party or subcontractor the organization deals with directly.
A fourth party sits one step further removed. It supplies the organization's third party, and the organization commonly has no direct contractual relationship with it. This indirectness is the essential distinction from a third party.
Because there is no direct contract, fourth-party risk falls outside the organization's concern.
Risks arising from fourth parties can still affect the organization through its dependence on the third party. Many organizations treat fourth-party exposure as part of extended third-party or supply chain risk management, even where direct oversight is limited.
Contractual flow-down clauses fully transfer control over fourth parties to the organization.
Flow-down provisions may extend expectations to subcontractors, but the organization typically retains no direct relationship with the fourth party and relies on the third party to enforce those terms. Such clauses shape obligations rather than guarantee oversight or outcomes.

Best practices

Require third parties to disclose material fourth parties, particularly those supporting critical or high-risk services, so that indirect dependencies can be identified.
Use contractual flow-down provisions to extend relevant security, confidentiality, and assurance expectations to fourth parties, while recognizing that enforcement typically depends on the third party.
Assess concentration and dependency risk by identifying where multiple third parties rely on the same underlying fourth party.
Incorporate fourth-party considerations into the organization's broader third-party or supply chain risk management processes rather than treating them in isolation.
Seek assurance about fourth-party controls indirectly through the third party, for example via reporting, attestations, or right-to-audit provisions, given the absence of a direct relationship.
Calibrate the depth of fourth-party oversight to the criticality of the service and the applicable jurisdictional or sectoral expectations, which may differ across contexts.
Promotional banner for the Penetration Report Template Kit