Fourth Party
A fourth party is a vendor or subcontractor that one of your own vendors relies on to deliver its services. In other words, if a third party is a company you contract with directly, a fourth party is a company that third party contracts with, meaning you have no direct relationship with them. These indirect relationships can still introduce security, compliance, and business risks to your organization.
In third-party risk management, a fourth party is an entity engaged by a third-party provider, commonly a subcontractor, downstream service provider, or strategic partner, that supports the delivery of goods or services to an organization without holding a direct contractual relationship with that organization. Fourth-party risk refers to the security, compliance, and business risks introduced through these indirect dependencies within an organization's supply chain. Because the organization typically lacks direct oversight or contractual leverage over fourth parties, exposure is generally assessed indirectly through the due diligence, contractual provisions, and monitoring applied to the intermediary third party. This entry addresses the GRC usage of the term and does not cover unrelated meanings such as mediation practice-management software or the political-science 'Fourth Party System.'
Why it matters
Fourth-party relationships extend an organization's risk exposure beyond the vendors it directly contracts with, into a tier of the supply chain where it has no direct contractual relationship and typically limited visibility. When a third party depends on a subcontractor or downstream provider to deliver its services, disruptions, security failures, or compliance breaches at that fourth party can flow through to the organization even though it never engaged that entity. This indirect nature is precisely what makes fourth-party risk difficult to govern: the organization generally cannot exercise direct oversight or contractual leverage over a party it has no agreement with.
The practical significance lies in the concentration and cascade effects that can arise deep in a supply chain. A single fourth party supporting multiple of an organization's third parties can become a hidden single point of failure, and because the dependency is indirect, it may not be surfaced during standard vendor onboarding. Left unmapped, these relationships can undermine assumptions about resilience, data protection, and regulatory adherence that an organization believes it has addressed through its direct third-party controls.
Because exposure to fourth parties is generally assessed indirectly, the quality of an organization's third-party due diligence, contractual provisions, and ongoing monitoring largely determines how well fourth-party risk is contained. Where those intermediary controls are weak, downstream risks may go unidentified until they materialize.
Who it's relevant to
Inside Fourth Party
Common questions
Answers to the questions practitioners most commonly ask about Fourth Party.