Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

fourth-party risk — Fourth-Party Risk: Managing the Subcontractor You Never Contracted With (2026)

Fourth-Party Risk: Managing the Subcontractor You Never Contracted With (2026)

Fourth-party risk is the risk that arrives through a provider’s own supplier: the subcontractor that holds your data, runs part of your service or sits in the delivery chain, and that you have never contracted with, assessed or, in many programmes, heard of. It is the part of third-party risk that the individual relationship review cannot see, and the regimes have caught up with it. This guide explains what fourth-party risk is, which obligations reach it, how to build the register and the contract rights that make it visible, and how to monitor a party you do not pay.

What this guide covers

fourth-party risk explained
Fourth-party risk: the register, the rights and the monitoring

What fourth-party risk is, and why it is yours

A third party is anyone you have a business arrangement with. A fourth party is anyone your third party relies on to deliver that arrangement: the data centre operator behind your cloud platform, the offshore development team behind your software vendor, the payment gateway behind your billing provider, the backup service behind the backup service. The provider chose them, contracted them and, in theory, oversees them. In practice, the provider’s oversight is the only control between your data and a company you cannot name.

Fourth-party risk is yours because every regime says accountability does not move with the activity. If a subcontractor loses your customer data, your regulator, your customers and your auditor hold you responsible, and the contract you signed with the provider decides whether you had any right to know the subcontractor existed.

The obligations that reach fourth-party risk

Regime What it requires
Interagency Guidance (2023) Reliance on subcontractors is due diligence factor (l); subcontractor reliance, location and the provider’s own oversight of them are monitoring considerations; subcontracting is contract consideration (n)
DORA Article 29(2) Weigh the benefits and risks of subcontracting critical services, particularly third-country subcontractors; assess whether long or complex chains impair monitoring and supervision
DORA Article 30(2)(a) The contract states whether subcontracting of critical services is permitted and on what conditions
GDPR Article 28(2) and 28(4) No sub-processor without prior written authorisation and a right to object; the same obligations flow down; the processor stays liable
HIPAA 45 CFR 164.314(a), 164.308(b) Business associates must bind their subcontractors by written contract to the same requirements
NIS2 Article 21(3) Account taken of the vulnerabilities specific to each supplier and the overall quality of their practices
NIST CSF 2.0 GV.SC-04, GV.SC-07 Suppliers known and prioritised; risks monitored over the relationship, which for a critical supplier includes its own suppliers

The DORA text goes furthest, because it asks a financial entity to consider before contracting whether a subcontracting chain would leave it unable to monitor the service or its supervisor unable to supervise. That is a question about fourth-party risk a programme has to be able to answer in writing. Our guide to DORA subcontracting covers the financial-entity specifics.

Building the fourth-party register

You cannot manage a party you have not listed. The register records every material subcontractor behind each provider: who it is, where it is, which part of your service it delivers, whether it holds or accesses your data, whether it supports a critical function, how you learned of it, whether you consented, whether the provider has evidenced its own oversight, whether the subcontractor itself subcontracts, and when the list was last confirmed. “Material” means any subcontractor performing part of a critical or important function or holding your data; the office cleaner behind your office cleaner is not the point.

Three sources populate the fourth-party risk register. Due diligence, where the questionnaire asks the provider to list every subcontractor with location and role. Contract notices, where the provider tells you before adding or replacing one. And assurance reports, whose carved-out subservice organisations are fourth parties the report does not cover. A subcontractor found on the provider’s list at a review and absent from your register is an unnotified change, and a finding.

The contract rights that make fourth-party risk visible

Everything above depends on four provisions negotiated in the third-party contract. Notice: the provider tells you, in advance, before adding or replacing a subcontractor on your service, with its location and role. Objection: you may refuse on reasonable grounds, and for a critical service the refusal is a termination right if the subcontracting would impair your monitoring or your regulator’s supervision.

Flow-down: every subcontractor is bound by obligations no less protective than the provider’s own, including the security schedule and any data protection or business associate terms, and the provider remains fully responsible for its subcontractors’ acts. And audit: your access and audit rights extend to subcontractors delivering critical services.

The contract also states, for critical services, whether subcontracting is permitted at all and on what conditions, and requires the same notice and consent for any further subcontracting down the chain. A contract without these provisions has made fourth-party risk unmanageable before the first subcontractor is engaged. The provisions cost nothing to include at signature and are close to impossible to obtain afterwards, which is why the requirements checklist treats them as mandatory for any provider that holds data or supports a critical function.

Assessing a proposed subcontractor for fourth-party risk

Question What to consider
What will it do, and with what data or access? Apply the same data and access assessment used for the provider
Where is it? A third-country location triggers the transfer assessment and, for financial entities, the data protection and enforcement questions
How long is the chain? Each link you cannot see is a link you cannot monitor; a chain that defeats supervision is a reason to refuse
Can you recover your data if it fails? Insolvency law in its jurisdiction, data location, the provider’s recovery obligation
Does the provider oversee it? Evidence of the provider’s own due diligence, contract flow-down and monitoring, not a statement that it does
Is it already behind another of your providers? A subcontractor shared across several critical providers is a concentration

Monitoring fourth-party risk through the provider

You do not contract with the subcontractor, so fourth-party risk monitoring runs through the provider. At each cadence point the provider confirms its current subcontractor list and you reconcile it to the register. For material subcontractors, the provider evidences its oversight: its assessment summary, confirmation that the security and data protection terms flow down, and the date of its last review. For critical arrangements you establish how deep the chain runs and record the point at which your visibility ends. Where the risk warrants it, the audit rights the contract reserved over subcontractors are exercised on the same risk basis as over the provider.

The finding that matters most is the one no single relationship review can produce: the same subcontractor, region or platform behind several of your critical providers. That is fourth-party risk becoming concentration risk, and it is found by reading the register across the portfolio, at least annually, and taking the result to the committee. Our guide to the vendor due diligence checklist covers where subcontractors enter the review; the third-party risk assessment guide covers the tiering question that flags unknown subcontracting as a risk in itself.

What good fourth-party risk management looks like

A register that reconciles to every provider’s disclosed list. Contracts that give notice, objection, flow-down and audit rights over subcontractors, with a stated position on subcontracting critical services. A due diligence questionnaire that asks for the subcontractor list with locations and roles and scores an unknown answer as a finding. A monitoring cadence that confirms the list and the provider’s oversight evidence.

A concentration assessment that reads the register across the portfolio. And a data return and destruction certificate at exit that covers what the subcontractors held, not only what the provider did. The TPRM Toolkit ships each of those: the fourth-party register, the subcontracting clause guide, the fourth-party monitoring procedure, the concentration procedure and register, and the destruction certificate with its subcontractor section. For the wider programme, start with what TPRM is, the TPRM lifecycle and the third-party risk management framework.

Frequently asked questions about fourth-party risk

How far down the chain does fourth-party risk go?

As far as your data and your critical functions go. A fifth party holding your data is inside your risk exactly as a fourth party is. The practical rule is to require notice and consent for any further subcontracting of critical services and to record the depth at which your visibility ends.

Can we assess fourth parties directly?

Usually only through the provider, which is why the provider’s oversight evidence matters. Where the contract reserves audit rights over subcontractors delivering critical services, direct assessment is possible and, for the most important ones, worth exercising.

Are cloud regions and data centres fourth parties?

Yes. The hyperscale platform behind a SaaS provider and the colocation operator behind that platform are subcontractors delivering your service. Their assurance reports are usually available and their locations are the first thing the register records.

What is the single most common fourth-party risk failure?

Not knowing. A programme that asks the question in due diligence, reserves the rights in the contract and confirms the list at each review gives itself the chance to see a fourth-party incident coming. A programme that does none of the three learns its subcontractor’s name from the breach notification.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.