Guide · Foundations

Fourth-party risk, explained.

Foundations · 8 min read · Updated July 2026

Fourth-party risk is the risk you inherit from your vendors' vendors — the subprocessors, hosting providers, and component suppliers you never signed a contract with but still depend on. It is the part of your attack surface you can't see directly, only through the third parties you do control. It sits inside third-party risk management and runs naturally into supply chain risk management. This guide explains where it comes from, why it's growing, and how to bring it into view.

In one sentence

Fourth-party risk is the risk that flows to you from your vendors' own suppliers — the subprocessors, infrastructure providers, and downstream vendors your third parties rely on, whom you depend on indirectly but never contracted with.

What fourth-party risk is

Your third parties have third parties. The SaaS platform you pay runs on a cloud provider you didn't choose; that platform sends your data to a subprocessor for analytics, and that subprocessor uses a hosting company of its own. Each link past your direct suppliers is a fourth party — and the risk that reaches you through them is fourth-party risk.

The counting is literal. You are the first party; your direct supplier is the third party; their supplier is the fourth. Keep going and you reach the fifth, sixth, and beyond — which is why practitioners increasingly say nth-party risk to name the whole chain rather than a single link. The label matters less than the point: your data and your operations depend on parties several steps removed from any contract you signed.

The clearest everyday example is the subprocessor. Under GDPR, a processor that handles personal data on your behalf may engage sub-processors to help — and those sub-processors handle your data without ever appearing in your vendor register unless you go looking for them.

Why fourth-party risk matters now

Two forces make fourth-party risk larger every year. The first is concentration. A handful of cloud platforms, identity providers, and infrastructure companies sit beneath a huge share of the software economy, which means a single fourth party can be shared — invisibly — across dozens of your third parties. When it fails, it doesn't fail for one of your vendors; it fails for many at once.

The second is opacity. Your controls end at your direct supplier. You can audit them, question them, and write terms into their contract — but their choice of subprocessor is theirs, and the next link is theirs, and visibility decays with every step. When an incident starts several parties out, your third party may not learn of it in time to tell you, and your own monitoring never sees it coming.

Regulators have noticed. The EU's DORA explicitly reaches ICT subcontracting chains, not just the direct provider, and expects financial entities to understand concentration risk across the chain. This is an informational summary of an EU baseline, not legal advice — verify the detail against DORA itself and its national transposition. The direction of travel is clear either way: fourth-party exposure is something you are now expected to account for.

How to bring fourth parties into view

You cannot manage what you cannot see, and fourth parties are, by definition, one step past your visibility. Three practices narrow the gap:

  • Subprocessor disclosure. Require your third parties to name their subprocessors and notify you of changes — as a contractual term, not a favour. Many mature vendors already publish a subprocessor list; make reviewing it part of assessment.
  • Map concentration. Look across your register for the shared fourth parties — the cloud region, the identity provider, the payment rail that many of your vendors quietly rely on. Concentration is where a single failure becomes a correlated one.
  • Watch external signals. Continuous monitoring of your third parties can surface trouble in the chain behind them — a subprocessor breach, a downstream outage, a lapsed certification — before your next scheduled reassessment would.

That last practice is where outside-in monitoring earns its place. It won't tell you what a vendor holds of yours — only your own exposure model does that — but it is well suited to catching movement in the chain. Polestead's external signals layer does exactly this: it watches the outside-in picture as a monitoring feed on top of your exposure-based classification, rather than as the classification itself.

How to manage fourth-party risk

Fourth-party risk can't be assessed the way a direct vendor is — you have no contract to compel evidence, and no standing to send a questionnaire. So the management model shifts from direct diligence to indirect control:

  1. Push obligations down the chain. Require your third parties to hold their subprocessors to standards equivalent to the ones you hold them to — flow-down clauses that survive past the first link.
  2. Prioritise by your exposure, not their count. A fourth party beneath a low-exposure vendor rarely matters; one beneath a supplier that holds your regulated data matters a great deal. Let the third party's exposure to you set how far down you look.
  3. Model concentration explicitly. Treat a widely shared fourth party as a single point of failure and plan for its loss, the same way you would for a critical direct vendor.
  4. Monitor continuously. Because you can't audit fourth parties on a schedule, lean on ongoing signals to tell you when something in the chain has moved.

Fourth-party risk is ultimately a supply-chain problem wearing a cyber label — which is why it belongs in the same program as your supply chain risk management, governed by the same tiering logic and the same principle: depth follows exposure.

Where fourth-party risk shows up

Fourth-party risk is easier to act on once you can recognise it in the wild. A few patterns recur across almost every organization:

  • The shared cloud region. A dozen of your SaaS vendors run in the same cloud provider's single region. That region is one fourth party — and one outage takes all twelve offline together.
  • The analytics or messaging subprocessor. Your CRM vendor pipes customer data to a third-party analytics or email service. Your data now lives somewhere you never assessed and can't audit directly.
  • The upstream component maker. A hardware supplier sources a critical chip from a single manufacturer several tiers down. A shortage or compromise there ripples straight through to you.
  • The shared identity provider. Many of your vendors authenticate through the same identity platform. Its compromise is a skeleton key to a large slice of your supply base at once.

None of these parties are on your contracts, yet each can take down or expose something you depend on. Naming the pattern is the first step to pricing the risk.

Watch the chain
Polestead pairs exposure-based classification with outside-in monitoring.

External signals watch your third parties — and the movement in the chain behind them — as a continuous feed on top of an inside-out model that scopes depth to what each vendor actually holds of yours.

See how external signals work →
FAQ

Common questions.

What is fourth-party risk?+

The risk that reaches you through your vendors' own suppliers — the subprocessors, infrastructure providers, and downstream vendors your third parties depend on, whom you depend on indirectly but never contracted with.

What is the difference between third-party and fourth-party risk?+

Third-party risk comes from the suppliers you contract with directly; fourth-party risk comes from their suppliers — one link further down the chain, past your direct visibility and control. See our TPRM guide.

What is nth-party risk?+

A generalisation of fourth-party risk to the whole chain — fifth, sixth, and beyond. The term names the reality that your data and operations can depend on parties many steps removed from any contract you signed.

How do you manage risk from subprocessors you never contracted with?+

Indirectly: require your direct vendors to disclose and control their subprocessors through flow-down clauses, map where a shared fourth party concentrates risk, and monitor continuously for movement in the chain rather than relying on point-in-time audits you have no standing to run.

Keep reading
Third-party risk management
The program fourth-party risk sits inside.
Supply chain risk management
Where the chain view is governed end to end.
External signals →
How Polestead monitors the chain behind your vendors.