In today’s interconnected supply chains, assessing and monitoring your contracted third-party suppliers is no longer enough. Critical supply chain risks are now emerging from your suppliers’ suppliers: fourth-party vendors.
From vendor concentration risks to cascading supply chain breaches, fourth-party vendors can trigger widespread disruption to your business operations even without a direct commercial link.
If a fourth-party vendor suffers an outage - be it the cloud infrastructure your direct suppliers rely on or the LLM underpinning your SaaS tools’ functionality - it can wipe out handfuls of your critical suppliers in one go, undermining your ability to deliver core services.
Yet, despite the increasing prevalence of fourth-party failures, such as Crowdstrike’s 2024 outage disabling 8.5 million Windows devices, most organisations struggle to see their fourth-party connections, let alone manage them.
As traditional third-party risk management (TPRM) focuses on individual direct supplier assurance, security leaders have limited visibility beyond third parties. Our research found that 96% of CISOs consider extended supply chain visibility essential for mitigating risks, but 73.2% of organisations lack full visibility into their nth party connections.
That’s why security leaders are now embracing fourth-party vendor risk management. By actively assessing and monitoring vendor risk beyond third-parties, InfoSec and supply chain teams are gaining crucial insights into their supply chain ecosystem and strengthening operational resilience.
In this guide, you will learn:
- Why fourth-party vendor risk management increasingly matters
- The common examples of fourth-party vendors
- A practical framework for managing fourth-party vendors
- How to assess and monitor changing fourth-party vendor risk
What is fourth-party vendor risk management?
Fourth-party vendor risk management focuses on how you identify, assess, monitor and mitigate supply chain risks that emanate from your suppliers’ suppliers, such as the payment processor your CRM uses or the cloud infrastructure your payroll platform relies on. Fourth-party vendor risk management helps you reduce your exposure to vendor concentration risks and cascading data breaches arising from your fourth-party suppliers and other invisible relationships deeper in the supply chain.
Your relationship with third, fourth and nth parties
Some companies talk about vendors in ordinal numbers, others prefer ‘tiers’. Either way, they both relate to your relationship with the vendor.
- Third-party (Tier 1): your direct contractual supplier
- Fourth-party (Tier 2): your direct supplier's supplier (i.e. sub-contractor, sub-processor, cloud hosting platform etc)
- Nth parties (Tier 3+): your direct suppliers’ suppliers’ suppliers and any layer beyond that (i.e. fifth, sixth, seventh etc)
As it’s not the type of company that defines a fourth-party vendor, but its relationship to other companies in the supply chain (and, ultimately, to the organisation assessing the risk), fourth-party vendors come in many shapes and sizes: they can be obscure, low-spend SaaS tools or giant hyperscalers.
The fundamental criteria of a fourth-party is you don’t have a contractual relationship with them yourself. You have not chosen to enter into a SLA and yet, by choosing to work with a third-party supplier that does have a contract with the vendor, you have inherited their operational and cyber exposure. That’s why fourth-party vendor risk management is so important.

Third-party vs fourth-party risk
Both third-party and fourth-party vendors can severely disrupt your ability to deliver critical services. But the type of risk - and how you manage it - is fundamentally different.
Third-party risk
Third-party risk is direct (i.e. your payroll provider). If there’s an outage or breach, the supplier can no longer provide the service.
As you have chosen to enter into a contractual agreement with a third-party supplier, you can perform due diligence on their security posture before onboarding and assess this periodically. You can state minimum levels of security controls in the contract and demand updates when they make security changes that affect you. Your security team can create a list of all your third-party suppliers, highlight which services they support and assign an individual risk rating. If there’s an incident, your team can coordinate with the supplier directly.
Fourth-party risk
Fourth-party risk is indirect (i.e. your payroll provider’s cloud platform). If there’s an outage or breach, then all connected third-party suppliers are affected, effectively removing their services simultaneously.
As you don’t have a contractual agreement with fourth-party vendors, you are not able to carry out supplier assurance on them. You are unaware of their changing security controls and commercial relationships. Your security team has very limited visibility on fourth-party connections and relies on the third-party supplier to tell you who they are and if an incident occurs (even if the incident is public news, you’re unlikely to know the full level of your exposure).
Why direct-supplier-only TPRM creates blind spots
As the name suggests, traditional third-party risk management (TPRM) focuses on your third-party suppliers. Most organisations focus exclusively on ‘Tier 1’ or direct third-party relationships, ignoring the vast, invisible web of fourth, fifth and nth parties that those suppliers rely on to deliver their services.
But this ignorance is involuntary. Security leaders are increasingly aware of the risks that fourth-party vendors represent, but are often unaware of their own fourth-party vendor connections. That’s because traditional supplier records usually follow contracts, showing who your organisation buys from, but not who those suppliers depend on. Meanwhile, classic TPRM assessment questionnaires enable your security team to gather evidence on individual suppliers, but this narrow focus fails to identify deeper supply chain connections, leaving you blind to fourth-party risk.
Our research found that only 37.2% of UK cyber security professionals consider TPRM "truly effective" in today’s threat landscape with the lack of visibility into dependencies (36.8%) one of the most cited concerns. Other common TPRM issues include:
- Supplier registers built around legal entities rather than business services. Procurement’s internal supplier lists tend to focus on the legal name, contract value and security controls. They might generally state the services the supplier provides, but not the criticality of these services. For example, they do not differentiate between your IAM tech provider failing - resulting in your customers being unable to log-in to use your services - and your employee expenses software going offline.
- Information held across procurement, privacy, resilience and security teams. Traditionally, procurement gathers information on your suppliers, partners, intermediaries and brokers (and any other third party that is not your customer), but this info is not shared or stored centrally for use by privacy, resilience or security teams. These teams each have their own lists, making fourth-party vendor risk difficult to manage without a single source of truth.
- Suppliers changing sub-processors or technology providers between reviews. Most TPRM assessments take place on an annual basis, but your suppliers are not sitting still during that time. They’re growing their business and making new connections, so relying on annual assessments leaves your organisation in total darkness for 364 days of the year unless you're actively tracking and managing their developments. Even if they are contractually obliged to update you, this is often just a link to a webpage announcing its latest sub-processors.
Common examples of fourth-party vendors
As fourth-party vendors supply services to your contracted third-party vendors, almost any organisation can be a fourth-party. They can be low-spend SaaS tools like Calendly, a common payment processor like Stripe or a giant cloud platform like AWS. In fact, our own fourth-party discovery data - looking at critical fourth parties across thousands of live supplier connections - revealed Google, AWS, Microsoft, Salesforce and HubSpot were the most common fourth-party vendors.
What’s more, while many third-party suppliers vary sector by sector, such as third-party Industrial Control Systems (ICS) in manufacturing or emergency responder SaaS in the public sector, fourth-party vendors tend to be sector agnostic. Both the ICS and emergency SaaS app might use the same payroll platform, for instance.
Here’s a breakdown of common fourth-party vendors and their potential impact.
How AI muddies the fourth-party picture
By now, all organisations have adopted some level of AI tooling. In many cases, this is a direct action: from buying a company-wide license for Anthropic to purchasing a clearly AI-powered SaaS tool like UiPath. However, many third-party SaaS tools use the same foundational LLM model to power their applications. If 20 of your apps rely on ChatGPT for its Gen AI functions, you’re now exposed to shocks at OpenAI without a choice.
To make matters worse, AI adoption is not centralised. Your suppliers might add AI tooling two months or two years after you've contracted with them. We’ve also seen engineers within third-party suppliers introducing APIs into fourth-party AI providers without following organisational guidelines, sending your confidential data into an LLM at the fourth party layer without even the third-party supplier knowing, let alone your organisation.
Why fourth-party risk matters
Supply chain risk doesn’t adhere to contractual boundaries. Even if you’re unaware of your connections with the fourth-party vendor, an outage or breach can leave you dealing with the financial, operational, reputational and regulatory consequences.
Here’s why you should take fourth-party risk seriously.
Critical service disruption
A direct supplier may be unable to deliver its service when an underlying hosting, communications or software provider fails.
Your ability to deliver core services relies on an interconnected stack of APIs, cloud providers, and managed services. If the fourth-party vendor suffers an outage that causes your third-party to go offline, this affects your ability to deliver services. If the fourth-party vendor suffers a breach (or one of their nth-party connections does), there is now a digital avenue that attackers could take right to your door. What’s more, the impact magnifies. With a third-party vendor breach, only one service might go offline. With a fourth-party vendor incident, this could be 10 critical suppliers failing at the same time. For example, the 2025 Cloudflare Bot Management outage caused multiple distinct third-party payment platforms and financial apps to go offline, causing simultaneous service disruptions for downstream organisations.
Data and privacy exposure
Fourth-party sub-processors may store, transmit or access data even when the direct supplier remains contractually responsible.
Fourth-party vendors represent a double whammy of data confidentiality risk. On the one hand, a security-assessed third-party vendor might use a non-security-assessed fourth-party vendor to store your sensitive data. If that fourth-party vendor suffers a security incident, your sensitive data is at risk. On the other hand, you’re the one that could still fall foul of regulations for the data breach, such as GDPR, HIPAA and PCI-DSS. For example, in 2018, Ticketmaster was using a third-party customer service provider, Inbenta. When the fourth-party software that Ibenta was using was compromised, this led to the exposure of Ticketmaster’s customers’ payments details and a hefty GDPR fine of £1.25 million.
Privileged access
Technology providers used by MSPs or other operational suppliers may have highly privileged access across several customer environments.
TPRM supplier assurance checks whether third-parties have adequate controls in place in order to use your customer’s data. However, even secure third-parties could be compromised if their fourth-party vendor suffers a breach. This is what happened during the MOVEit Transfer Supply Chain Attack. Zellis, a major payroll provider used by many UK organisations (third-party), used MOVEit Transfer (the fourth-party) to process files. When MOVEit was exploited, attackers were able to exfiltrate employee data from Zellis’ enterprise clients, such as British Airways.
Slower incident response
When an incident affects an indirect provider, security teams need to determine which suppliers use it, which services are affected and who owns each relationship.
When you buy from one vendor, you are implicitly inheriting the risk of an entire ecosystem that you have no direct way to monitor or influence. So when a major global vulnerability hits, organisations spend weeks asking their third parties if they are affected as those third parties, in turn, are asking their fourth parties. This ‘cascading inquiry’ model is too slow to stop an active exploit. Take Log4J, for instance. It was able to flow through 60% of corporate networks in just 72 hours with security teams unable to keep up.
Cascading impact
Cybercriminals actively target weaker links further down the supply chain as a way to infiltrate bigger fish upstream.
Digital connections are like highways for cyber incidents. Whether it’s a targeted attack or accidental breach, a vulnerability at a fourth-party can quickly travel through the supply chain, impacting your direct supplier and, ultimately, your own environment. For example, 1000+ financial organisations, including the likes of JP MorganChase and Morgan Stanley, were affected by the 2025 data breach at financial services provider SitusAMC.
A practical fourth-party risk management framework
Fourth-party vendor risk management is increasingly crucial to your organisation’s operational resilience, but many security teams are unsure how to implement a successful FPRM strategy. We’ve put together this framework based on what's worked (and what hasn't) for Risk Ledger customers.
- Start with critical services. Identify the business services whose disruption, compromise or data loss would cause significant harm to your operations and reputation. For example, a financial services organisation may prioritise retail banking and lending services.
- Identify the direct suppliers supporting them. Connect each important service to the suppliers, systems and internal owners involved. For instance, your Identity and Access Management (IAM) software is essential if customers need to log-in to use your services.
- Collect key dependency information. Ask critical suppliers about relevant sub-contractors, sub-processors, infrastructure providers and technologies. This will help you create a through-line for each critical service highlighting direct and indirect dependencies.
- Add business context. Record what the fourth party supports, what data it handles, what access it has and whether an alternative exists. If possible, try to understand their contractual agreement to determine how easy it may be for the third-party to switch to an alternative provider offering a similar level of service quality.
- Assess the direct supplier’s oversight. Review how the supplier selects, assesses, contracts with and monitors its own providers. This should also include the regularity of assessments and how they’re alerted if there’s an incident.
- Prioritise critical exposure. Apply deeper scrutiny where an indirect provider could affect a critical service, sensitive data or privileged access. You should also look at the operational impact of failure, expected duration of disruption and complexity of switching to an alternative when assessing criticality.
- Set contractual expectations. Make key sub-contractor disclosure, change notification, security requirements, incident communication and flow-down obligations mandatory in the contract. Outline the outcomes (i.e. cancellation of service) if these contractual obligations are not met.
- Monitor relevant change. Review new sub-processors, technology changes, incidents, outages and important changes to critical services. In particular, look for vendor concentration risks and how these changes could affect your critical services.
- Prepare the incident workflow. Create a list of required actions if there’s an incident at a critical fourth party. By linking each fourth-party to its direct suppliers and services, you should be able to create an action plan (i.e. a hot/cold site concept or back-up supplier) that minimises the fourth-party risk.
How far down the supply chain should you look?
By reading this, you’ve already succeeded in the first challenge: moving on from third-party thinking. In today’s connected economy, you need to approach supply chain assurance from a network perspective; you can't just focus on individual companies.
However, modern supply chains are endless and it doesn’t make sense trying to identify, assess and monitor every possible supplier link. Nor is it a good idea to arbitrarily stop at fourth-party coverage. Instead, the tiers and vendors you manage all boil down to criticality. This could be in relation to your business operations or the sensitivity of data handled, but understanding which third-parties are critical will help you work out which fourth-parties (and potentially nth parties) are critical too.
To determine supplier criticality, consider the following checklist.
Fourth-party risk assessment: what should teams evaluate?
As fourth-party vendor risk assessments are a resilience issue, the main evaluation criteria revolves around what would happen if there was an incident at the fourth-party vendor. To better understand your level of exposure and create action plans to mitigate the risk, first consider the following elements.
By focusing on these eight areas, you will be able to determine the level of risk of each critical fourth-party and also gain insights into how to reduce that risk. For instance, if the fourth-party vendor is easily replaceable with an alternative, you may suggest your third-party supplier enters an agreement with a back-up in case the fourth-party fails (or you could enter an agreement with a back-up in case the third-party fails).
What should fourth-party monitoring include?
After establishing your critical fourth-party vendors, you then need to monitor them continuously. Many organisations outsource this monitoring to their third-party suppliers through security questionnaires or contractual obligations. But given the level of potential disruption, you shouldn’t rely on third-parties to provide regular monitoring updates.
Instead, set up your own fourth-party monitoring system. This should track and provide alerts to key changes that impact risk levels, so you can get ahead of potential incidents.
In particular, fourth-party monitoring should track changes to:
Remember: monitoring alone is only half of the battle. Every risk signal should lead to tangible actions and outcomes, such as a review, escalation, remediation, acceptance or incident response.

Regulatory considerations around fourth-party vendors
You can outsource tech, but you cannot outsource regulatory responsibility.
Current security and resilience regulations want to see that you understand the weaknesses in your supply chain, can identify your critical third parties, and have a plan in place if these third-parties are attacked. Meanwhile, data protection regulations vary depending on where the supplier is based, where you are based, where the data is coming from, and the geographic location of the people whose data you're collecting.
While most regulations do not make fourth-party vendor risk management obligatory (yet), this is the clear direction of travel with some regulators recently updating guidance on the risks posed by fourth-party suppliers.
Here are some key regulations to be aware of in relation to fourth-parties.
- 2026 updates to PRA SS2/21 specifically calls out vendor concentration risks and “fourth party/supply chain dependencies” with expectations that financial services companies periodically assess and take reasonable steps to manage dependencies “where multiple otherwise unconnected service providers depend on the same sub-contractor for the delivery of their services.”
- The EU’s DORA demands financial entities assess digital supply chain risks, especially around their “indirect reliance on ICT subcontractors”. In particular, financial entities should focus on “subcontractors that provide ICT services that support critical or important functions.”
- The UK’s Cyber Security and Resilience (Network and Information Systems) Bill expands the scope of the NIS2 regime to specific third–parties, including 1000+ Managed Service Providers and data centres (who are often critical fourth-parties). The bill also enables regulators to identify ‘designated critical suppliers’ that they deem a concentration risk and toughens reporting requirements for supply chain cyber incidents.
- While not calling out fourth parties specifically, the NCSC’s Cyber Assessment Framework (CAF) Principle A4 calls for “a deep understanding of your supply chain, including sub-contractors,” Meanwhile, the Government Cyber Security Strategy (GCSS) demands “improved understanding of suppliers and their dependencies” and the “mapping of government’s critical and common suppliers.”
What to look for in fourth-party risk management software
There’s a reason why regulators have started making inroads into fourth-party vendor risk management: in interconnected supply chains, every supplier matters.
Organisations need fourth-party risk management software to help them identify their fourth parties, determine whether a fourth-party connection supports a critical business service and track relevant changes at the fourth-party vendor that impacts downstream risk.
That’s why, as a bare minimum, fourth-party risk management software should include:
- Visibility of fourth-parties. Instead of static supplier lists, the software should provide the full picture of your fourth-party vendors in real-time (i.e. every time a third-party vendor makes a new connection) and map these to your critical business services.
- Continuous monitoring of changes. Instead of waiting for updates from third-party vendors, the software should monitor changes to fourth-party vendor risk, send alerts of emerging threats, enable your SOC to simulate the blast radius of potential incidents, and provide accurate information during live incidents (i.e. what's going on, what your exposure is to it and how long it's going to take to remediate).
- Means to collaborate with suppliers. Instead of scrabbling to get your third-party suppliers on the phone, the software should provide a means for you and your suppliers to communicate and coordinate directly without looking up a phone number or relying on email.
In addition, look out for these other core capabilities.
How Risk Ledger supports fourth-party risk management
At Risk Ledger, our platform provides organisations with a live network view of their entire supplier ecosystem. Our supply chain mapping, continuous monitoring, nth-party visibility and direct supplier collaboration are essential for managing fourth-party risk.
By joining Risk Ledger, you get access to:
- Supplier-maintained evidence. Our 16,000+ suppliers create and maintain a standardised and peer-reviewed security profile, highlighting all their security controls and posture, with questions linked to key standards like Cyber Essentials and ISO27001.
- Standardised assurance data. All suppliers answer a common security assessment based on key regulations and standards, creating a common language of risk for the entire ecosystem.
- Relationship visibility. See how your diverse third-party vendors connect to the wider ecosystem with a real-time map showing third, fourth and nth-party relationships.
- Nth-party dependency insights. By showing all your third, fourth and nth-party relationships on one map, you can see hidden dependencies, identify single points of failure and better understand how supplier disruptions cascade through the ecosystem.
- Shared provider and concentration analysis. With a bird's-eye view of your entire network’s changing concentration risks, you can make risk-based decisions and take premeditated action to mitigate disruptions.
- Emerging threat investigation. With real-time risk signals, intuitive dashboards and simulated disruptions, you can assess the impact of emerging threats, create solid response playbooks and make informed choices around supplier diversification.
- More direct communication across connected organisations. Your security team has a direct two-way channel to communicate with third parties and fourth-party vendors. Every supplier can communicate directly over the platform regarding a specific control, fourth-party connection or incident without losing context via email back and forth.

Spotlight: NHS Test and Trace
The COVID Test and Trace team had two different suppliers providing a critical chemical reagent required for the UK government to run its testing. They purposely chose two separate suppliers so that if one had an incident or went bust, they could default to the second.
However, through our platform's mapping function, we were able to show them that both of those third-party suppliers actually relied on the exact same fourth-party supplier underneath them.All they had done was inadvertently push their bottleneck one layer further down the supply chain.
We identified that concentration risk and helped them decouple those supply chains so that each third party used a completely different fourth party.
Risk Ledger results: fourth-party vendor risk management
Fourth-Party Vendor Risk Management FAQs
What is fourth-party vendor risk management?
Fourth-party vendor risk management focuses on how you identify, assess, monitor and mitigate supply chain risks that emanate from your suppliers’ suppliers, such as the payment processor your CRM uses or the cloud infrastructure your payroll platform relies on. Fourth-party vendor risk management helps you reduce your exposure to vendor concentration risks and cascading data breaches arising from your fourth-party suppliers and other invisible relationships deeper in the supply chain.
What is the difference between third-party and fourth-party risk?
Third-party risk is direct. If there’s an outage or breach, the supplier can no longer provide the service. As you have a contractual agreement with a third-party supplier, you can perform direct due diligence on their security posture before onboarding and assess this periodically.
Fourth-party risk is indirect. If there’s an outage or breach, then all connected third-party suppliers are affected, effectively removing their services simultaneously. As you don’t have a contractual agreement, you rely on the third-party supplier to tell you who they are and if an incident occurs.
What are common examples of fourth-party vendors?
As fourth-party vendors supply services to your contracted third-party vendors, almost any organisation can be a fourth-party. They can be low-spend SaaS tools like Calendly, a common payment processor like Stripe or a giant cloud platform like AWS. In fact, our own fourth-party discovery data - looking at critical fourth parties across thousands of live supplier connections - revealed Google, AWS, Microsoft, Salesforce and HubSpot were the most common fourth-party vendors.
Do organisations need to assess every fourth party?
No. Supply chains are endless and it doesn’t make sense trying to identify, assess and monitor every possible supplier link. Nor is it a good idea to arbitrarily stop at fourth-party coverage. Instead, it all boils down to criticality. This could be in relation to your business operations or the sensitivity of data handled, but understanding which third-parties are critical will help you work out which fourth-parties (and potentially nth parties) are critical too.
How can security teams identify and manage fourth-party risk?
To identify critical fourth-party risk, look at its service dependency, the potential business impact of disruption, the level of data/access it has, and the ability to switch to alternatives if there’s an incident. To manage the risk, assess the direct supplier’s oversight, consider updating contractual expectations, monitor relevant changes continuously and prepare incident workflows. Consider using specific fourth-party vendor risk management software to assist you.



