concept

Fourth Party Risk

The dependencies of your dependencies, which you did not choose, may not know about, and remain accountable for.

Third-party risk management assesses the vendors an organisation contracts with. Those vendors have their own vendors, and the chain continues. A payment provider depends on a cloud region; a SaaS tool depends on an authentication provider; a monitoring service depends on a content delivery network.

Concentration hides in that chain. Four suppliers that appear independent may all depend on the same infrastructure provider, in the same region, so a single failure takes out what looked like a diversified set. This has happened repeatedly and each time the surprise was genuine, because nobody had mapped the second layer.

The obligations do not stop at the first tier. Personal data processed by a sub-processor is still the controller's responsibility, and a regulator asking where data is processed expects the full chain rather than the immediate contract.

What is achievable, given that full visibility is not: require disclosure of material sub-processors and notice of changes in contracts; map the critical dependencies of critical suppliers even approximately, since even a partial map finds the shared points; and test the scenario rather than the vendor — the question that matters is what the business does when a supplier is unavailable, and that answer does not require knowing why.