Insights on Crypto Payments, Infrastructure, and Operations

Fourth-Party Risk

Pronunciation: FAWRTH PAHR-tee RISK

Definition

Fourth-party risk is exposure created by the subcontractors, infrastructure providers, or other dependencies used by an organization's direct third parties. A score for Fourth-Party Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions. Fourth-Party Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner.

Overview

Fourth-party risk arises when a vendor relies on another provider to deliver a service, process data, host systems, secure keys, or maintain operations. The customer may have no direct contract or visibility into that downstream dependency.

Several direct vendors may share the same cloud, identity, software, data, or payment provider, creating hidden concentration. A fourth-party incident can therefore affect many services simultaneously even when direct suppliers appear diversified.

Organizations should require material subcontractor disclosure, map critical dependencies, assess contractual flow-down controls, monitor concentration, and define notification and exit rights. Due diligence should focus on services whose failure would materially affect security, compliance, resilience, or customer obligations.

Fourth-party risk is exposure created by the subcontractors, infrastructure providers, or other dependencies used by an organization’s direct third parties. Direct vendor diversification may be misleading when those vendors depend on the same critical fourth-party infrastructure or service.

For Fourth-Party Risk, the assessment should evaluate exposure created by the subcontractors, infrastructure providers, or other dependencies used by an organization’s direct third parties. The assessment record should separate observed evidence supporting exposure created by the subcontractors, infrastructure providers, or other dependencies used by an organization’s direct third parties from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in exposure created by the subcontractors, infrastructure providers, or other dependencies used by an organization’s direct third parties have changed enough to require a new rating, treatment, or approval.

Decision-makers should use findings about exposure created by the subcontractors, infrastructure providers, or other dependencies used by an organization’s direct third parties to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.

Key Takeaway

Direct vendor diversification may be misleading when those vendors depend on the same critical fourth-party infrastructure or service.

Sources

  1. NIST Documentation: Cyberframework — NIST (2026-07-30)
  2. FATF Documentation: Virtual Assets — FATF (2026-07-30)