Terminology Index

Glossary

1801 terms

Open concept maps

Showing 673-704 of 1801 terms

F
32

Fourth Party Risk

Risk arising from the vendors of your vendors, the subcontractors and service providers your third parties depend on, which can affect you even though you have no direct relationship with them.

When you rely on a vendor (a third party), that vendor often relies on its own providers (fourth parties), and a failure or breach at one of them can cascade up to you. Fourth-party risk is this indirect exposure, harder to see and govern because you have no direct contract with the fourth party. Managing it means understanding your vendors' critical dependencies and ensuring they manage their own supply chain, extending third-party risk management one layer deeper.

Introduced in: Risk Management Fundamentals

Examples

  • A breach at your vendor's cloud provider affecting your data.
  • An outage at a subcontractor your key vendor depends on disrupting your service.
  • Mapping a vendor's critical dependencies to understand fourth-party exposure.

No related terms linked yet.