FAQ
Fourth-Party Risk

What is a fourth-party dependency?

A fourth-party dependency is a provider, platform or technology used by one of an organisation’s direct third parties to deliver its service. The organisation may have no direct contract with the fourth party, yet an outage or compromise can still affect critical operations. Examples include a supplier’s cloud provider, payment processor or embedded software service. Supply Chain Intelligence maps observable indirect relationships and helps identify fourth parties that are shared across several suppliers or close to critical systems. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert. The strongest implementation combines external intelligence with internal knowledge, supplier engagement and documented risk decisions, creating a view that remains useful as the digital ecosystem changes.