Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

Fourth-Party Risk KRIs: Monitoring Concentration You Do Not Directly Control

You have no contract with fourth parties—but you inherit their failures. Here are the KRIs that surface cloud concentration, shared subcontractors, and upstream dependency risk before it becomes your incident.

By Rebecca Leung · May 27, 2026 ·
Table of Contents

TL;DR

  • Fourth-party risk—your vendor’s subcontractors—can’t be contracted away, but it can be measured and monitored through KRIs.
  • The Change Healthcare ransomware attack (February 2024) affected up to 190 million Americans and cost UnitedHealth $2.8 billion because an entire industry had concentrated its claims processing through one clearinghouse.
  • OCC Bulletin 2023-17 doesn’t require you to assess every fourth party directly—but it does require you to evaluate whether your critical vendors are managing their subcontractors competently.
  • Key fourth-party KRIs: subcontractor disclosure completion rate, hyperscale cloud concentration ratio, SOC report carve-out count, fourth-party incident notification lag, and contract visibility gap percentage.
  • DORA designated 19 Critical ICT Third-Party Providers (CTPPs) in 2025, with direct oversight of AWS, Azure, and Google Cloud implications for any financial entity with EU operations.

You have no contract with a fourth party. You never approved them. They don’t know your name. But when their infrastructure goes down at 2 a.m., your critical vendor’s SLA clock starts ticking—and so does yours.

The Change Healthcare ransomware attack, which hit on February 22, 2024, affected up to 190 million Americans and produced $2.8 billion in direct costs for UnitedHealth Group. What made it a systemic event rather than a single-institution incident was concentration: Change Healthcare processed approximately one-third of U.S. healthcare transactions. When one node failed, an entire sector found out how dependent it had become on a single clearinghouse it had never formally risk-assessed.

If your TPRM program ends at the contract level, you’re monitoring the vendors you see while the real concentration risk sits one layer behind them.

Why Fourth-Party Risk Is Hard to Measure

The core problem is visibility. You can send a vendor questionnaire to your core processor. You can review their SOC 2. You can conduct an annual due diligence review and call it done. But your core processor’s infrastructure may run on a hyperscale cloud provider you’ve never formally assessed, use a payment rail operator with no contractual relationship to you, and rely on a KYC subprocessor whose security controls you’ve never seen.

Traditional third-party risk programs measure what’s visible: questionnaire completion rates, SOC exceptions, incident notifications. Critical vendor KRI monitoring covers performance against SLAs and identified findings. But fourth-party risk requires a different posture—measuring the structure of the risk rather than the symptoms.

The June 2023 interagency guidance (OCC Bulletin 2023-17) explicitly addressed this. Responding to commenters who worried about infinite regress, the agencies clarified that banking organizations are not expected to assess every subcontractor directly. The focus is on evaluating whether your critical vendors have their own processes for managing subcontractor risk—and applying more scrutiny where concentration and criticality are high.

That’s the framing for fourth-party KRIs: you’re not auditing every fourth party. You’re measuring whether you know what concentration you have, whether your vendors are managing it, and whether you’d know before it became an incident.

The KRI Categories That Matter

Fourth-party risk KRIs fall into four practical categories: concentration exposure, structural visibility, incident propagation, and contract access.

Concentration Exposure KRIs

Hyperscale cloud concentration ratio. For your critical and high-risk vendors, what percentage rely on the same cloud provider (AWS, Azure, or GCP) for hosting their primary systems? A concentration ratio above 60–70% in a single provider means that provider’s availability is effectively a systemic dependency for your operations, even without a direct contract. DORA’s designation of 19 Critical ICT Third-Party Providers—with AWS, Azure, and Google Cloud widely expected among the named CTPPs—reflects exactly this concern. All three hyperscale providers experienced major global outages in 2025: AWS US-EAST-1 in October, Google Cloud’s authentication system in June, and Azure in both October and December.

ThresholdStatusAction
<40% critical vendors on single providerGreenMaintain monitoring
40–60% critical vendors on single providerAmberRequire vendor disclosure of fallback
>60% critical vendors on single providerRedEscalate to board; require exit plan verification

Common subcontractor overlap count. How many of your critical vendors share the same material subcontractors outside of major cloud providers? A shared KYC provider, a shared payment rail, or a shared clearinghouse represents concentration risk that compounds across your vendor relationships. Tracking this number—even at a high level—quantifies your exposure to fourth-party cascade events.

Critical path fourth-party count. For each of your top-five critical services (payments processing, core banking, identity verification, regulatory reporting, customer communication), how many distinct fourth parties sit in the service delivery chain? A single critical function running through six fourth parties is a more complex risk profile than three critical functions each with one known subcontractor.

Structural Visibility KRIs

Subcontractor disclosure completion rate. Of your critical and high-risk vendors, what percentage have provided a list of material subcontractors touching your data, your customers, or your critical operations? This is the foundational metric. Without it, all downstream fourth-party KRIs are estimates.

Target: 100% of critical-tier vendors; 80%+ of high-risk vendors within 12 months of onboarding.

SOC report subservice organization (carve-out) count. When you review your vendors’ SOC 2 reports, how many subservice organizations are carved out—meaning the SOC 2 explicitly does not cover their controls? Each carve-out is a control gap you’re expected to address. Tracking carve-out counts across your vendor population shows whether your upstream oversight is contracting away assurance or maintaining it. A rising carve-out count is a governance KRI, not just a vendor-specific finding.

Vendor subcontractor management maturity score. When you ask critical vendors about their subcontractor oversight—do they have a vendor inventory for their own third parties? An annual review cadence? Notification obligations flowing down to subcontractors?—you can score their responses. A simple 1–5 maturity rating for your top vendors makes the population manageable and tracks changes over time.

Incident Propagation KRIs

Fourth-party-originated incident rate. Of all vendor incidents in the reporting period, what percentage originated in a subcontractor rather than the vendor itself? This KRI answers whether your vendor management is catching incidents at the right level. A rising fourth-party origin rate with low vendor incident rates suggests the vendor is not surfacing subcontractor problems until they’ve already affected your service. Third-party incident KRI monitoring covers the broader incident tracking framework; fourth-party origin tagging extends that to the subcontractor level.

Notification lag for fourth-party events. When a critical vendor’s subcontractor has a significant incident, how long does it take before you receive formal notification from the vendor? Contracts typically require 4–24 hours for initial notification. If you’re regularly finding out from customers before hearing from vendors, that’s a structural failure—the vendor either doesn’t know about their subcontractor’s problem in time, or doesn’t escalate it to you promptly.

Post-incident root cause attribution rate. Of significant vendor incidents, what percentage include a root cause disclosure identifying whether the incident originated with the vendor or a subcontractor? Vendors that consistently report “internal system issue” without specifying whether the root cause was a cloud provider, a subprocessor, or their own infrastructure are obscuring the fourth-party exposure your program needs to track.

Contract Access KRIs

Vendor contract flow-down coverage rate. What percentage of your critical vendor contracts include explicit requirements for the vendor to (1) notify you of material subcontractor changes, (2) flow down data security and privacy obligations to subcontractors, and (3) extend audit rights or SOC 2 coverage to subcontractors touching your data? Contracts signed before 2023 interagency guidance may lack these provisions. Tracking coverage and targeting renegotiation at renewal cycles is a governance KRI with a practical remediation path.

Subcontractor change notification response time. When vendors notify you that they’re adding, changing, or terminating a material subcontractor, how long does your internal review take? If the answer is “we don’t have a formal review process for that,” the KRI value is infinite—and the notification requirement in your contract is a paper obligation that your operational process doesn’t support.

How to Build These KRIs Without Boiling the Ocean

The common objection to fourth-party KRIs is scope: “We have 200 vendors. We can’t track all their subcontractors.” That’s the wrong starting point. Fourth-party risk programs are scoped to critical and high-risk vendors—typically the top 10–20% by criticality tier. That’s likely 20–40 vendors, not 200.

For those vendors:

  1. Send a structured disclosure request. Ask for a list of material subcontractors touching your data or critical operations. “Material” means subcontractors whose failure would affect the services you’re purchasing. Not their office supplies vendor. Document which vendors respond, what they disclose, and any they flag as confidential (which is itself a data point).

  2. Review SOC 2 subservice organization listings. Every SOC 2 Type 2 report that uses the carve-out method lists subservice organizations explicitly. Compile these listings for your critical vendors. Look for shared names—the same AWS environment, the same Twilio SMS provider, the same identity verification service appearing across multiple vendors is a concentration signal.

  3. Add subcontractor change notification to your contract template. At the next renewal for each critical vendor, add a clause requiring 30-day advance notice of material subcontractor changes with your right to object. This is now standard language in post-OCC-2023-17 TPRM programs.

  4. Track incidents by origin. When you log vendor incidents, add a field for “incident origin”—vendor, fourth-party subcontractor, or unknown. After two or three quarters, the distribution tells you whether your vendor incident reporting is capturing subcontractor exposure.

So What?

The fourth-party risk problem isn’t that your vendors use subcontractors—it’s that you don’t know which ones matter until they fail. Change Healthcare processed a third of U.S. healthcare transactions before anyone formally assessed what would happen if it went down. DORA’s designation of 19 Critical ICT Third-Party Providers is regulators saying explicitly: the hyperscale cloud concentration risk is real, visible, and now subject to direct oversight.

Your fourth-party KRI program doesn’t have to be complex to be defensible. Subcontractor disclosure completion rate and hyperscale cloud concentration ratio are numbers your TPRM program can track today, with the vendor data you can request in the next review cycle. They give you the data to make informed decisions about dependency, give your board a meaningful picture of concentration exposure, and give an examiner something more substantive than “we rely on our vendors to manage their subcontractors.”

The Third-Party Risk Management (TPRM) Kit includes a vendor inventory and concentration tracking template that extends to fourth-party disclosure tracking—so you’re not building the data structure from scratch. Get it at buy.stripe.com/14A14g8Bd01dazP4mO6J204.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are fourth-party risk KRIs?
Fourth-party risk KRIs are metrics that track your exposure to your vendors' subcontractors and upstream dependencies—providers you have no direct contract with but whose failures cascade into your operations. They include concentration ratios (how much of a critical service chain runs through a single subcontractor), SOC report carve-out counts (subservice organizations explicitly excluded from your vendor's SOC scope), fourth-party incident notification lag (how long before a vendor tells you their subcontractor had a problem), and contract visibility gaps (critical vendors that can't or won't disclose their material subcontractors).
Do I have to monitor every fourth party?
No. The June 2023 interagency guidance (OCC Bulletin 2023-17) explicitly clarified that banking organizations are not expected to assess or oversee all subcontractors directly. The expectation is that you evaluate your critical and high-risk vendors' processes for overseeing their subcontractors, with deeper scrutiny where subcontractor risk is elevated. Focus fourth-party KRIs on your top-tier vendors—typically your highest-criticality 10–20%.
What's the difference between fourth-party risk and cloud concentration risk?
Cloud concentration risk is a specific form of fourth-party risk where multiple vendors share the same hyperscale cloud provider (AWS, Azure, or GCP) as a common subcontractor. Change Healthcare—processed on AWS—is the defining example: when it went down in February 2024, the failure propagated not because of a cloud outage but because so many healthcare workflows had a single clearinghouse as a common dependency. You can have fourth-party risk without cloud concentration, and cloud concentration risk without traditional fourth-party risk—but they often appear together.
How does DORA change fourth-party risk monitoring requirements?
DORA (Digital Operational Resilience Act, enforceable since January 2025) designated 19 Critical ICT Third-Party Providers (CTPPs) subject to direct regulatory oversight—including major hyperscale cloud providers. Financial entities with material reliance on CTPPs must document concentration risk, maintain exit plans tested at least annually, and participate in JOC-led oversight exercises. For US institutions with EU operations or EU-regulated counterparties, DORA effectively raised the bar on fourth-party concentration monitoring, even where US regulators haven't yet matched that specificity.
What KRI should I start with if I've never tracked fourth-party risk before?
Start with a subcontractor disclosure completion rate: for each of your critical and high-risk vendors, what percentage have provided a list of material subcontractors touching your data or operations? That's the foundational data layer everything else runs on. Without it, you don't know what fourth-party concentration you have—and you can't set thresholds on what you can't see.
What should I do when a fourth-party KRI goes red?
A red fourth-party KRI—say, concentration in a single cloud provider above your threshold—doesn't necessarily mean exit the vendor. It means the risk needs to be named, owned, and managed. Typical responses include: requiring your vendor to provide a concentration risk disclosure and remediation plan, tightening incident notification SLAs in the next contract cycle, verifying the vendor has a tested fallback or continuity option, or formally risk-accepting the concentration with board-level visibility. Unacknowledged concentration is the real risk; named and owned is a manageable risk.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.