Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

Nth-Party Risk in TPRM: Mapping the Subcontracting Chain OCC 2023-17 Expects You to Understand

26% of financial institutions don't assess fourth-party risk at all. OCC 2023-17 made subcontracting oversight explicit. Here's how to map your vendor chain, what contract provisions you need, and what examiners expect to see.

By Rebecca Leung · June 12, 2026 ·
Table of Contents

On July 19, 2024, a faulty CrowdStrike content update crashed 8.5 million Windows systems in four hours. Banks, payment processors, and financial market infrastructure were among the affected organizations worldwide — and many of their IT vendors were too. The banks that experienced the most significant disruption weren’t CrowdStrike customers. They were customers of vendors that were CrowdStrike customers.

That’s nth-party risk. And according to the 2026 State of TPRM Survey, 26% of financial institutions still don’t assess fourth-party risk at all.

OCC 2023-17 — the interagency third-party risk guidance issued jointly by the OCC, Federal Reserve, and FDIC in June 2023 — made the obligation explicit. Financial institutions are expected to understand their critical vendors’ subcontracting relationships, build appropriate oversight provisions into contracts, and demonstrate to examiners that they have visibility into the chain, not just the link directly in front of them.

TL;DR

  • 26% of financial institutions don’t assess fourth-party risk; 27% don’t assess or monitor it after the initial review (2026 State of TPRM Survey)
  • OCC 2023-17 requires evaluation of third-party subcontracting oversight processes for critical activities — this is now an exam finding area
  • AWS, Azure, and GCP host approximately 62% of cloud infrastructure globally, creating structural concentration across vendor chains regardless of which vendors you’ve selected
  • Four practical tools to map your chain: contract disclosure requirements, SOC 2 subservice org review, vendor questionnaire subcontracting section, and concentration mapping
  • DORA Article 30 requires sub-outsourcing chain provisions for critical ICT functions — affecting US FIs with EU operations

What Nth-Party Risk Actually Means

The terminology gets loose in practice, so the definitions matter:

Party LevelDefinitionExample
First partyYour institutionThe bank
Second partyYour customers and counterpartiesDepositors, borrowers
Third partyYour direct vendors and service providersCore banking system provider, cloud hosting vendor
Fourth partyYour third party’s subcontractorsThe data center your core banking vendor uses; the cloud provider under your SaaS vendor
Fifth party (and beyond)Subcontractors of subcontractorsThe CDN provider your vendor’s cloud host uses

In practice, “nth-party risk” is commonly used to refer to fourth-party and beyond. “Nth” signals that the chain doesn’t stop at four — for complex technology vendors, the actual subcontracting depth can reach eight or ten layers before you hit hardware.

The risk profile changes at each layer. Your direct vendor (third party) is subject to your contract terms, your due diligence requirements, and your exit provisions. Your vendor’s subcontractor (fourth party) is subject only to whatever your vendor has negotiated with them — and to whatever requirements you’ve contractually obligated your vendor to flow down. Without explicit flow-down provisions, your vendor may have subcontracted a critical function to an entity that has no awareness you exist and no obligation to your regulatory requirements.

What OCC 2023-17 Actually Requires

The OCC’s interagency guidance on third-party risk management — issued jointly with the Federal Reserve and FDIC in June 2023 and replacing the OCC’s 2013 guidance — addresses subcontracting in the Planning, Due Diligence, and Contract Negotiation sections.

In the Due Diligence phase, the guidance expects institutions to “assess the third party’s use of subcontractors, especially for critical activities, including the subcontractors’ locations and whether foreign-based third parties or subcontractors present unique risks.” That means your vendor questionnaire for critical vendors should explicitly address: who their critical subcontractors are, where those subcontractors are located, and how your vendor oversees them.

In the Contract Negotiation phase, the guidance identifies specific contract provisions that should address subcontracting:

  • The third party’s obligation to notify the institution before making material changes to subcontracting arrangements
  • The institution’s right to approve material subcontracting changes for critical activities (or at minimum, to receive advance notice)
  • Flow-down of regulatory compliance obligations to subcontractors where applicable
  • Audit rights that extend to subcontractors for critical activities

For Ongoing Monitoring, the guidance expects institutions to “monitor whether third parties are using subcontractors as expected and whether those subcontractors continue to meet performance and risk standards.” This means annual subcontractor disclosure isn’t a one-time due diligence item — it’s a continuous monitoring requirement for critical vendors.

The examination consequence is straightforward: examiners reviewing your TPRM program for critical vendors will ask whether you know who the critical subcontractors are and whether your contracts include the provisions above. An inability to answer is a finding.

Why Cloud Concentration Makes This Structural

Here’s the challenge that makes nth-party risk hard to manage through contract provisions alone: many of the most significant fourth-party concentrations aren’t the result of poor vendor management. They’re structural features of the modern technology landscape.

AWS, Microsoft Azure, and Google Cloud provide approximately 62% of global cloud infrastructure. That means two vendors you selected independently — say, your core banking SaaS provider and your fraud analytics vendor — may both be running on AWS. Your cloud concentration risk from those two vendors exists at a fourth-party level you didn’t create and can’t fully contract away.

Other structural concentration points in financial services:

  • Telecom infrastructure: A significant share of financial institution voice and data circuits routes through AT&T, Verizon, or Lumen at some layer of the stack. The January 2024 AT&T outage demonstrated this when multiple banks reported transaction processing delays from vendors who didn’t appear on the AT&T customer list but whose hosting providers did.
  • DNS and CDN providers: Cloudflare, Akamai, and Fastly concentrate web routing and content delivery for large portions of the internet. An outage at any of them — like the Fastly outage in June 2021 that took down major news sites and payment portals — can cascade through vendor chains.
  • Identity and authentication providers: Okta, Azure AD, and a handful of other identity providers authenticate users for a large share of enterprise SaaS applications. An Okta security breach, like the one in October 2023, doesn’t just affect Okta customers — it affects every vendor that uses Okta to authenticate its users.

The regulatory expectation isn’t that you eliminate these concentrations — you can’t. It’s that you understand them, document them, and have considered the recovery implications in your contingency planning.

Four Practical Tools for Chain Mapping

1. Annual Subcontractor Disclosure Requirements

For critical and high-risk vendors, add an explicit contract provision requiring annual disclosure of material subcontractors — defined as any subcontractor that performs functions material to the service the vendor provides to you. The provision should require:

  • Annual disclosure of the subcontractor name, location, and function
  • Advance notice (30 to 60 days) before adding new material subcontractors
  • Prior written approval (or a right to object) for changes to subcontractors handling critical functions

This converts subcontractor visibility from a goodwill exercise into a contractual right. Vendors that push back on annual disclosure requirements for critical functions deserve scrutiny — the resistance itself is an information signal about their subcontracting practices.

For existing contracts that lack these provisions, include them in the next renewal cycle. For contracts that are mid-term and cover critical activities, consider whether the gap is significant enough to warrant a contract amendment.

2. SOC 2 Subservice Organization Review

Every SOC 2 Type II report identifies the scope of what was tested and, critically, what was excluded through the “subservice organization” or “carved-out” scope limitation. When a vendor uses a subservice organization (a subcontractor that performs functions included in the service scope), the SOC 2 either includes that subservice organization in the scope (inclusive method) or excludes it and notes it as carved out.

When reviewing a vendor’s SOC 2 report, look specifically at:

  • Section 1 or Section 2: Description of subservice organizations and how they’re handled in the scope
  • Complementary Subservice Organization Controls (CSOCs): Controls the vendor assumes subservice organizations are performing — which you should verify with those organizations’ own reports
  • Bridging letters: For major subservice organizations (AWS, Azure, Azure AD), request or locate the subservice organization’s own SOC 2 to verify the controls assumed in your vendor’s report are actually in place

A vendor whose entire infrastructure runs on AWS but whose SOC 2 carves AWS out and lists 40 CSOCs is relying entirely on AWS controls without testing them. That gap in assurance coverage is a fourth-party risk finding.

3. Vendor Questionnaire Subcontracting Section

Add a dedicated subcontracting section to your standard vendor risk questionnaire. For critical and high-risk vendors, the section should ask:

  • List all material subcontractors (those performing functions material to the service provided)
  • For each, provide: name, location, function, contract term, and whether they are included in your most recent SOC 2 scope
  • Describe your process for overseeing subcontractor performance and compliance
  • Describe your change management process when adding or replacing material subcontractors
  • Have any material subcontractors experienced a security incident, regulatory action, or business continuity event in the past 24 months?

The last question surfaces incidents that may not have reached you through normal channels — a fourth-party breach that your vendor responded to but didn’t disclose because there was no contractual obligation to do so.

4. Concentration Mapping

Build a simple matrix that plots your critical and high-risk vendors against their primary infrastructure providers. The columns represent the key fourth-party providers (AWS, Azure, GCP, major telecom carriers, identity providers). The rows represent your critical vendors. A check mark where they intersect shows you where concentration exists.

The output isn’t a list of problems to solve. It’s a documented understanding of your fourth-party landscape that you can present to examiners, incorporate into business continuity scenarios, and use to inform your fourth-party KRI monitoring framework. Examiners don’t expect zero concentration — they expect evidence that you understand it and have considered the recovery implications.

DORA’s Sub-Outsourcing Chain Requirements

For US financial institutions with EU operations, DORA added regulatory teeth to nth-party risk requirements that took effect January 17, 2025. Article 30 of DORA — which governs key contractual provisions for ICT third-party service arrangements — requires that contracts for critical and important functions include:

  • Explicit provisions governing sub-outsourcing of the ICT service, including the conditions under which sub-outsourcing is permitted
  • A list of current subcontractors involved in the ICT service
  • Obligations for the ICT provider to notify the institution before making material changes to the subcontracting chain
  • The financial institution’s right to object to or terminate if material subcontracting changes are made without notification

DORA’s ICT contract requirements also require institutions to maintain an information register of all ICT third-party service arrangements — which effectively requires mapping the sub-outsourcing chain for all critical functions, not just the ones you select to review.

For US banks that treated DORA as someone else’s problem, the sub-outsourcing chain documentation requirements are worth noting even outside the EU compliance context. The FFIEC’s interagency guidance and DORA’s Article 30 are converging on the same expectation: know your vendor’s subcontractors for critical functions, build it into your contracts, and document it.

What Examiners Are Asking

Based on the current examination climate, these are the five questions your TPRM program should be able to answer before an examiner asks them:

  1. “For your top ten critical vendors, who are their material subcontractors?” — If you can’t answer this, you have a gap in your ongoing monitoring program.

  2. “Do your critical vendor contracts require advance notice before material subcontracting changes?” — Pull the relevant contract sections and be able to cite the provision number.

  3. “Have you identified any cloud infrastructure concentration across your critical vendor portfolio?” — The answer isn’t “no.” It’s “yes, and here’s what we documented.”

  4. “When did you last review your critical vendors’ SOC 2 subservice organization disclosures?” — The answer should be “in the last 12 months,” with documentation.

  5. “If your largest critical vendor’s primary cloud infrastructure provider experienced an extended outage, which of your critical functions would be affected, and what’s your recovery plan?” — This is the Business Continuity question that flows directly from nth-party concentration mapping.

So What?

Most TPRM programs are built to manage the vendor in front of them. The exam standard — and the CrowdStrike, Synapse, and AT&T pattern from the last two years — is that the failures you don’t see coming are the ones routed through a subcontractor your vendor never disclosed.

Closing that gap doesn’t require a new platform or a comprehensive re-underwriting of every vendor. It requires four practical additions to your existing program: annual subcontractor disclosure requirements in critical vendor contracts, SOC 2 subservice org review as part of your due diligence process, a subcontracting section in your questionnaire, and a one-page concentration map for your critical vendor portfolio.

The Third-Party Risk Management (TPRM) Kit includes vendor contract checklists, questionnaire templates with a subcontracting section, and the due diligence documentation framework that maps to OCC 2023-17’s expectations — built to answer the five examiner questions above before they’re asked.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is nth-party risk in TPRM?
Nth-party risk refers to the risk exposure that flows from your vendors' vendors — and their vendors' vendors — through the subcontracting chain. A fourth party is a subcontractor of your direct vendor (your third party). A fifth party is a subcontractor of that subcontractor. The risk is material because a failure at any point in the chain can disrupt the service your vendor provides to you, and you may have no direct contractual relationship with the entity that failed.
What does OCC 2023-17 require for subcontracting oversight?
OCC 2023-17 (the interagency guidance on third-party relationships) requires banking organizations to evaluate whether their third parties have adequate processes for overseeing their own subcontractors, particularly for critical activities. The guidance expects financial institutions to include subcontracting provisions in third-party contracts — including requirements for prior approval or notification before material subcontracting changes — and to understand the subcontracting landscape for their highest-risk vendors.
What's the most practical way to map fourth-party dependencies?
Start with your critical and high-risk vendors: (1) require annual subcontractor disclosure as a contract provision, (2) review the SOC 2 Type II report's subservice organization section to identify key fourth parties, (3) add a dedicated subcontracting section to your vendor risk questionnaire, and (4) build a concentration map that identifies which fourth-party infrastructure providers appear across multiple critical vendors. Cloud providers and telecom carriers are where concentration typically surfaces.
What enforcement cases illustrate nth-party risk in practice?
The Synapse Financial Technologies bankruptcy in April 2024 locked approximately $265 million in consumer funds across multiple fintech platforms — all of whom used Synapse as a Banking-as-a-Service middleware layer that those platforms' end-users never knew existed. The fintechs were the FIs' fourth parties, not their direct vendors. The CrowdStrike outage in July 2024 disrupted 8.5 million Windows systems globally; many affected banks' technology vendors used CrowdStrike as an endpoint security subcontractor. Neither event required the affected institutions to have a direct relationship with the entity that failed.
Does DORA require sub-outsourcing chain documentation?
Yes. DORA Article 30 requires that ICT third-party service contracts for critical or important functions include sub-outsourcing chain provisions — specifically, the conditions under which sub-outsourcing is permitted, which sub-outsourcing arrangements are already in place, and what obligations the ICT provider has to notify the financial institution of material changes to the sub-outsourcing chain. For US financial institutions with EU operations, DORA compliance was required as of January 17, 2025.
How do I identify cloud concentration across my vendor chain?
AWS, Microsoft Azure, and Google Cloud collectively provide approximately 62% of cloud infrastructure globally. That means a significant portion of your vendors — even if they compete directly with each other — likely run on the same underlying infrastructure. To surface this: add 'primary cloud infrastructure provider(s)' to your vendor questionnaire for critical vendors, review SOC 2 subservice org disclosures for cloud dependencies, and build a simple matrix mapping critical vendors to their cloud provider. Any single cloud provider that appears across more than 20-25% of your critical vendor base represents a concentration you should document and monitor.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.