Feature Third-Party Risk
Nth-Party Risk in TPRM: Mapping the Subcontracting Chain OCC 2023-17 Expects You to Understand
26% of financial institutions don't assess fourth-party risk at all. OCC 2023-17 made subcontracting oversight explicit. Here's how to map your vendor chain, what contract provisions you need, and what examiners expect to see.
Table of Contents
On July 19, 2024, a faulty CrowdStrike content update crashed 8.5 million Windows systems in four hours. Banks, payment processors, and financial market infrastructure were among the affected organizations worldwide — and many of their IT vendors were too. The banks that experienced the most significant disruption weren’t CrowdStrike customers. They were customers of vendors that were CrowdStrike customers.
That’s nth-party risk. And according to the 2026 State of TPRM Survey, 26% of financial institutions still don’t assess fourth-party risk at all.
OCC 2023-17 — the interagency third-party risk guidance issued jointly by the OCC, Federal Reserve, and FDIC in June 2023 — made the obligation explicit. Financial institutions are expected to understand their critical vendors’ subcontracting relationships, build appropriate oversight provisions into contracts, and demonstrate to examiners that they have visibility into the chain, not just the link directly in front of them.
TL;DR
- 26% of financial institutions don’t assess fourth-party risk; 27% don’t assess or monitor it after the initial review (2026 State of TPRM Survey)
- OCC 2023-17 requires evaluation of third-party subcontracting oversight processes for critical activities — this is now an exam finding area
- AWS, Azure, and GCP host approximately 62% of cloud infrastructure globally, creating structural concentration across vendor chains regardless of which vendors you’ve selected
- Four practical tools to map your chain: contract disclosure requirements, SOC 2 subservice org review, vendor questionnaire subcontracting section, and concentration mapping
- DORA Article 30 requires sub-outsourcing chain provisions for critical ICT functions — affecting US FIs with EU operations
What Nth-Party Risk Actually Means
The terminology gets loose in practice, so the definitions matter:
| Party Level | Definition | Example |
|---|---|---|
| First party | Your institution | The bank |
| Second party | Your customers and counterparties | Depositors, borrowers |
| Third party | Your direct vendors and service providers | Core banking system provider, cloud hosting vendor |
| Fourth party | Your third party’s subcontractors | The data center your core banking vendor uses; the cloud provider under your SaaS vendor |
| Fifth party (and beyond) | Subcontractors of subcontractors | The CDN provider your vendor’s cloud host uses |
In practice, “nth-party risk” is commonly used to refer to fourth-party and beyond. “Nth” signals that the chain doesn’t stop at four — for complex technology vendors, the actual subcontracting depth can reach eight or ten layers before you hit hardware.
The risk profile changes at each layer. Your direct vendor (third party) is subject to your contract terms, your due diligence requirements, and your exit provisions. Your vendor’s subcontractor (fourth party) is subject only to whatever your vendor has negotiated with them — and to whatever requirements you’ve contractually obligated your vendor to flow down. Without explicit flow-down provisions, your vendor may have subcontracted a critical function to an entity that has no awareness you exist and no obligation to your regulatory requirements.
What OCC 2023-17 Actually Requires
The OCC’s interagency guidance on third-party risk management — issued jointly with the Federal Reserve and FDIC in June 2023 and replacing the OCC’s 2013 guidance — addresses subcontracting in the Planning, Due Diligence, and Contract Negotiation sections.
In the Due Diligence phase, the guidance expects institutions to “assess the third party’s use of subcontractors, especially for critical activities, including the subcontractors’ locations and whether foreign-based third parties or subcontractors present unique risks.” That means your vendor questionnaire for critical vendors should explicitly address: who their critical subcontractors are, where those subcontractors are located, and how your vendor oversees them.
In the Contract Negotiation phase, the guidance identifies specific contract provisions that should address subcontracting:
- The third party’s obligation to notify the institution before making material changes to subcontracting arrangements
- The institution’s right to approve material subcontracting changes for critical activities (or at minimum, to receive advance notice)
- Flow-down of regulatory compliance obligations to subcontractors where applicable
- Audit rights that extend to subcontractors for critical activities
For Ongoing Monitoring, the guidance expects institutions to “monitor whether third parties are using subcontractors as expected and whether those subcontractors continue to meet performance and risk standards.” This means annual subcontractor disclosure isn’t a one-time due diligence item — it’s a continuous monitoring requirement for critical vendors.
The examination consequence is straightforward: examiners reviewing your TPRM program for critical vendors will ask whether you know who the critical subcontractors are and whether your contracts include the provisions above. An inability to answer is a finding.
Why Cloud Concentration Makes This Structural
Here’s the challenge that makes nth-party risk hard to manage through contract provisions alone: many of the most significant fourth-party concentrations aren’t the result of poor vendor management. They’re structural features of the modern technology landscape.
AWS, Microsoft Azure, and Google Cloud provide approximately 62% of global cloud infrastructure. That means two vendors you selected independently — say, your core banking SaaS provider and your fraud analytics vendor — may both be running on AWS. Your cloud concentration risk from those two vendors exists at a fourth-party level you didn’t create and can’t fully contract away.
Other structural concentration points in financial services:
- Telecom infrastructure: A significant share of financial institution voice and data circuits routes through AT&T, Verizon, or Lumen at some layer of the stack. The January 2024 AT&T outage demonstrated this when multiple banks reported transaction processing delays from vendors who didn’t appear on the AT&T customer list but whose hosting providers did.
- DNS and CDN providers: Cloudflare, Akamai, and Fastly concentrate web routing and content delivery for large portions of the internet. An outage at any of them — like the Fastly outage in June 2021 that took down major news sites and payment portals — can cascade through vendor chains.
- Identity and authentication providers: Okta, Azure AD, and a handful of other identity providers authenticate users for a large share of enterprise SaaS applications. An Okta security breach, like the one in October 2023, doesn’t just affect Okta customers — it affects every vendor that uses Okta to authenticate its users.
The regulatory expectation isn’t that you eliminate these concentrations — you can’t. It’s that you understand them, document them, and have considered the recovery implications in your contingency planning.
Four Practical Tools for Chain Mapping
1. Annual Subcontractor Disclosure Requirements
For critical and high-risk vendors, add an explicit contract provision requiring annual disclosure of material subcontractors — defined as any subcontractor that performs functions material to the service the vendor provides to you. The provision should require:
- Annual disclosure of the subcontractor name, location, and function
- Advance notice (30 to 60 days) before adding new material subcontractors
- Prior written approval (or a right to object) for changes to subcontractors handling critical functions
This converts subcontractor visibility from a goodwill exercise into a contractual right. Vendors that push back on annual disclosure requirements for critical functions deserve scrutiny — the resistance itself is an information signal about their subcontracting practices.
For existing contracts that lack these provisions, include them in the next renewal cycle. For contracts that are mid-term and cover critical activities, consider whether the gap is significant enough to warrant a contract amendment.
2. SOC 2 Subservice Organization Review
Every SOC 2 Type II report identifies the scope of what was tested and, critically, what was excluded through the “subservice organization” or “carved-out” scope limitation. When a vendor uses a subservice organization (a subcontractor that performs functions included in the service scope), the SOC 2 either includes that subservice organization in the scope (inclusive method) or excludes it and notes it as carved out.
When reviewing a vendor’s SOC 2 report, look specifically at:
- Section 1 or Section 2: Description of subservice organizations and how they’re handled in the scope
- Complementary Subservice Organization Controls (CSOCs): Controls the vendor assumes subservice organizations are performing — which you should verify with those organizations’ own reports
- Bridging letters: For major subservice organizations (AWS, Azure, Azure AD), request or locate the subservice organization’s own SOC 2 to verify the controls assumed in your vendor’s report are actually in place
A vendor whose entire infrastructure runs on AWS but whose SOC 2 carves AWS out and lists 40 CSOCs is relying entirely on AWS controls without testing them. That gap in assurance coverage is a fourth-party risk finding.
3. Vendor Questionnaire Subcontracting Section
Add a dedicated subcontracting section to your standard vendor risk questionnaire. For critical and high-risk vendors, the section should ask:
- List all material subcontractors (those performing functions material to the service provided)
- For each, provide: name, location, function, contract term, and whether they are included in your most recent SOC 2 scope
- Describe your process for overseeing subcontractor performance and compliance
- Describe your change management process when adding or replacing material subcontractors
- Have any material subcontractors experienced a security incident, regulatory action, or business continuity event in the past 24 months?
The last question surfaces incidents that may not have reached you through normal channels — a fourth-party breach that your vendor responded to but didn’t disclose because there was no contractual obligation to do so.
4. Concentration Mapping
Build a simple matrix that plots your critical and high-risk vendors against their primary infrastructure providers. The columns represent the key fourth-party providers (AWS, Azure, GCP, major telecom carriers, identity providers). The rows represent your critical vendors. A check mark where they intersect shows you where concentration exists.
The output isn’t a list of problems to solve. It’s a documented understanding of your fourth-party landscape that you can present to examiners, incorporate into business continuity scenarios, and use to inform your fourth-party KRI monitoring framework. Examiners don’t expect zero concentration — they expect evidence that you understand it and have considered the recovery implications.
DORA’s Sub-Outsourcing Chain Requirements
For US financial institutions with EU operations, DORA added regulatory teeth to nth-party risk requirements that took effect January 17, 2025. Article 30 of DORA — which governs key contractual provisions for ICT third-party service arrangements — requires that contracts for critical and important functions include:
- Explicit provisions governing sub-outsourcing of the ICT service, including the conditions under which sub-outsourcing is permitted
- A list of current subcontractors involved in the ICT service
- Obligations for the ICT provider to notify the institution before making material changes to the subcontracting chain
- The financial institution’s right to object to or terminate if material subcontracting changes are made without notification
DORA’s ICT contract requirements also require institutions to maintain an information register of all ICT third-party service arrangements — which effectively requires mapping the sub-outsourcing chain for all critical functions, not just the ones you select to review.
For US banks that treated DORA as someone else’s problem, the sub-outsourcing chain documentation requirements are worth noting even outside the EU compliance context. The FFIEC’s interagency guidance and DORA’s Article 30 are converging on the same expectation: know your vendor’s subcontractors for critical functions, build it into your contracts, and document it.
What Examiners Are Asking
Based on the current examination climate, these are the five questions your TPRM program should be able to answer before an examiner asks them:
-
“For your top ten critical vendors, who are their material subcontractors?” — If you can’t answer this, you have a gap in your ongoing monitoring program.
-
“Do your critical vendor contracts require advance notice before material subcontracting changes?” — Pull the relevant contract sections and be able to cite the provision number.
-
“Have you identified any cloud infrastructure concentration across your critical vendor portfolio?” — The answer isn’t “no.” It’s “yes, and here’s what we documented.”
-
“When did you last review your critical vendors’ SOC 2 subservice organization disclosures?” — The answer should be “in the last 12 months,” with documentation.
-
“If your largest critical vendor’s primary cloud infrastructure provider experienced an extended outage, which of your critical functions would be affected, and what’s your recovery plan?” — This is the Business Continuity question that flows directly from nth-party concentration mapping.
So What?
Most TPRM programs are built to manage the vendor in front of them. The exam standard — and the CrowdStrike, Synapse, and AT&T pattern from the last two years — is that the failures you don’t see coming are the ones routed through a subcontractor your vendor never disclosed.
Closing that gap doesn’t require a new platform or a comprehensive re-underwriting of every vendor. It requires four practical additions to your existing program: annual subcontractor disclosure requirements in critical vendor contracts, SOC 2 subservice org review as part of your due diligence process, a subcontracting section in your questionnaire, and a one-page concentration map for your critical vendor portfolio.
The Third-Party Risk Management (TPRM) Kit includes vendor contract checklists, questionnaire templates with a subcontracting section, and the due diligence documentation framework that maps to OCC 2023-17’s expectations — built to answer the five examiner questions above before they’re asked.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is nth-party risk in TPRM?
What does OCC 2023-17 require for subcontracting oversight?
What's the most practical way to map fourth-party dependencies?
What enforcement cases illustrate nth-party risk in practice?
Does DORA require sub-outsourcing chain documentation?
How do I identify cloud concentration across my vendor chain?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026