Feature Third-Party Risk
Fourth-Party Risk: What the 2023 Interagency Guidance Actually Requires When Your Vendor's Vendor Is the Exposure
Regulators don't use the phrase 'fourth-party risk' — they call it subcontractor risk, and the 2023 interagency guidance has specific requirements for it. Here's what examiners are looking for, what common MRAs look like, and how the CrowdStrike incident and UK Critical Third Party designations changed the calculus.
Table of Contents
TL;DR
- Regulators call it “subcontractor risk,” not “fourth-party risk” — and the 2023 interagency guidance (OCC Bulletin 2023-17 / FDIC FIL-29-2023 / Fed SR 23-4) has specific requirements for it across the full vendor lifecycle
- Banks are not expected to assess every subcontractor — they must evaluate their vendor’s own oversight process, identify concentrations, and build specific contract provisions
- Common MRAs: no subcontractor risk process, concentration not documented, contracts missing notification and audit-right provisions
- The CrowdStrike incident (8.5 million devices), the AWS US-EAST-1 outage (October 2025), and the UK’s first-ever Critical Third Party cloud designations (July 2026) have made regulators significantly less patient with gaps in this area
The Incident That Made the Concept Real
On July 19, 2024, a faulty content update to CrowdStrike’s Falcon endpoint security software triggered Blue Screen of Death errors on approximately 8.5 million Windows devices globally. Banks, payment networks, airlines, and hospitals were simultaneously impaired — not because they’d all made the same technology decision, but because they’d all licensed a product that relied on a common update mechanism from a common vendor.
The banking sector felt it directly. Trading desks couldn’t access systems. Back-office operations slowed. Customer-facing apps went dark. None of these institutions had a contract with CrowdStrike’s content delivery infrastructure. It was a subcontractor relationship — a fourth-party dependency — that most had neither mapped nor stress-tested.
The OCC’s Fall 2024 Semiannual Risk Perspective named the incident explicitly when discussing elevated third-party operational risks across the financial sector. That’s when fourth-party risk moved from a theoretical concern in regulatory guidance to an examiner priority.
What the Guidance Actually Says (and Doesn’t Say)
US regulators don’t use the phrase “fourth-party risk.” The 2023 Interagency Guidance on Third-Party Relationships: Risk Management — published June 6, 2023 as OCC Bulletin 2023-17, FDIC FIL-29-2023, and Federal Reserve SR 23-4 — uses “subcontractors,” defined as “suppliers, service providers, or other organizations enlisted by a third party.” The risk arises from “the absence of a direct relationship between the banking organization and the subcontractor.”
Critically, the guidance also says what banks are not required to do: “Banking organizations are not expected to assess or oversee all subcontractors of a third party.” The obligation is targeted, not universal.
What the guidance does require:
1. Evaluate the vendor’s own process. During due diligence, banks must assess “the third party’s ability to identify, manage, and mitigate risks from its own subcontracting arrangements.” You’re reviewing their vendor management program, not performing direct diligence on each subcontractor.
2. Identify concentration risk. The guidance is direct: “Concentrations may arise when a bank relies on a single third party for multiple activities, particularly when several of the activities are critical to bank operations.” And: “Geographic concentrations can arise when a bank’s own operations, and that of its third parties and subcontractors, are located in the same region or are dependent on the same critical power and telecommunications infrastructures.”
3. Embed protections in contracts. Agreements with critical vendors must require: notification of material changes to subcontractor relationships; the vendor’s maintenance of its own vendor management program; audit rights for critical subcontractors; and geographic restrictions on where subcontracted data is stored or processed.
4. Monitor ongoing changes. Vendors add and change subcontractors. Your ongoing monitoring program must track whether those changes heighten risk to the bank.
That’s the framework. The gap most examiners find isn’t that banks misunderstood the requirements — it’s that the third-party risk process stops at the direct vendor relationship and never extends to what sits beneath it.
Cloud Concentration: The Specific Problem Nobody Has Fully Solved
Cloud infrastructure is where subcontractor concentration becomes a systemic issue. Most banks have made independent decisions to use major cloud providers — AWS, Azure, and Google Cloud — for their own infrastructure. Many of their critical vendors have made the same decision. The result: an institution might interact with AWS through its own systems, through its core processor, through its fraud detection vendor, and through its payment network — and never have assessed the concentration.
The FFIEC’s 2020 Joint Statement on Security in a Cloud Computing Environment is the most specific US regulatory document on this. It requires that cloud vendor contracts address “notification or approval requirements for the use of subcontractors (i.e., fourth parties), data ownership, expectations for removal and return of data at contract termination, and restrictions on geographic locations where data may be stored.”
The US approach remains principles-based — no cloud provider has been named in formal US regulatory enforcement. That’s in sharp contrast to what just happened in the UK.
On July 13, 2026, HM Treasury formally designated four cloud providers as Critical Third Parties under the Financial Services and Markets Act 2023: AWS EMEA SARL, Microsoft Ireland Operations (Azure), Google Cloud EMEA, and Oracle UK. The Bank of England, PRA, and FCA can now compel these providers to provide information, conduct resilience assessments, enforce CTP-specific rules, require stress testing, and mandate incident reporting. It’s the first instance anywhere in the world of financial regulators directly overseeing hyperscale cloud providers.
The designation came in part because of the October 2025 AWS US-EAST-1 outage, which disrupted trading platforms, consumer banking apps, and financial services across the US and UK. US regulators watched that incident. The Basel Committee on Banking Supervision, in its December 2025 final Principles for the Sound Management of Third-Party Risk (BCBS d605), requires banks to maintain up-to-date registers of all third-party arrangements and key parties in the supply chain, and to assess and aggregate concentration risk — language that points directly at cloud provider concentration.
The US hasn’t named AWS in a guidance document. But when the UK just did, in the context of a global framework that US regulators actively participated in building, the direction of travel is clear.
What Examiners Are Actually Looking For
Based on OCC Bulletin 2017-7 supplemental examination procedures and the 2023 interagency guidance, here’s what typically shows up on the pre-examination information request for third-party risk:
| Category | What Examiners Request |
|---|---|
| Vendor inventory | Complete list of all third-party relationships with risk classifications (low, high, critical) |
| Due diligence files | Full due diligence package for critical vendor selection, including questionnaires, financial reviews, security assessments |
| Contracts | Sample of vendor agreements reviewed for required provisions — audit rights, subcontractor notice, exit rights, incident notification |
| Ongoing monitoring | Monitoring plans, vendor scorecards, audit findings, compliance reviews |
| Concentration documentation | Evidence the bank assessed whether concentrations exist and how they’re monitored |
| Board oversight | Board approvals for critical vendor relationships, reporting received |
Common examiner findings that generate MRAs:
- No comprehensive vendor inventory — specifically, no complete list with risk rankings applied
- Missing or stale due diligence for vendors classified as critical or high-risk (stale = more than 12 months without refresh for critical vendors)
- Contracts missing required provisions — most commonly: audit rights, subcontractor notification requirements, exit rights
- No ongoing monitoring beyond onboarding — a due diligence package exists, but there’s no evidence of annual review or monitoring output
- No process for subcontractor risk — the third-party risk program addresses direct vendors but has no documented process for assessing what sits beneath them
- Concentration not identified despite reliance on a single provider for multiple critical functions
This last one is the fourth-party problem in examiner language. When your fraud detection vendor, your core processor’s cloud environment, and your own infrastructure all sit on the same AWS region — and you haven’t documented that concentration, assessed the impact of its failure, or tested your recovery from it — that’s a finding.
The BaaS Consent Orders: What Concentrated Third-Party Failure Looks Like
Between late 2023 and mid-2024, the FDIC entered consent orders with a wave of banks offering Banking as a Service through fintech partnerships. Piermont Bank (February 2024) and Sutton Bank (February 2024) were among the most-cited. The FDIC found that Piermont had “failed to have the internal controls and information systems needed for the bank’s size, as well as for the scope and risk involved with its third-party relationships.”
The requirements imposed: enhanced board supervision of third-party relationships, and a 120-day review of whether the bank’s third-party program had adequate due diligence procedures, written agreement parameters, oversight and monitoring policies, and data and systems controls. These consent orders addressed the BaaS-fintech relationship directly, but the underlying examination process surfaced the same gaps that appear in fourth-party examinations: no process, no monitoring, no contract provisions, no concentration assessment.
BaaS is a useful lens for understanding fourth-party risk generally. When a sponsor bank enables a fintech, the fintech has its own technology vendors, its own subcontractors, its own cloud dependencies. The sponsor bank’s direct vendor — the fintech — sits on infrastructure the bank has never assessed. The FDIC consent orders made clear that “my vendor’s vendor” is not an acceptable boundary for responsibility.
Building the Third-Party Program That Covers This
The practitioner challenge with fourth-party risk is that it’s infinite in theory — any vendor has vendors who have vendors. The regulatory guidance is helpful here: it explicitly says you don’t need to trace every subcontractor. You need a targeted, risk-based process. Specifically:
For critical vendors: require subcontractor disclosure as part of onboarding. Document which subcontractors support delivery of the critical service to you. Review the vendor’s own subcontractor management process. Build contract provisions requiring notification of material changes.
For concentration mapping: run an annual exercise that asks one question — if this provider (cloud platform, SaaS application, network provider) went down, how many of our critical functions would be affected simultaneously? For any provider that appears in three or more critical function chains, document the concentration and the mitigation.
For contract remediation: if you inherited contracts that don’t have subcontractor notification provisions, your vendor due diligence and contract remediation process needs a specific workstream for critical vendors. Not all contracts will be renegotiable on your timeline, but the gap needs to be logged and tracked toward resolution.
For ongoing monitoring: your TPRM lifecycle and RACI structure needs an annual subcontractor refresh step for critical vendors — not a full re-assessment, but a documented check: did the vendor add or change material subcontractors? Did any new concentration emerge?
The BCBS framework (d605, December 2025) adds one more requirement that’s worth building toward: bank-level concentration risk analysis that aggregates across the full third-party portfolio. Not just “this vendor uses AWS” — but “across all our critical vendors, how much of our operational capability is exposed to AWS EAST-1?” That’s the analysis the UK just required through its Critical Third Party regime. It’s not a US requirement yet. It will be.
So What Does This Mean for Your Program?
The 2023 interagency guidance didn’t invent fourth-party risk — it codified what examiners had been looking for through MRAs for years. The CrowdStrike incident made the stakes visible to everyone. The UK CTP designations made clear where regulators globally are headed.
For most banks, the gap isn’t in the policy — it’s in the execution. The policy says the program is risk-based. The vendor questionnaire asks whether the vendor uses subcontractors. But there’s no documented process for what happens when the answer is yes, no concentration analysis has been run, and the most recent contracts with cloud vendors have no fourth-party notification clause.
That’s what the vendor questionnaire review process exists to surface. And it’s the finding that generates the MRA: not a missing policy, but a gap between what the policy says and what the documentation shows.
The Third-Party Risk Management (TPRM) Kit includes a vendor risk assessment framework, questionnaire templates, contract checklist, and ongoing monitoring program designed for banking organizations subject to the 2023 interagency guidance. The kit specifically covers subcontractor risk assessment workflow and concentration risk documentation.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does the 2023 interagency guidance actually require banks to do about their vendors' vendors?
Does my bank need to do due diligence on every subcontractor my critical vendors use?
What contract provisions should address fourth-party subcontractor risk?
What are the most common MRAs related to fourth-party and concentration risk?
What does the UK's Critical Third Party designation of AWS, Azure, Google Cloud, and Oracle mean for US banks?
What did CrowdStrike's July 2024 outage change in bank examiner focus on third-party risk?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Vendor Due Diligence After the Contract Is Signed: A 10-Day Recovery Plan
Use this vendor risk assessment checklist when Risk is brought in after signature: contain access, assess gaps, add conditions, and record exposure.
Jul 27, 2026
Third-Party Risk
Vendor Risk Questionnaire Review: Which Answers Require Challenge, Proof, or a Contract Condition
Review a vendor risk questionnaire by turning each answer into proof, a compensating control, a contract condition, escalation, or rejection.
Jul 26, 2026
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026