Feature Third-Party Risk
Fourth-Party Risk: A Practical Subcontractor Evidence File
Use the 2023 interagency guidance to scope subcontractor risk, contract controls, concentration analysis, and examiner-ready evidence.
Table of Contents
TL;DR
- The federal banking agencies use subcontractor rather than “fourth party,” and they do not expect a bank to assess every subcontractor in every vendor chain.
- The practical obligation is risk-based: understand whether subcontracting heightens risk, evaluate the direct vendor’s oversight, address material dependencies in the contract, and monitor meaningful changes.
- A useful examination artifact is a short subcontractor evidence file that connects each important dependency to the service, control evidence, concentration assessment, owner, and open action.
Fourth-party risk becomes unmanageable when the program starts with “map every vendor’s vendor.” That is not the standard the banking agencies set.
The 2023 Interagency Guidance on Third-Party Relationships: Risk Management, issued by the Federal Reserve, FDIC, and OCC, takes a targeted approach. In the preamble, the agencies acknowledged the difficulty of overseeing organizations with which a bank has no direct relationship. They clarified that banking organizations are not expected to assess or oversee every subcontractor. Instead, the bank evaluates its direct third party’s process and asks whether subcontracting creates additional risk to the bank.
That distinction should drive the evidence file. The objective is not an infinite supply-chain diagram. It is a defensible record showing that the bank found the downstream dependencies capable of disrupting a higher-risk activity and made a reasoned decision about them.
What the 2023 guidance actually says about subcontractors
The full interagency guidance defines subcontractors broadly as suppliers, service providers, or other organizations enlisted by a third party. It addresses them at several points in the third-party lifecycle:
- Due diligence. A banking organization considers how the third party manages risks from subcontracting, including how it selects and oversees subcontractors and ensures they implement effective controls. Geographic location and dependence on one provider for several activities are relevant considerations.
- Other contractual arrangements. The bank may evaluate the third party’s legally binding arrangements with subcontractors to determine whether they create or transfer risk to the bank or its customers.
- Contract negotiation. Depending on risk and complexity, the contract can address notice of significant changes involving subcontractors, access to relevant audit material, responsibility for subcontractor conduct, and termination rights if subcontracting arrangements breach agreed obligations.
- Ongoing monitoring. Changes in the third party’s agreements with other entities may create new risk or affect its ability to perform. Monitoring should be proportionate to the relationship and adjusted as the risk changes.
These are risk-management considerations, not a universal clause checklist. The guidance repeatedly ties depth and frequency to the activity’s risk and complexity. A low-risk office-supply vendor and a provider supporting a critical payment service should not produce identical files.
Triage the downstream dependency before expanding the file
Start with the direct relationship. Ask the business owner and the vendor which subcontractors are necessary to deliver the service used by the bank. Then triage each disclosed dependency.
| Triage question | Evidence to capture | Why it matters |
|---|---|---|
| What bank service or activity depends on the subcontractor? | Service description and process or system map | Prevents collecting vendor names with no link to operational impact |
| Does it support a higher-risk or critical activity? | Criticality rationale and impact analysis | Sets the depth of due diligence and monitoring |
| Does it handle bank or customer data? | Data type, access, processing and hosting location | Identifies confidentiality, integrity, privacy and location risk |
| Could one failure affect several bank services or vendors? | Cross-portfolio concentration map | Exposes shared cloud, telecom, software and processing dependencies |
| How does the direct vendor oversee it? | Selection standards, monitoring description, control reports and issue process | Tests the capability the guidance tells the bank to evaluate |
| What happens when the subcontractor changes? | Contract notice terms and operational intake workflow | Turns a clause into an actual monitoring process |
The file can stop growing when the bank can explain why a dependency is not material. Record the reason. “Vendor uses subcontractors” is not, by itself, a conclusion that each one requires separate review.
Contract controls should follow the risk—not boilerplate
The interagency guidance says contract detail may be tailored to risk and complexity. For subcontracting, it identifies several considerations rather than prescribing a single mandatory provision for every agreement.
For a higher-risk relationship, counsel and the relationship owner can consider:
- when and how the third party notifies the bank of its use or intended use of material subcontractors;
- whether identified subcontractors or locations require consent or are prohibited;
- what relevant performance, audit, control and compliance information the third party must provide;
- whether the third party remains responsible for the subcontractor’s performance;
- who bears additional monitoring or remediation costs; and
- whether nonconforming subcontracting permits termination without penalty.
The 2020 Joint Statement on Security in a Cloud Computing Environment gives a cloud-specific example: management should understand contractual responsibilities, including notification or approval requirements for subcontractors, data ownership, data return or removal, and geographic restrictions. The statement describes risk-management practices; it does not make one standard cloud clause suitable for every institution.
If a vendor will not accept a requested term, document the limitation, the resulting residual risk, compensating evidence, decision authority, and renewal or exit plan. The 2023 guidance expressly recognizes that banks may have limited negotiating leverage. A rejected clause is not a reason to pretend the dependency disappeared.
Build a portfolio-level concentration view
A vendor-by-vendor review can miss a shared dependency. The guidance calls out dependence on a single provider for multiple activities and geographic concentrations where the bank, its vendors, and subcontractors rely on the same region, power, or telecommunications infrastructure.
A simple concentration register should answer:
- Which downstream providers appear in more than one higher-risk service chain?
- Which important services share a region, facility, network, identity platform, or cloud provider?
- Could a single incident breach several recovery assumptions at once?
- Is the proposed mitigation truly independent, or does the fallback use the same underlying provider?
Do not turn an arbitrary count into a regulatory threshold. Rank the concentration by business-service impact, customer harm, substitutability, recovery capability, and the quality of available evidence. A provider appearing twice can matter more than one appearing ten times if both dependencies support the same time-critical service.
The examiner-ready subcontractor evidence file
For each higher-risk direct relationship, keep one concise record rather than scattering evidence across procurement email, security tooling, and contract folders.
| Field | Minimum useful content | Owner |
|---|---|---|
| Service and criticality | Activity supported, criticality decision and review date | Business owner |
| Material subcontractors | Name, function, location, data access and source/date of disclosure | Third-party risk |
| Vendor oversight assessment | How the vendor selects, contracts with, monitors and remediates subcontractors | Third-party risk / security |
| Contract position | Notice, information, audit, responsibility, incident and termination terms; documented gaps | Legal / procurement |
| Control evidence | Relevant reports, certifications, test results, exceptions and expiry dates | Security / compliance |
| Concentration | Shared dependencies and combined operational impact | Operational resilience |
| Monitoring trigger | Change notice, incident, adverse control result, material location change or renewal | Relationship owner |
| Decision and actions | Residual-risk decision, approver, remediation owner and due date | Accountable risk owner |
The OCC’s 2024 community-bank guide is useful when scaling this work. It offers questions and resources, but it does not replace the interagency guidance or create a separate checklist. Use it to make the review practical for the bank’s size, risk profile, and relationship complexity.
A focused 30-day cleanup
This is a RiskTemplates implementation recommendation, not a regulator-imposed deadline.
- Week 1 — Scope. Select the bank’s higher-risk relationships and identify the downstream providers necessary to deliver those services.
- Week 2 — Evidence. Compare disclosures, due-diligence files, contracts, control reports, architecture maps and business-continuity documentation. Log contradictions instead of choosing the most convenient version.
- Week 3 — Concentration. Normalize provider names and map shared provider, region, facility and network dependencies across the selected relationships.
- Week 4 — Decide. Assign each gap an owner, due date and escalation path. Record accepted limitations and the evidence supporting the decision.
The strongest file is not the longest. It shows the line from dependency to risk, evidence, decision and action—and it can be refreshed when the vendor changes how the service is delivered.
The Third-Party Risk Management (TPRM) Kit includes vendor assessment, contract, monitoring, and concentration-risk artifacts that can be tailored to the 2023 interagency guidance.
Primary sources
- OCC Bulletin 2023-17: Interagency Guidance on Third-Party Relationships: Risk Management
- Interagency Guidance on Third-Party Relationships: Risk Management (PDF)
- OCC Bulletin 2020-46: Joint Statement on Security in a Cloud Computing Environment
- OCC Bulletin 2024-11: Third-Party Relationships—A Guide for Community Banks
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does a bank need to assess every subcontractor used by every third party?
What subcontractor evidence should a bank retain?
Does the 2023 guidance require a specific subcontractor contract clause?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
DORA Register of Information: Turn the 2024 Dry-Run Results Into a Data-Quality Control
Only 6.5% of 947 integrated DORA dry-run registers passed all 116 checks. Here is a repeatable remediation and evidence process.
Aug 16, 2026
Third-Party Risk
UK Critical Third Parties: What the 2026 Cloud Designations Mean for TPRM
Four UK critical-third-party designations took effect July 13, 2026. Separate provider duties, firm duties, PS26/2, and existing U.S. authority.
Aug 8, 2026
Third-Party Risk
Your Bank Partner Just Got an OCC Consent Order. What Happens to Your Fintech Program.
In May 2026, the OCC made public a consent order against Community Federal Savings Bank for BSA/AML deficiencies tied to fintech-partner payment processing growth—wire, ACH, and cross-border volume the bank couldn't supervise. Fintechs whose programs run through enforcement-action banks face program pause, enhanced scrutiny, or termination. Here's what your TPRM program needs to monitor.
Aug 3, 2026