Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Third-Party Risk

Fourth-Party Risk: A Practical Subcontractor Evidence File

Use the 2023 interagency guidance to scope subcontractor risk, contract controls, concentration analysis, and examiner-ready evidence.

Table of Contents

TL;DR

  • The federal banking agencies use subcontractor rather than “fourth party,” and they do not expect a bank to assess every subcontractor in every vendor chain.
  • The practical obligation is risk-based: understand whether subcontracting heightens risk, evaluate the direct vendor’s oversight, address material dependencies in the contract, and monitor meaningful changes.
  • A useful examination artifact is a short subcontractor evidence file that connects each important dependency to the service, control evidence, concentration assessment, owner, and open action.

Fourth-party risk becomes unmanageable when the program starts with “map every vendor’s vendor.” That is not the standard the banking agencies set.

The 2023 Interagency Guidance on Third-Party Relationships: Risk Management, issued by the Federal Reserve, FDIC, and OCC, takes a targeted approach. In the preamble, the agencies acknowledged the difficulty of overseeing organizations with which a bank has no direct relationship. They clarified that banking organizations are not expected to assess or oversee every subcontractor. Instead, the bank evaluates its direct third party’s process and asks whether subcontracting creates additional risk to the bank.

That distinction should drive the evidence file. The objective is not an infinite supply-chain diagram. It is a defensible record showing that the bank found the downstream dependencies capable of disrupting a higher-risk activity and made a reasoned decision about them.

What the 2023 guidance actually says about subcontractors

The full interagency guidance defines subcontractors broadly as suppliers, service providers, or other organizations enlisted by a third party. It addresses them at several points in the third-party lifecycle:

  1. Due diligence. A banking organization considers how the third party manages risks from subcontracting, including how it selects and oversees subcontractors and ensures they implement effective controls. Geographic location and dependence on one provider for several activities are relevant considerations.
  2. Other contractual arrangements. The bank may evaluate the third party’s legally binding arrangements with subcontractors to determine whether they create or transfer risk to the bank or its customers.
  3. Contract negotiation. Depending on risk and complexity, the contract can address notice of significant changes involving subcontractors, access to relevant audit material, responsibility for subcontractor conduct, and termination rights if subcontracting arrangements breach agreed obligations.
  4. Ongoing monitoring. Changes in the third party’s agreements with other entities may create new risk or affect its ability to perform. Monitoring should be proportionate to the relationship and adjusted as the risk changes.

These are risk-management considerations, not a universal clause checklist. The guidance repeatedly ties depth and frequency to the activity’s risk and complexity. A low-risk office-supply vendor and a provider supporting a critical payment service should not produce identical files.

Triage the downstream dependency before expanding the file

Start with the direct relationship. Ask the business owner and the vendor which subcontractors are necessary to deliver the service used by the bank. Then triage each disclosed dependency.

Triage questionEvidence to captureWhy it matters
What bank service or activity depends on the subcontractor?Service description and process or system mapPrevents collecting vendor names with no link to operational impact
Does it support a higher-risk or critical activity?Criticality rationale and impact analysisSets the depth of due diligence and monitoring
Does it handle bank or customer data?Data type, access, processing and hosting locationIdentifies confidentiality, integrity, privacy and location risk
Could one failure affect several bank services or vendors?Cross-portfolio concentration mapExposes shared cloud, telecom, software and processing dependencies
How does the direct vendor oversee it?Selection standards, monitoring description, control reports and issue processTests the capability the guidance tells the bank to evaluate
What happens when the subcontractor changes?Contract notice terms and operational intake workflowTurns a clause into an actual monitoring process

The file can stop growing when the bank can explain why a dependency is not material. Record the reason. “Vendor uses subcontractors” is not, by itself, a conclusion that each one requires separate review.

Contract controls should follow the risk—not boilerplate

The interagency guidance says contract detail may be tailored to risk and complexity. For subcontracting, it identifies several considerations rather than prescribing a single mandatory provision for every agreement.

For a higher-risk relationship, counsel and the relationship owner can consider:

  • when and how the third party notifies the bank of its use or intended use of material subcontractors;
  • whether identified subcontractors or locations require consent or are prohibited;
  • what relevant performance, audit, control and compliance information the third party must provide;
  • whether the third party remains responsible for the subcontractor’s performance;
  • who bears additional monitoring or remediation costs; and
  • whether nonconforming subcontracting permits termination without penalty.

The 2020 Joint Statement on Security in a Cloud Computing Environment gives a cloud-specific example: management should understand contractual responsibilities, including notification or approval requirements for subcontractors, data ownership, data return or removal, and geographic restrictions. The statement describes risk-management practices; it does not make one standard cloud clause suitable for every institution.

If a vendor will not accept a requested term, document the limitation, the resulting residual risk, compensating evidence, decision authority, and renewal or exit plan. The 2023 guidance expressly recognizes that banks may have limited negotiating leverage. A rejected clause is not a reason to pretend the dependency disappeared.

Build a portfolio-level concentration view

A vendor-by-vendor review can miss a shared dependency. The guidance calls out dependence on a single provider for multiple activities and geographic concentrations where the bank, its vendors, and subcontractors rely on the same region, power, or telecommunications infrastructure.

A simple concentration register should answer:

  • Which downstream providers appear in more than one higher-risk service chain?
  • Which important services share a region, facility, network, identity platform, or cloud provider?
  • Could a single incident breach several recovery assumptions at once?
  • Is the proposed mitigation truly independent, or does the fallback use the same underlying provider?

Do not turn an arbitrary count into a regulatory threshold. Rank the concentration by business-service impact, customer harm, substitutability, recovery capability, and the quality of available evidence. A provider appearing twice can matter more than one appearing ten times if both dependencies support the same time-critical service.

The examiner-ready subcontractor evidence file

For each higher-risk direct relationship, keep one concise record rather than scattering evidence across procurement email, security tooling, and contract folders.

FieldMinimum useful contentOwner
Service and criticalityActivity supported, criticality decision and review dateBusiness owner
Material subcontractorsName, function, location, data access and source/date of disclosureThird-party risk
Vendor oversight assessmentHow the vendor selects, contracts with, monitors and remediates subcontractorsThird-party risk / security
Contract positionNotice, information, audit, responsibility, incident and termination terms; documented gapsLegal / procurement
Control evidenceRelevant reports, certifications, test results, exceptions and expiry datesSecurity / compliance
ConcentrationShared dependencies and combined operational impactOperational resilience
Monitoring triggerChange notice, incident, adverse control result, material location change or renewalRelationship owner
Decision and actionsResidual-risk decision, approver, remediation owner and due dateAccountable risk owner

The OCC’s 2024 community-bank guide is useful when scaling this work. It offers questions and resources, but it does not replace the interagency guidance or create a separate checklist. Use it to make the review practical for the bank’s size, risk profile, and relationship complexity.

A focused 30-day cleanup

This is a RiskTemplates implementation recommendation, not a regulator-imposed deadline.

  1. Week 1 — Scope. Select the bank’s higher-risk relationships and identify the downstream providers necessary to deliver those services.
  2. Week 2 — Evidence. Compare disclosures, due-diligence files, contracts, control reports, architecture maps and business-continuity documentation. Log contradictions instead of choosing the most convenient version.
  3. Week 3 — Concentration. Normalize provider names and map shared provider, region, facility and network dependencies across the selected relationships.
  4. Week 4 — Decide. Assign each gap an owner, due date and escalation path. Record accepted limitations and the evidence supporting the decision.

The strongest file is not the longest. It shows the line from dependency to risk, evidence, decision and action—and it can be refreshed when the vendor changes how the service is delivered.


The Third-Party Risk Management (TPRM) Kit includes vendor assessment, contract, monitoring, and concentration-risk artifacts that can be tailored to the 2023 interagency guidance.

Primary sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does a bank need to assess every subcontractor used by every third party?
No. In the preamble to the 2023 interagency guidance, the Federal Reserve, FDIC, and OCC said they did not expect banking organizations to assess or oversee every subcontractor. The risk-based task is to evaluate whether subcontracting raises additional risk and whether the direct third party can select, oversee, and control the subcontractors that matter to the bank's activity.
What subcontractor evidence should a bank retain?
For higher-risk relationships, retain the current material-subcontractor information supplied by the third party, the bank's assessment of the third party's oversight process, relevant contract and notification provisions, available control or audit reports, documented concentrations, identified gaps, risk acceptance, and remediation tracking. The exact file should be proportionate to the relationship's risk and complexity.
Does the 2023 guidance require a specific subcontractor contract clause?
No single clause is prescribed for every relationship. The guidance identifies risk-based contract considerations, including notice of significant operational changes such as use of subcontractors, audit coverage for relevant subcontractors, and more detailed obligations when subcontracting is integral to the activity. Institutions should tailor language to the service, data, criticality, and negotiating leverage.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.