Feature Third-Party Risk
Fourth-Party Risk KRIs: Monitoring Concentration You Do Not Directly Control
You have no contract with fourth parties—but you inherit their failures. Here are the KRIs that surface cloud concentration, shared subcontractors, and upstream dependency risk before it becomes your incident.
Table of Contents
TL;DR
- Fourth-party risk—your vendor’s subcontractors—can’t be contracted away, but it can be measured and monitored through KRIs.
- The Change Healthcare ransomware attack (February 2024) affected up to 190 million Americans and cost UnitedHealth $2.8 billion because an entire industry had concentrated its claims processing through one clearinghouse.
- OCC Bulletin 2023-17 doesn’t require you to assess every fourth party directly—but it does require you to evaluate whether your critical vendors are managing their subcontractors competently.
- Key fourth-party KRIs: subcontractor disclosure completion rate, hyperscale cloud concentration ratio, SOC report carve-out count, fourth-party incident notification lag, and contract visibility gap percentage.
- DORA designated 19 Critical ICT Third-Party Providers (CTPPs) in 2025, with direct oversight of AWS, Azure, and Google Cloud implications for any financial entity with EU operations.
You have no contract with a fourth party. You never approved them. They don’t know your name. But when their infrastructure goes down at 2 a.m., your critical vendor’s SLA clock starts ticking—and so does yours.
The Change Healthcare ransomware attack, which hit on February 22, 2024, affected up to 190 million Americans and produced $2.8 billion in direct costs for UnitedHealth Group. What made it a systemic event rather than a single-institution incident was concentration: Change Healthcare processed approximately one-third of U.S. healthcare transactions. When one node failed, an entire sector found out how dependent it had become on a single clearinghouse it had never formally risk-assessed.
If your TPRM program ends at the contract level, you’re monitoring the vendors you see while the real concentration risk sits one layer behind them.
Why Fourth-Party Risk Is Hard to Measure
The core problem is visibility. You can send a vendor questionnaire to your core processor. You can review their SOC 2. You can conduct an annual due diligence review and call it done. But your core processor’s infrastructure may run on a hyperscale cloud provider you’ve never formally assessed, use a payment rail operator with no contractual relationship to you, and rely on a KYC subprocessor whose security controls you’ve never seen.
Traditional third-party risk programs measure what’s visible: questionnaire completion rates, SOC exceptions, incident notifications. Critical vendor KRI monitoring covers performance against SLAs and identified findings. But fourth-party risk requires a different posture—measuring the structure of the risk rather than the symptoms.
The June 2023 interagency guidance (OCC Bulletin 2023-17) explicitly addressed this. Responding to commenters who worried about infinite regress, the agencies clarified that banking organizations are not expected to assess every subcontractor directly. The focus is on evaluating whether your critical vendors have their own processes for managing subcontractor risk—and applying more scrutiny where concentration and criticality are high.
That’s the framing for fourth-party KRIs: you’re not auditing every fourth party. You’re measuring whether you know what concentration you have, whether your vendors are managing it, and whether you’d know before it became an incident.
The KRI Categories That Matter
Fourth-party risk KRIs fall into four practical categories: concentration exposure, structural visibility, incident propagation, and contract access.
Concentration Exposure KRIs
Hyperscale cloud concentration ratio. For your critical and high-risk vendors, what percentage rely on the same cloud provider (AWS, Azure, or GCP) for hosting their primary systems? A concentration ratio above 60–70% in a single provider means that provider’s availability is effectively a systemic dependency for your operations, even without a direct contract. DORA’s designation of 19 Critical ICT Third-Party Providers—with AWS, Azure, and Google Cloud widely expected among the named CTPPs—reflects exactly this concern. All three hyperscale providers experienced major global outages in 2025: AWS US-EAST-1 in October, Google Cloud’s authentication system in June, and Azure in both October and December.
| Threshold | Status | Action |
|---|---|---|
| <40% critical vendors on single provider | Green | Maintain monitoring |
| 40–60% critical vendors on single provider | Amber | Require vendor disclosure of fallback |
| >60% critical vendors on single provider | Red | Escalate to board; require exit plan verification |
Common subcontractor overlap count. How many of your critical vendors share the same material subcontractors outside of major cloud providers? A shared KYC provider, a shared payment rail, or a shared clearinghouse represents concentration risk that compounds across your vendor relationships. Tracking this number—even at a high level—quantifies your exposure to fourth-party cascade events.
Critical path fourth-party count. For each of your top-five critical services (payments processing, core banking, identity verification, regulatory reporting, customer communication), how many distinct fourth parties sit in the service delivery chain? A single critical function running through six fourth parties is a more complex risk profile than three critical functions each with one known subcontractor.
Structural Visibility KRIs
Subcontractor disclosure completion rate. Of your critical and high-risk vendors, what percentage have provided a list of material subcontractors touching your data, your customers, or your critical operations? This is the foundational metric. Without it, all downstream fourth-party KRIs are estimates.
Target: 100% of critical-tier vendors; 80%+ of high-risk vendors within 12 months of onboarding.
SOC report subservice organization (carve-out) count. When you review your vendors’ SOC 2 reports, how many subservice organizations are carved out—meaning the SOC 2 explicitly does not cover their controls? Each carve-out is a control gap you’re expected to address. Tracking carve-out counts across your vendor population shows whether your upstream oversight is contracting away assurance or maintaining it. A rising carve-out count is a governance KRI, not just a vendor-specific finding.
Vendor subcontractor management maturity score. When you ask critical vendors about their subcontractor oversight—do they have a vendor inventory for their own third parties? An annual review cadence? Notification obligations flowing down to subcontractors?—you can score their responses. A simple 1–5 maturity rating for your top vendors makes the population manageable and tracks changes over time.
Incident Propagation KRIs
Fourth-party-originated incident rate. Of all vendor incidents in the reporting period, what percentage originated in a subcontractor rather than the vendor itself? This KRI answers whether your vendor management is catching incidents at the right level. A rising fourth-party origin rate with low vendor incident rates suggests the vendor is not surfacing subcontractor problems until they’ve already affected your service. Third-party incident KRI monitoring covers the broader incident tracking framework; fourth-party origin tagging extends that to the subcontractor level.
Notification lag for fourth-party events. When a critical vendor’s subcontractor has a significant incident, how long does it take before you receive formal notification from the vendor? Contracts typically require 4–24 hours for initial notification. If you’re regularly finding out from customers before hearing from vendors, that’s a structural failure—the vendor either doesn’t know about their subcontractor’s problem in time, or doesn’t escalate it to you promptly.
Post-incident root cause attribution rate. Of significant vendor incidents, what percentage include a root cause disclosure identifying whether the incident originated with the vendor or a subcontractor? Vendors that consistently report “internal system issue” without specifying whether the root cause was a cloud provider, a subprocessor, or their own infrastructure are obscuring the fourth-party exposure your program needs to track.
Contract Access KRIs
Vendor contract flow-down coverage rate. What percentage of your critical vendor contracts include explicit requirements for the vendor to (1) notify you of material subcontractor changes, (2) flow down data security and privacy obligations to subcontractors, and (3) extend audit rights or SOC 2 coverage to subcontractors touching your data? Contracts signed before 2023 interagency guidance may lack these provisions. Tracking coverage and targeting renegotiation at renewal cycles is a governance KRI with a practical remediation path.
Subcontractor change notification response time. When vendors notify you that they’re adding, changing, or terminating a material subcontractor, how long does your internal review take? If the answer is “we don’t have a formal review process for that,” the KRI value is infinite—and the notification requirement in your contract is a paper obligation that your operational process doesn’t support.
How to Build These KRIs Without Boiling the Ocean
The common objection to fourth-party KRIs is scope: “We have 200 vendors. We can’t track all their subcontractors.” That’s the wrong starting point. Fourth-party risk programs are scoped to critical and high-risk vendors—typically the top 10–20% by criticality tier. That’s likely 20–40 vendors, not 200.
For those vendors:
-
Send a structured disclosure request. Ask for a list of material subcontractors touching your data or critical operations. “Material” means subcontractors whose failure would affect the services you’re purchasing. Not their office supplies vendor. Document which vendors respond, what they disclose, and any they flag as confidential (which is itself a data point).
-
Review SOC 2 subservice organization listings. Every SOC 2 Type 2 report that uses the carve-out method lists subservice organizations explicitly. Compile these listings for your critical vendors. Look for shared names—the same AWS environment, the same Twilio SMS provider, the same identity verification service appearing across multiple vendors is a concentration signal.
-
Add subcontractor change notification to your contract template. At the next renewal for each critical vendor, add a clause requiring 30-day advance notice of material subcontractor changes with your right to object. This is now standard language in post-OCC-2023-17 TPRM programs.
-
Track incidents by origin. When you log vendor incidents, add a field for “incident origin”—vendor, fourth-party subcontractor, or unknown. After two or three quarters, the distribution tells you whether your vendor incident reporting is capturing subcontractor exposure.
So What?
The fourth-party risk problem isn’t that your vendors use subcontractors—it’s that you don’t know which ones matter until they fail. Change Healthcare processed a third of U.S. healthcare transactions before anyone formally assessed what would happen if it went down. DORA’s designation of 19 Critical ICT Third-Party Providers is regulators saying explicitly: the hyperscale cloud concentration risk is real, visible, and now subject to direct oversight.
Your fourth-party KRI program doesn’t have to be complex to be defensible. Subcontractor disclosure completion rate and hyperscale cloud concentration ratio are numbers your TPRM program can track today, with the vendor data you can request in the next review cycle. They give you the data to make informed decisions about dependency, give your board a meaningful picture of concentration exposure, and give an examiner something more substantive than “we rely on our vendors to manage their subcontractors.”
The Third-Party Risk Management (TPRM) Kit includes a vendor inventory and concentration tracking template that extends to fourth-party disclosure tracking—so you’re not building the data structure from scratch. Get it at buy.stripe.com/14A14g8Bd01dazP4mO6J204.
Sources:
- OCC Bulletin 2023-17: Third-Party Relationships: Interagency Guidance on Risk Management
- DORA Critical ICT Third-Party Providers — Designations 2025
- Change Healthcare Data Breach — Panorays Analysis
- NYDFS Industry Letter: Guidance on Managing Risks Related to Third-Party Service Providers (October 21, 2025)
- DORA in 2026: Why Cloud Resilience Will Define Financial Services Compliance
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are fourth-party risk KRIs?
Do I have to monitor every fourth party?
What's the difference between fourth-party risk and cloud concentration risk?
How does DORA change fourth-party risk monitoring requirements?
What KRI should I start with if I've never tracked fourth-party risk before?
What should I do when a fourth-party KRI goes red?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026