Skip to content
Nth-party intelligence

See the real blast radius before it reaches you

Your vendors run on the same clouds, processors and software. VendRisk360 maps fourth parties and subservice organizations, measures where your critical services concentrate, and shows exactly who is affected when one shared provider fails.

Relationship mapping

Your risk does not stop at the contract

Operational resilience regulators now ask about the chain, not just the counterparty. The platform builds the chain from evidence you already collect.

1st party

You

Your critical or important functions, business services and the data types they depend on.

3rd party

Your vendors

Each vendor record: services, tier, data types, contracts, evidence and findings.

4th+ party

Their providers

Subservice organizations from SOC reports and dependencies vendors disclose, each one shared across every vendor that uses it.

One entity per provider

A cloud platform named by twelve vendors is one node with twelve links, not twelve separate notes.

Direct and indirect paths

See whether a critical service depends on a provider directly, through a vendor, or through a vendor’s subservice organization.

Tied to your services and data

Each dependency connects to the vendor services, tiers and data types on the vendor record, so impact reads in terms of your operations.

Concentration and systemic risk

Find the single points of failure you did not choose

Concentration rarely comes from one decision. It accumulates, contract by contract, until a single provider sits under a third of your critical services.

  • Concentration by provider, by service type and by hosting region
  • Critical services that share a fourth party, highlighted
  • Systemic risk: providers whose failure would affect many of your vendors at once
  • Concentration Risk Briefing deck for the risk committee, from the same data
Blast-radius analysis

When a shared provider fails, who is affected?

These are the scenarios risk committees now ask about. Each one starts with a single provider and ends with a list of affected vendors, services and owners.

A shared cloud region goes down

Scenario
A hyperscaler region fails for several hours. Your core banking provider, your fraud screening vendor and your customer messaging platform all run there, through different contracts.
What VendRisk360 shows
Every vendor and critical service hosted in that region, the business services they support, and which of them have tested failover evidence on file.

A core processor is breached

Scenario
A payment or core processing provider used by many institutions discloses a breach. Some of your vendors rely on it indirectly as a subservice organization.
What VendRisk360 shows
Direct and indirect exposure through the fourth-party map, the data types involved at each vendor, and the owners who need to make notification decisions.

Widely used software is compromised

Scenario
A vulnerability is exploited in a file-transfer or remote-access product used across the industry.
What VendRisk360 shows
Vendors that disclosed the product as a dependency, their tier and data types, so outreach starts with the vendors that matter most.

A subservice organization’s SOC report has exceptions

Scenario
A data center operator carved out of three vendors’ SOC reports receives a qualified opinion.
What VendRisk360 shows
Each vendor that carves out the same subservice organization, and the CUECs and compensating controls you rely on.

Scenarios are generic illustrations and do not describe any specific provider or event.

CUEC tracking

The controls the SOC report assumes you run

Every SOC 1 and SOC 2 report lists complementary user entity controls. If you do not operate them, the auditor’s conclusion may not hold for you. Most programs never check.

Captured from every SOC report

CUECs are recorded during SOC review by your analyst, or captured by VendRisk360 assessors through Comprehensive Vendor Risk Assessment Services or a SOC Report Review.

Mapped to your own controls

Each CUEC is linked to the internal control and owner that satisfies it, so gaps are visible and assigned.

Tracked across vendors

The same CUEC in several reports maps to one internal control, so a gap is resolved once, not vendor by vendor.

Regulatory drivers

Why regulators now ask about the whole chain

Fourth-party and concentration risk moved from good practice to explicit expectation across major markets. VendRisk360 is aligned to these requirements; each organization remains responsible for its own compliance.

EU

DORA

The register of information records ICT third-party arrangements and the subcontractors supporting critical or important functions. Article 29 requires assessment of ICT concentration risk before contracting.

EU

EBA Guidelines on outsourcing

Sub-outsourcing of critical or important functions must be identified, approved and monitored, with the risks of the full chain assessed.

UK

PRA SS2/21

Material outsourcing and sub-outsourcing oversight, with concentration and exit considered as part of operational resilience.

Australia

APRA CPS 230

Material service providers must be identified and managed, including the risks from their own reliance on downstream providers, with concentration considered.

India

RBI

The Master Direction on outsourcing of IT services requires regulated entities to assess concentration risk and sub-contracting arrangements of service providers.

Singapore

MAS Guidelines on Outsourcing

Sub-contracting in material outsourcing must be assessed and controlled so oversight is not diluted.

Canada

OSFI Guideline B-10

Third-party risk management extends to subcontractors that support critical arrangements, with concentration risk assessed across the portfolio.

United States

OCC and Interagency Guidance

Due diligence and ongoing monitoring should consider a third party’s reliance on subcontractors, and concentration where many banks depend on the same provider.

See global regulatory coverage
FAQ

Frequently asked questions

What is nth-party risk?

Nth-party risk is the risk that comes from your vendors’ own vendors (fourth parties) and their providers in turn. A failure at a cloud platform, processor or software supplier you have never contracted with can still disrupt your critical services through the vendors that rely on it.

Where does fourth-party data come from?

VendRisk360 builds the relationship map from the subservice organizations named in SOC reports and from what vendors disclose in their questionnaires and evidence through the vendor portal. Each fourth party is one shared entity, linked to every vendor that relies on it.

How is concentration risk measured?

The platform counts how many of your vendors and critical services depend on the same provider, service or hosting region, and highlights where that dependence exceeds what you consider acceptable. The result feeds the Concentration Risk Briefing deck for the risk committee.

What is blast-radius analysis?

Blast-radius analysis starts from one failing provider and shows every vendor, critical service and business process that depends on it, directly or indirectly. It turns a news headline into a list of affected relationships and owners.

What are CUECs and why track them?

Complementary user entity controls are controls that a SOC report assumes the customer operates, such as reviewing user access or reconciling reports. If you do not operate them, the auditor’s conclusion may not hold for you. VendRisk360 lists each CUEC and maps it to your own control and owner.

Does this help with the DORA register of information?

Yes. The vendor and fourth-party records hold the ICT arrangements, supported functions and subcontracting chains the register draws on, and the data exports to Excel. Your compliance team remains responsible for the final submission and its format.

Get started

See VendRisk360 on your own vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.