Scrutineer · Vendor risk
Fourth-party risk management software and concentration risk
Your vendor's vendor caused the outage. You had no contract with them, no questionnaire from them, and no practical way to make anyone fix anything.
Scrutineer maps the subcontractors behind each critical vendor, shows where they concentrate, and tracks the contract terms that turn that map into leverage.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with fourth-party risk
The banking guidance everyone cites for concentration risk never uses the word
When a US vendor risk team justifies a concentration program to its board, it cites the Interagency Guidance on Third-Party Relationships that the Federal Reserve, FDIC and OCC issued on June 6, 2023 as OCC Bulletin 2023-17, SR 23-4 and FIL-29-2023. Search the text of that guidance for the word concentration and you will not find it. What it actually says sits in the due diligence section titled Reliance on Subcontractors, and it is narrower and more usable: evaluate whether additional risk is presented by the geographic location of a subcontractor or dependency on a single provider for multiple activities. One provider doing several jobs for you, and where those jobs physically happen. That is the test. The guidance also never says fourth party. It calls them subcontractors and treats them as part of the third-party relationship you already own, which is exactly why your leverage over them runs through your vendor contract instead of through any assessment you can send them.
The report that already lists your fourth parties is the one nobody reads to the end
Most teams buy discovery tooling to answer a question their filing cabinet already answers. When a SOC 2 audit involves subservice organizations, the usual treatment is the carve-out method: the report names each subservice organization, describes what it does, and states the controls the service organization assumes it performs, while the service auditor tests nothing at all at those organizations. Those assumed controls have a name, complementary subservice organization controls, and they are a disclosure requirement rather than a tested assertion. So the SOC 2 report you collected at onboarding already contains a list of your vendor's critical fourth parties plus an explicit written statement of what was never examined. Most vendor reviews capture the opinion type, the period covered and the exceptions, then stop. Reading the complementary subservice organization controls section is the cheapest fourth-party discovery there is, and the only thing it costs is attention.
Discovery is not leverage. Contract language is.
A dependency map tells you who is in the chain. It does not give you a single right you did not already have. The 2023 interagency guidance is unusually specific about where the rights come from, and every item is a contract clause: when and how the third party must notify you of its use or intent to use a subcontractor, whether specific subcontractors are prohibited outright, whether the contract bars assignment, transfer or subcontracting without your consent, reporting on the subcontractor's performance measures and audit results, a provision stating the third party's liability for the actions of its subcontractors, which side pays for the extra monitoring, and the right to terminate without penalty if the subcontracting arrangements breach the contract. New York regulators reached the same place at state level. The NYDFS industry letter of October 21, 2025 tells covered entities to require disclosure of subcontractor use, to keep the ability to reject specific subcontractors, and to evaluate the service provider's own service provider diligence process. That letter imposes no new rules, which is the point: examiners already expect this under Part 500, and Part 500 compliance cannot be delegated to a vendor.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Builds a chain view under each critical vendor, so a subcontractor that supports four of your suppliers stops looking like four unrelated relationships
- Pulls the named subservice organizations and complementary subservice organization controls out of every SOC 2 you hold, instead of leaving them in a PDF nobody opens
- Flags dependency on a single provider for multiple activities, which is the concentration test the interagency guidance actually states
- Tracks which contracts carry subcontractor notice, consent, prohibition, liability and termination language, and which ones give you no rights at all
- Keeps geographic location of subcontractors and the data they touch on the record, because the guidance treats location as a diligence factor in its own right
- Reassesses the chain when a vendor discloses a new subcontractor, rather than once a year at renewal when the disclosure is already stale
- Produces the documentation NYDFS examiners ask for on third-party governance, due diligence and contracting, from evidence you collected anyway
- Feeds the same control library your SOC 2, ISO 27001, HIPAA and FedRAMP work already runs on, so the fourth-party layer is not a separate program
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Fourth-party leverage reference
Who is really in the chain, and what you can actually do about each one
Nearly every fourth-party table published is a map: here are the tiers, here is who sits behind whom. A map does not change an outcome. The question that decides whether you can act is whether an obligation reaches that party at all, and through what. This table runs on contractual reach rather than visibility.
| Who is in the chain | Direct contract with you | How an obligation reaches them | Who can force a change | What you can verify today |
|---|---|---|---|---|
| The third party you signed | Yes | Directly, through your own agreement and your own questionnaire | You can, up to the limits of the contract | Everything you negotiated the right to see: audit reports, evidence, questionnaire responses, notification of incidents |
| A subcontractor named in the vendor contract | No | Through the flow-down clauses your vendor agreed to, and only those | Your vendor, if you ask and the clause supports it | Whatever the flow-down obliges the vendor to report on: performance measures, audit results, compliance with laws |
| A subcontractor added after signing, with no notice clause | No | Nothing reaches them. You are unaware the relationship exists | Nobody, because nobody at your organization knows to ask | Nothing, until an incident or a renewal questionnaire happens to reveal it |
| A subservice organization carved out of your vendor's SOC 2 | No | Through the complementary subservice organization controls your vendor assumes it performs | Your vendor, and only through its own commercial relationship | The name, the service and the assumed controls, all printed in the report. The service auditor tested none of them |
| The hyperscale cloud your vendor is built on | No, unless you separately buy from the same provider | Through published shared responsibility documentation and the provider's own audit reports | Effectively nobody at your scale. This one is a market structure, not a negotiation | The provider's SOC 2 and ISO certificates, region and data residency, and the parts of the responsibility split your vendor owns |
| An offshore development or support contractor | No | Through flow-down terms if they exist, plus whatever the vendor discloses about location | Your vendor, and in practice only before renewal | Location of the work and the data, which the interagency guidance names as a diligence factor on its own |
| A fourth party you first learn about from a breach notice | No | Nothing reached them beforehand. Everything is now remediation | Regulators and lawyers, on their timetable rather than yours | What the notice tells you, and what your own logs show about data that moved through the vendor |
Contract rights described here follow the Interagency Guidance on Third-Party Relationships issued June 6, 2023 by the Federal Reserve, FDIC and OCC, and the NYDFS industry letter on third-party service provider risk dated October 21, 2025. SOC 2 treatment follows the carve-out method under the AICPA attestation standards. Your own contracts govern what you can actually compel, so read them before relying on any row here. Scrutineer organizes readiness evidence and does not issue attestations or certifications.
Good questions
Questions about fourth-party risk
Keep reading
Guides that go deeper on this framework
Best fourth-party risk management software
The four categories of tooling sold against this problem, what each one can and cannot see, and the question that decides which you actually need.
Read the guideFourth-party risk explained
How exposure travels down the chain, why it surfaces late, and where the practical limits of tracing it sit.
Read the guideVendor tiering that holds up in an audit
How to tier suppliers by criticality so diligence depth matches exposure instead of contract value.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification