Scrutineer.ai

Scrutineer · Vendor risk

Fourth-party risk management software and concentration risk

Your vendor's vendor caused the outage. You had no contract with them, no questionnaire from them, and no practical way to make anyone fix anything.

Scrutineer maps the subcontractors behind each critical vendor, shows where they concentrate, and tracks the contract terms that turn that map into leverage.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with fourth-party risk

The banking guidance everyone cites for concentration risk never uses the word

When a US vendor risk team justifies a concentration program to its board, it cites the Interagency Guidance on Third-Party Relationships that the Federal Reserve, FDIC and OCC issued on June 6, 2023 as OCC Bulletin 2023-17, SR 23-4 and FIL-29-2023. Search the text of that guidance for the word concentration and you will not find it. What it actually says sits in the due diligence section titled Reliance on Subcontractors, and it is narrower and more usable: evaluate whether additional risk is presented by the geographic location of a subcontractor or dependency on a single provider for multiple activities. One provider doing several jobs for you, and where those jobs physically happen. That is the test. The guidance also never says fourth party. It calls them subcontractors and treats them as part of the third-party relationship you already own, which is exactly why your leverage over them runs through your vendor contract instead of through any assessment you can send them.

The report that already lists your fourth parties is the one nobody reads to the end

Most teams buy discovery tooling to answer a question their filing cabinet already answers. When a SOC 2 audit involves subservice organizations, the usual treatment is the carve-out method: the report names each subservice organization, describes what it does, and states the controls the service organization assumes it performs, while the service auditor tests nothing at all at those organizations. Those assumed controls have a name, complementary subservice organization controls, and they are a disclosure requirement rather than a tested assertion. So the SOC 2 report you collected at onboarding already contains a list of your vendor's critical fourth parties plus an explicit written statement of what was never examined. Most vendor reviews capture the opinion type, the period covered and the exceptions, then stop. Reading the complementary subservice organization controls section is the cheapest fourth-party discovery there is, and the only thing it costs is attention.

Discovery is not leverage. Contract language is.

A dependency map tells you who is in the chain. It does not give you a single right you did not already have. The 2023 interagency guidance is unusually specific about where the rights come from, and every item is a contract clause: when and how the third party must notify you of its use or intent to use a subcontractor, whether specific subcontractors are prohibited outright, whether the contract bars assignment, transfer or subcontracting without your consent, reporting on the subcontractor's performance measures and audit results, a provision stating the third party's liability for the actions of its subcontractors, which side pays for the extra monitoring, and the right to terminate without penalty if the subcontracting arrangements breach the contract. New York regulators reached the same place at state level. The NYDFS industry letter of October 21, 2025 tells covered entities to require disclosure of subcontractor use, to keep the ability to reject specific subcontractors, and to evaluate the service provider's own service provider diligence process. That letter imposes no new rules, which is the point: examiners already expect this under Part 500, and Part 500 compliance cannot be delegated to a vendor.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Builds a chain view under each critical vendor, so a subcontractor that supports four of your suppliers stops looking like four unrelated relationships
  • Pulls the named subservice organizations and complementary subservice organization controls out of every SOC 2 you hold, instead of leaving them in a PDF nobody opens
  • Flags dependency on a single provider for multiple activities, which is the concentration test the interagency guidance actually states
  • Tracks which contracts carry subcontractor notice, consent, prohibition, liability and termination language, and which ones give you no rights at all
  • Keeps geographic location of subcontractors and the data they touch on the record, because the guidance treats location as a diligence factor in its own right
  • Reassesses the chain when a vendor discloses a new subcontractor, rather than once a year at renewal when the disclosure is already stale
  • Produces the documentation NYDFS examiners ask for on third-party governance, due diligence and contracting, from evidence you collected anyway
  • Feeds the same control library your SOC 2, ISO 27001, HIPAA and FedRAMP work already runs on, so the fourth-party layer is not a separate program
FOURTH-PARTY RISK readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Fourth-party leverage reference

Who is really in the chain, and what you can actually do about each one

Nearly every fourth-party table published is a map: here are the tiers, here is who sits behind whom. A map does not change an outcome. The question that decides whether you can act is whether an obligation reaches that party at all, and through what. This table runs on contractual reach rather than visibility.

Who is in the chain Direct contract with you How an obligation reaches them Who can force a change What you can verify today
The third party you signed Yes Directly, through your own agreement and your own questionnaire You can, up to the limits of the contract Everything you negotiated the right to see: audit reports, evidence, questionnaire responses, notification of incidents
A subcontractor named in the vendor contract No Through the flow-down clauses your vendor agreed to, and only those Your vendor, if you ask and the clause supports it Whatever the flow-down obliges the vendor to report on: performance measures, audit results, compliance with laws
A subcontractor added after signing, with no notice clause No Nothing reaches them. You are unaware the relationship exists Nobody, because nobody at your organization knows to ask Nothing, until an incident or a renewal questionnaire happens to reveal it
A subservice organization carved out of your vendor's SOC 2 No Through the complementary subservice organization controls your vendor assumes it performs Your vendor, and only through its own commercial relationship The name, the service and the assumed controls, all printed in the report. The service auditor tested none of them
The hyperscale cloud your vendor is built on No, unless you separately buy from the same provider Through published shared responsibility documentation and the provider's own audit reports Effectively nobody at your scale. This one is a market structure, not a negotiation The provider's SOC 2 and ISO certificates, region and data residency, and the parts of the responsibility split your vendor owns
An offshore development or support contractor No Through flow-down terms if they exist, plus whatever the vendor discloses about location Your vendor, and in practice only before renewal Location of the work and the data, which the interagency guidance names as a diligence factor on its own
A fourth party you first learn about from a breach notice No Nothing reached them beforehand. Everything is now remediation Regulators and lawyers, on their timetable rather than yours What the notice tells you, and what your own logs show about data that moved through the vendor

Contract rights described here follow the Interagency Guidance on Third-Party Relationships issued June 6, 2023 by the Federal Reserve, FDIC and OCC, and the NYDFS industry letter on third-party service provider risk dated October 21, 2025. SOC 2 treatment follows the carve-out method under the AICPA attestation standards. Your own contracts govern what you can actually compel, so read them before relying on any row here. Scrutineer organizes readiness evidence and does not issue attestations or certifications.

Good questions

Questions about fourth-party risk

Fourth-party risk is the risk you inherit from your vendors' vendors: the subcontractors, cloud providers, data processors and support firms your direct suppliers rely on to deliver your service. You have no contract with them and usually no visibility into them, yet an outage or a breach at that layer reaches your customers exactly as if it had happened at your own vendor.
A third party is an organization you contract with directly. A fourth party is an organization your third party contracts with. The practical difference is leverage, not distance. You can assess, negotiate with and terminate a third party. With a fourth party you can only exercise rights your vendor agreed to pass down, which means the quality of your fourth-party program is decided by contract language, not by tooling.
Nth-party risk extends the same idea past the fourth layer to the whole dependency chain: your vendor's subcontractor's cloud provider's payment processor, and onward. In practice, useful nth-party work stops where materiality stops. Trace the chain until you reach parties whose failure would not interrupt a critical activity, then spend the remaining effort on the concentrations you already found.
Vendor concentration risk is exposure created when many of your critical activities depend on one provider, or when several of your suppliers quietly depend on the same underlying one. The 2023 interagency guidance frames it as dependency on a single provider for multiple activities. The second form is the dangerous one, because it looks like diversification on your vendor list and is not.
The Federal Reserve, FDIC and OCC do not use the term fourth party. Their June 2023 interagency guidance handles the same exposure under the heading Reliance on Subcontractors, and expects banking organizations to evaluate how a third party selects and oversees its subcontractors, whether those subcontractors implement effective controls, and whether the geographic location of a subcontractor adds risk. The obligation is real. The vocabulary is different.
Start with documents you already hold rather than with new questionnaires. Pull the named subservice organizations out of each vendor SOC 2, list the subcontractors disclosed in each contract, then ask your critical vendors directly for their subcontractor list and their own diligence process. Map which of those names appear behind more than one vendor. Only then decide where new assessment work is worth paying for.
Usually not, and it says so plainly. Under the carve-out method the report names each subservice organization and lists the controls assumed of it, but the service auditor performs no testing at that organization. Those assumed controls are called complementary subservice organization controls and are a disclosure rather than a tested assertion. The inclusive method does test them, and is far less common.
The 2023 interagency guidance names them specifically: notice of the use or intended use of a subcontractor, the right to prohibit named subcontractors, a bar on assignment, transfer or subcontracting without consent, reporting on subcontractor performance and audit results, the third party's liability for its subcontractors' actions, allocation of monitoring costs, and the right to terminate without penalty if subcontracting breaches the contract.
Four sources, in order of cost. The subservice organization section of the vendor's SOC 2. The subcontractor and flow-down clauses in your own contract. A direct written request to the vendor, which the NYDFS October 2025 guidance expects you to be making anyway. Then technical inference from DNS, certificates and integration scopes, which only ever sees internet-facing dependencies and misses payroll, offshore development and paper processes entirely.
Yes, indirectly and through contract. A business associate that passes protected health information to a subcontractor must obtain satisfactory assurances through a written agreement that the subcontractor will safeguard it, and since the 2013 Omnibus Rule those subcontractors are themselves directly liable under HIPAA. As a covered entity you enforce that chain through your business associate agreement rather than by assessing the subcontractor yourself.
The industry letter of October 21, 2025 walks through four stages of a third-party relationship: identification and due diligence, contracting, ongoing monitoring, and termination. On subcontractors it expects covered entities to require disclosure of subcontractor use, to keep the ability to reject specific subcontractors, and to evaluate the service provider's own diligence over its providers. It states that it imposes no new requirements, which means examiners already expect this under Part 500.
No. Scrutineer is readiness and evidence software, not an assessment firm, an auditor or a rating agency. It organizes what you already hold: the subservice organizations disclosed in vendor SOC 2 reports, the subcontractor terms in your contracts, the concentrations across your vendor list, and the evidence an examiner or auditor will ask to see. Your team keeps every decision about which relationships to accept, restrict or exit.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification