Cyber Prepared
← Third-Party Risk
Version 1.0Updated Sep 05, 2026

Fourth-Party Risk Mapping Guide

A repeatable method for identifying material subcontractors, concentration risks, and hidden dependencies in critical services. The document provides clear ownership, decision thresholds, implementation steps, evidence expectations, and a repeatable review cadence so teams can apply the guidance consistently under operational pressure.

fourth-partysuppliersconcentrationmapping
Inside the document
  1. 01Dependency discovery
  2. 02Materiality assessment
  3. 03Concentration analysis
  4. 04Control and contract review
  5. 05Risk treatment map

Built for accountable execution

A repeatable method for identifying material subcontractors, concentration risks, and hidden dependencies in critical services.

Included operating aids

  • Defined owners and decision points
  • Practical validation and evidence prompts
  • Escalation and exception guidance
  • A repeatable review and improvement cadence