Your fourth party is the one that takes you down.
Most third-party programmes are questionnaire archives. Supervisors have stopped asking whether the questionnaire was returned and started asking whether the institution could keep operating without the provider. That is a resilience question, so it belongs in the same operating layer as everything else.
The lifecycle
Intake
Provider registered with service, data classes, jurisdictions and downstream dependencies captured at onboarding — not at renewal.
Criticality
Assessed against important business services, not spend. A low-cost provider inside a payment path is critical.
Substitutability
Time-to-replace, tested exit plan, and whether a credible alternative exists at institutional scale.
Concentration
Fourth-party mapping surfaces the cloud region, the model provider and the settlement rail three vendors deep.
Continuous monitoring
Provider posture, incident history and attestation currency tracked between reviews, not once a year.
Evidence
Contract clauses, audit reports, penetration test summaries and AI attestations bound to the control they satisfy.
Obligations it evidences
Register of information, contractual requirements, critical-provider designation and exit strategies.
Third-party risk lifecycle, criticality assessment and concentration reporting.
Model and AI provider governance where the model is supplied rather than built.
Supply-chain security measures for essential and important entities.
Third-party relationship lifecycle expectations for US banking organisations.
Obligations along the AI value chain where a provider becomes a deployer.