Fourth-Party Dependency Mapper
Finds the subcontractors, platforms and locations beneath a direct provider.
Combines disclosed subcontractors, architecture, network telemetry, bills of materials, contracts and external intelligence into a confidence-scored dependency chain. It exposes shared cloud, telecom, data and specialist-service dependencies while preserving unknowns instead of inventing a complete supply chain.
Authority
Inform
Team role
Provides specialist analysis
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Contracts, Fourth Parties & Regulatory Registers
Desk workflow
Diligence findings, then resilience clause review, then fourth-party mapping, then DORA and internal register updates, then legal and owner attestation.
Collaboration
Works within a defined desk workflow
Decision boundary
Provides evidence or analysis without committing the decision.
Systems and capabilities involved
Vendor subcontractor disclosures
Architecture and network inventory
Software and service bills of materials
External entity intelligence
Handoffs
What this role gives and receives
Capabilities offered
Map fourth-party dependencies
Build a confidence-scored subcontractor and infrastructure chain.
- Receives:
- Vendor, contracted service, disclosures, architecture and evidence scope
- Returns:
- Dependency graph, shared nodes, changes, locations and unknowns
Handoff to
Handoff to
Handoff to
Receives from
Receives from
External handoff
Vendor management
External handoff
Enterprise architecture
External handoff
Cyber supply-chain risk
Context
What the role needs to do the work
- Current work
- Provider, service, candidate fourth parties, evidence and unresolved edges.
- Prior interactions
- Prior disclosures, provider changes and incident-confirmed dependencies.
- Policies and reference
- Corporate entities, cloud regions, service taxonomy and infrastructure providers.
- Working method
- Dependency confidence, materiality and notification rules.
Illustrative workflow
How the work moves
Starting point
A provider announces a new subprocessor for identity verification.
- 01
Resolve the subprocessor entity, service, locations and upstream infrastructure.
- 02
Link affected contracts and important business services.
- 03
Recalculate concentration and trigger contract-notice review.
Result
Updated dependency graph with two affected services and one new concentration signal.
Checks and boundaries
What must be tested or reviewed
- 01Identifies a shared cloud region beneath two differently branded SaaS vendors.
- 02Labels an inferred subcontractor edge as unconfirmed when only DNS evidence exists.
- 03Alerts on a material hosting-location change without treating an entity rename as a new provider.
Human authority
- Vendor confirms material inferred dependencies
- Risk owner accepts unresolved opacity
Keep exploring