Skip to main content
Category: Supply Chain Mapping

Sub-Outsourcing

Also known as: Sub-Outsourcing Chain, Subcontracting of Outsourced Services, Onward Outsourcing
Simply put

Sub-outsourcing happens when a service provider that has been hired to perform an outsourced task passes some or all of that task to another party further down the chain. In other words, your vendor does not do all the work itself but relies on additional downstream entities to deliver the service. This creates layers of providers beyond the one your organization directly contracts with.

Formal definition

Sub-outsourcing refers to a situation where a service provider under an outsourcing arrangement further transfers the whole or part of an outsourced process, service, or function to another entity, forming a layered chain of downstream providers on which delivery depends. It sits within the fourth-party and Nth-party risk domain: the sub-outsourced party has no direct contractual relationship with the outsourcing institution, so oversight typically depends on contractual flow-down terms, notification and approval rights, and audit or access provisions imposed on the direct service provider. Definitions and expectations vary by jurisdiction and sector; in financial services, for example, supervisory guidance (such as European regulatory guidelines on outsourcing) commonly addresses sub-outsourcing of critical or important functions, associated termination rights, and chain transparency. This term describes the arrangement itself and does not, on its own, confer visibility beyond the first tier, guarantee independent verification of downstream controls, or address whether the risk is information-security, operational, financial, or geopolitical in nature.

Why it matters

Sub-outsourcing extends the risk surface of an outsourcing relationship beyond the party an organization directly contracts with. When a service provider passes some or all of an outsourced task to a downstream entity, the sub-outsourced party has no direct contractual relationship with the outsourcing institution. As a result, the organization's ability to see, assess, and influence downstream controls typically depends on how well obligations are flowed down through the direct provider, rather than on any direct line of oversight. This is a defining characteristic of fourth-party and Nth-party risk: a control failure, disruption, or concentration can originate several layers away from the entity that was actually engaged.

The practical concern is loss of transparency and control across the chain. Contractual flow-down terms, notification and approval rights, and audit or access provisions are the primary levers available, but these are only as effective as the direct provider's willingness and ability to enforce them downstream. In regulated sectors, this gap is treated as material. In financial services, for example, European regulatory guidelines on outsourcing commonly address the sub-outsourcing of critical or important functions, including expectations around chain transparency and termination rights. Definitions and supervisory expectations vary by jurisdiction and sector, so what is required of one institution may differ from another operating under a different regime.

It is important to note what sub-outsourcing does not, on its own, provide. Recognizing that an arrangement involves sub-outsourcing does not confer visibility beyond the first tier, does not guarantee independent verification of downstream controls, and does not by itself specify whether the underlying risk is information-security, operational, financial, or geopolitical in nature. Treating the mere existence of flow-down clauses as equivalent to assured downstream oversight is a common overstatement to avoid.

Who it's relevant to

Third-Party Risk and Vendor Management Teams
These teams are responsible for building sub-outsourcing considerations into onboarding and contracting, including flow-down terms, notification and approval rights, and audit or access provisions. Because their direct relationship is with the first-tier provider, they must rely on these contractual levers to reach downstream entities they do not directly engage, and should be clear that such terms do not by themselves verify downstream controls.
Procurement and Contract Managers
Procurement functions negotiate the clauses that govern whether and how a provider may further transfer outsourced tasks, including approval requirements and, where relevant, termination rights tied to sub-outsourcing. They need to distinguish contractual rights on paper from the provider's demonstrated ability to enforce equivalent commitments across its own subcontractors.
Compliance and Regulatory Teams in Financial Services
In sectors where supervisory guidance addresses outsourcing, such as under European regulatory guidelines, compliance teams must track expectations around sub-outsourcing of critical or important functions, chain transparency, and termination rights. Because definitions and expectations vary by jurisdiction and sector, they should map requirements to the specific regimes that apply rather than assuming a single global standard.
Operational Resilience and Continuity Teams
These teams need to understand where delivery depends on downstream entities several layers removed from the direct provider, since disruption or concentration in the chain can affect service availability. Sub-outsourcing awareness alone does not reveal these dependencies; it signals the need to seek visibility beyond the first tier where the function is important enough to warrant it.

Inside Sub-Outsourcing

Onward Delegation of Contracted Services
Sub-outsourcing occurs when a direct third party (the outsourced service provider) delegates all or part of the contracted function to its own supplier. This creates a fourth-party relationship from the perspective of the originating organization, extending the chain beyond the direct contractual counterparty.
Material vs. Non-Material Sub-Outsourcing
Many programs distinguish sub-outsourcing that affects a material or critical function from arrangements that are ancillary. The distinction typically drives whether prior notification, approval rights, or enhanced due diligence apply, though the threshold for materiality varies by program and, in regulated sectors, by supervisory expectation.
Contractual Flow-Down Provisions
Clauses in the primary contract that require the third party to impose equivalent obligations (for example, security, confidentiality, audit, or continuity requirements) on any sub-outsourced provider. Flow-down provisions are a control mechanism but do not, on their own, give the originating organization a direct contractual relationship with the fourth party.
Notification and Approval Rights
Terms under which the third party must inform, or seek consent from, the originating organization before engaging or changing a sub-outsourced provider. Rights of this kind support oversight but their practical effectiveness depends on the third party's disclosure discipline and the visibility the originating organization actually obtains.
Visibility and Nth-Party Risk
Sub-outsourcing introduces fourth-party (and potentially Nth-party) risk, where the originating organization's insight typically diminishes with each additional tier. This can obscure concentration risk, single-source dependency, and geographic or geopolitical exposure that is not apparent at the direct third-party level.
Regulatory and Framework Context
Sub-outsourcing is addressed in guidance on outsourcing arrangements, particularly for financial services and other regulated sectors, and touches supplier-relationship standards such as ISO 27036 for information security. Expectations differ across jurisdictions and sectors, so requirements should be interpreted against the applicable regime rather than assumed to be uniform.

Common questions

Answers to the questions practitioners most commonly ask about Sub-Outsourcing.

Is sub-outsourcing the same as fourth-party risk?
Not exactly. Sub-outsourcing refers to the arrangement in which your direct third party delegates part of the outsourced function to another provider, while fourth-party (or Nth-party) risk describes the risk exposure arising from those downstream parties. In other words, sub-outsourcing is the contractual and operational act of delegation, and fourth-party risk is one consequence of it. The distinction matters because your organization typically holds no direct contractual relationship with the sub-outsourced provider, which limits your ability to impose controls or gain visibility beyond the first tier.
Does approving a sub-outsourcing arrangement transfer accountability to the third party?
No. In many programs and under various regulatory expectations, the contracting organization retains accountability for the outsourced function even when a third party sub-outsources part of it. Approval or notification rights govern how sub-outsourcing is managed, but they generally do not shift the underlying responsibility for outcomes, service quality, or compliance. The third party's accountability to you does not dissolve, and your accountability to your own regulators or customers typically does not pass through the chain either.
How can we maintain visibility into sub-outsourced providers we have no contract with?
Visibility usually depends on flow-down provisions in the primary contract, since you generally lack a direct relationship with the sub-outsourced party. Common approaches include requiring the third party to disclose material sub-outsourcing, maintain an inventory of its subcontractors, and pass down relevant obligations such as security, confidentiality, and audit rights. Even so, visibility beyond the first tier is often limited and depends on the third party's willingness and ability to report accurately, so residual blind spots typically remain.
What contractual provisions typically address sub-outsourcing?
Programs frequently rely on notification or prior-approval clauses for material sub-outsourcing, flow-down of key obligations (for example security, data protection, confidentiality, and business continuity requirements), audit and information rights that extend to sub-outsourced providers, and termination or step-in rights where sub-outsourcing introduces unacceptable risk. The specific mix depends on the risk tier of the function and, in regulated sectors, on applicable regulatory expectations, which vary across regions and industries.
How should sub-outsourcing be treated during due diligence and ongoing monitoring?
At onboarding, due diligence may include identifying whether and how a prospective third party sub-outsources critical functions and assessing its own governance over subcontractors. Because arrangements change over time, point-in-time due diligence can become stale, so ongoing monitoring typically seeks updates on new or changed sub-outsourcing. Depending on the program and risk tier, monitoring may rely on periodic attestations from the third party, which are self-reported and generally not the same as independent verification of the sub-outsourced provider.
How does sub-outsourcing affect concentration risk assessment?
Sub-outsourcing can obscure concentration risk because multiple third parties may, unknown to you, rely on the same downstream provider, creating a shared dependency that is not visible at the first tier. Assessing this typically requires mapping sub-outsourced providers across your portfolio where visibility allows. It is worth distinguishing concentration risk (aggregated reliance on a provider) from single-source dependency and single point of failure, since a sub-outsourced provider could contribute to any of these but they are not interchangeable concepts.

Common misconceptions

Flow-down clauses in the primary contract mean the originating organization can directly hold the sub-outsourced provider accountable.
Flow-down provisions oblige the direct third party to impose equivalent terms on its supplier, but the originating organization generally has no privity of contract with the fourth party. Accountability typically runs through the direct third party, and enforcement depends on that party honoring and policing the flow-down obligations.
Assessing the direct third party is sufficient to understand the risk of a sub-outsourced arrangement.
Direct third-party due diligence does not automatically capture fourth-party or Nth-party exposure. Visibility typically diminishes with each tier, so risks such as concentration, single-source dependency, or geographic exposure introduced by a sub-outsourced provider may remain hidden unless specifically surfaced.
A notification or approval right guarantees the originating organization will always know about sub-outsourcing.
Such rights depend on the third party's disclosure discipline and are only as effective as the visibility actually obtained. Undisclosed or informally changed sub-outsourcing can occur, and a contractual right does not by itself provide independent verification that all arrangements have been reported.

Best practices

Include explicit flow-down provisions in primary contracts that require the third party to impose equivalent security, confidentiality, audit, and continuity obligations on any sub-outsourced provider, and confirm those obligations are actually passed through.
Establish notification and, where warranted for material or critical functions, prior-approval rights for sub-outsourcing, and calibrate the trigger for these rights to the risk tier of the affected function.
Extend due diligence and monitoring beyond the direct third party to identify fourth-party and Nth-party dependencies, treating point-in-time reviews as needing periodic refresh rather than one-time assurance.
Map sub-outsourced arrangements to surface concentration risk, single-source dependency, and geographic or geopolitical exposure that is not visible at the direct third-party tier.
Interpret sub-outsourcing requirements against the applicable jurisdictional and sector-specific regime, recognizing that supervisory expectations for regulated functions differ across regions.
Do not rely solely on the third party's self-reported disclosures; where feasible, seek independent evidence that sub-outsourcing has been reported and that flow-down controls are operating.
Promotional banner for the Pentest Readiness checklist download