Your Supply Chain Risk Isn’t Where You Think It Is, The Hidden Exposure Beyond Tier 1 In Financial Services
In July 2024, a single faulty software update from CrowdStrike, a cybersecurity provider sitting two or three tiers below the firms it ultimately disrupted, brought down trading systems at JPMorgan Chase, disrupted data services at the London Stock Exchange, and rendered Bloomberg terminals inaccessible across the market. The firms affected had no direct relationship with CrowdStrike. It sat deeper inside their third-party technology stacks, invisible to standard third-party provider governance frameworks.
The FCA has since confirmed that over 40% of cyber and operational incidents reported to it in 2025 involved a third-party provider. Most Financial Services firms still cannot map their third-party provider ecosystem beyond their direct relationships. As a result, understanding critical dependencies beyond tier 1 providers is becoming as important as managing tier 1 providers themselves.Â
Where Does Risk Really Sit?
Risk in Financial Services supply chains does not reside where governance frameworks are often focused. The third-party providers related to core banking services, payments infrastructure, as well as cloud and data platforms receive management attention. However, the dependencies those third-party providers have on their own supply chains remain largely opaque.Â
Sphera’s 2025 survey of 500 senior procurement and supply chain leaders found that for most organisations, active third-party provider engagement ends at tier 1, and that 85% of significant supply chain incidents originate in the tiers below. For Financial Services firms, that is precisely where the next material failure is accumulating undetected.Â
Concentration amplifies the exposure. A small number of technology providers underpin the operating models of hundreds of regulated firms simultaneously – meaning a single point of failure carries systemic, not just firm-level, consequences.Â
What This Means For Financial Services Leaders
Operational resilience frameworks that stop at tier 1 providers leave organisations exposed. The firms best positioned to withstand third-party disruption are those that have invested time and effort to map, monitor and stress-test the layers their peers have not yet looked at.Â
There are five steps that procurement and risk teams need to take to strengthen resilience ahead of the next third-party provider failure:Â
1. Extend mapping beyond tier 1. Material dependencies frequently sit two or three tiers into the supply chain, well beyond the reach of standard third-party provider registers.Â
2. Shift to continuous monitoring. Periodic assessments cannot detect the conditions that precede an unplanned outage. Real-time surveillance of financial, cyber and operational indicators is now a baseline expectation.Â
3. Develop credible substitution options. For critical dependencies, dual sourcing strategies and pre-qualified alternatives must be identified, stress-tested, contractually enabled, and operationally ready – not theoretical options that are not practically available.Â
4. Prepare for the FCA’s new reporting regime. Final rules published in March 2026 require firms to register all material third-party arrangements annually from March 2027. The implementation window demands immediate action on supply chain documentation and governance.Â
5. Build sub-tier risk capability. Governance frameworks and monitoring tools are only as effective as the teams operating them. Procurement and risk functions need individuals who are genuinely curious about what sits beneath their direct third-party relationships – questioning assurances, mapping dependencies proactively, and escalating early.Â
How 4C Associates can helpÂ
If you would like to discuss how your organisation is managing third-party risk beyond tier 1, please reach out to Andy Hemsley , 4C Associates Managing Partner for Financial Services. Â
Talk to us today: Andy Hemsley, Rohit Namdeo, Agnieszka Abbott. Â
