I don't believe that exists. For withdrawals and DSRs, there should be an obligation for additional controllers to provider identifiers to the first-party/subject-facing controller. Otherwise, these mostly can't be executed. It gives third-party controllers an edge (again).
♥ 3