Almost every adviser now runs on software and services it doesn't control. Portfolio accounting, CRM, custodial connections, email archiving, cybersecurity, the compliance stack itself. Each of those relationships is a place where an obligation you still own is being performed by someone else.

That's the whole premise of vendor due diligence for an RIA: outsourcing the function never outsources the responsibility. If a vendor loses client data, fails to retain records you're required to keep, or produces work that turns out to be wrong, the deficiency is yours.

Here's what to check before you sign, what belongs in the contract, and what you need to be able to show afterwards.

Start by tiering, not by listing

A full diligence exercise on every vendor is neither realistic nor expected. Sort them first, because the depth of review should follow the consequence of failure.

  • Critical. Holds client data, maintains required books and records, executes or reports on transactions, or performs a compliance function. Failure here is a regulatory event.
  • Important. Operationally significant but no client data and no records obligation. Failure disrupts the business without creating direct exposure.
  • Routine. Everything else. Note them, and move on.

Write the tiering logic down. A documented reason for reviewing one vendor lightly is a defensible position; no reason at all is not.

Pre-engagement diligence: what to actually collect

For anything in the critical tier, gather and keep the following before the relationship starts.

The firm itself

  • Corporate details, ownership, and how long they have operated
  • Financial stability — a vendor that fails commercially takes your data and records with it
  • Reference clients in the same regulatory context, and at least one conversation with one of them
  • Regulatory or litigation history relevant to the service

Information security

  • A current third-party audit or certification, such as SOC 2 Type II, read rather than just filed
  • Encryption in transit and at rest, access controls, and how privileged access is managed
  • Whether they use subcontractors, and where your data physically sits
  • Incident history and the actual notification process, including timeframes
  • Business continuity and disaster recovery arrangements, with recovery objectives that are stated rather than implied

Records and regulatory fit

  • Whether records they hold on your behalf meet your retention obligations in form and duration
  • How quickly you can extract your own data, in what format, and what happens on termination
  • Whether the vendor will make records available to your regulator if asked
  • For any vendor producing compliance work product, how their output is reviewed and by whom

What belongs in the contract

Diligence findings only protect you if they survive into the agreement. The clauses worth insisting on:

  • Confidentiality and permitted use — explicitly barring use of your data for the vendor's own purposes, including model training where relevant.
  • Breach notification with a defined timeframe, not “promptly.”
  • Data ownership and return — your data remains yours, is returned in usable form on termination, and is deleted afterwards.
  • Records access sufficient to meet your own obligations and any regulatory request.
  • Subcontractor limits — notice, and ideally consent, before your data moves further down the chain.
  • Audit or reporting rights, at minimum an annual right to current audit reports.
  • Service levels with a remedy attached, and clear termination rights.

Ongoing oversight is the part firms miss

Diligence at onboarding is comparatively easy. The recurring failure is a vendor engaged five years ago that nobody has looked at since — and it's exactly what an examiner will find, because the engagement date is on the contract.

An annual cycle for critical vendors is enough, and it doesn't need to be elaborate:

  • Obtain and read the current audit report; note any changed or qualified findings
  • Confirm nothing material has changed in ownership, subcontracting, or data location
  • Review any incidents, outages, or service failures over the year and how they were handled
  • Confirm the service still does what you're relying on it to do
  • Record the review, with a date and a conclusion

That last point is the one that counts. An oversight process you performed but didn't document reads, at exam, exactly like one you never performed.

The gaps that show up most often

  • No inventory — the firm cannot produce a complete list of who holds its data
  • Diligence performed informally at onboarding but never written down
  • A SOC 2 report collected once, filed, and never read or refreshed
  • No documented review of any vendor since engagement
  • Contracts silent on breach notification timing or data return
  • Sub-processors nobody at the firm is aware of

Where this fits

Vendor oversight isn't a standalone project. It belongs inside the annual compliance review, alongside policy currency, conflicts, and control testing — reviewed on the same cycle and documented in the same report.

Keeping that inventory current, and the evidence with it, is the kind of work we're building tools to carry. If this is something you're struggling with, we're here to help.