Vendor due diligence for RIAs and third-party vendor oversight

What vendor due diligence an RIA owes under Regulation S-P, Regulation S-ID and the compliance rule, how deep to go by risk, and how to document it.

Vendor due diligence is how an investment adviser shows that it looked at a service provider before relying on it, kept looking while the relationship lasted, and wrote down what it decided each time. Three rules reach it, and the custody rule adds oversight duties of its own toward custodians. Regulation S-P, since its 2024 amendments, requires an adviser’s policies to provide for oversight of service providers with access to customer information “including through due diligence and monitoring.” Regulation S-ID requires oversight of service provider arrangements for a firm that runs an identity theft program. And the compliance rule, Rule 206(4)-7, requires policies reasonably designed to prevent violations, which in Redan’s reading reach any provider doing work the adviser is responsible for.

This answer runs in five parts:

  • What the rules require: Regulation S-P, the custody rule, Regulation S-ID and the compliance rule, and what an examination may ask for.
  • Redan’s position on how deep the diligence should go, and how often to look again.
  • Documenting the decision: what the determination should say.
  • The record it should leave.
  • Frequently asked questions, then the sources.

What the rules require

Service providers that touch customer information. Rule 248.30(a)(5)(i) requires written policies and procedures “reasonably designed to require oversight, including through due diligence and monitoring, of service providers.” They must be reasonably designed to ensure that each service provider takes appropriate measures to protect against unauthorized access to or use of customer information, and to notify the adviser “as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider” (248.30(a)(5)(i)(A) and (B)).

A service provider, under Rule 248.30(d)(10), is any person or entity that “receives, maintains, processes, or otherwise is permitted access to customer information” through providing services directly to the adviser. The portfolio accounting system, the CRM, the email host, cloud document storage and the outsourced IT firm can all fall within it if client information passes through them. A provider that is itself a covered institution, such as a broker-dealer, is subject to Regulation S-P in its own right.

Rule 248.30(a)(5)(iii) says the obligation to make sure affected individuals are notified “rests with the covered institution,” whatever it has agreed with its providers.

The records. Rule 204-2(a)(25) requires an adviser to keep its service provider oversight policies and procedures (paragraph (a)(25)(iv)) and written documentation of any contract or agreement entered into under Rule 248.30(a)(5) (paragraph (a)(25)(v)).

Custodians. The custody rule carries its own oversight duties. An adviser with custody must have “a reasonable basis, after due inquiry,” for believing the qualified custodian sends account statements to clients at least quarterly (Rule 206(4)-2(a)(3)). Where the adviser or a related person acts as qualified custodian, it must obtain an internal control report from an independent public accountant at least once each calendar year (Rule 206(4)-2(a)(6)(ii)), and keep a copy (Rule 204-2(a)(17)(iii)).

Identity theft programs. Regulation S-ID applies to a registered adviser that is a financial institution or creditor as the Fair Credit Reporting Act defines those terms (Rule 248.201(a)(3)). Each such firm must periodically determine whether it offers or maintains covered accounts (248.201(c)), and one that does must run a written Identity Theft Prevention Program (248.201(d)(1)). Administering that program includes exercising “appropriate and effective oversight of service provider arrangements” (248.201(e)(4)). In its December 2022 observations on identity theft programs, the Division of Examinations reported firms that relied on service providers for activities connected with covered accounts but “did not evaluate the controls in place at the service provider to monitor for identity theft.”

Everything else a vendor does. The compliance rule, Rule 206(4)-7(a), requires written policies and procedures reasonably designed to prevent violations of the Advisers Act and its rules, and Rule 206(4)-7(b) requires an annual review of their adequacy and the effectiveness of their implementation. The rule does not name vendors. Redan’s reading is that where a provider performs something the adviser is responsible for, such as pricing, billing, trading systems or recordkeeping, oversight of that provider is how those policies reach the work. In its 2020 observations on adviser compliance programs, OCIE (now the Division of Examinations) listed “oversight of third-party service providers” among the areas where it saw deficiencies or weaknesses in advisers’ written policies and procedures, and “vendor management” among the cybersecurity areas.

What the adopting release adds

The Regulation S-P adopting release (Release No. IA-6604) chose policies and procedures over a mandatory written contract, and says two things about how oversight works in practice:

  • Assurances alone may not be enough. Receiving “reasonable assurances” from a service provider may help, but relying solely on them “may be insufficient depending on the facts and circumstances.”
  • Oversight continues. Covered institutions “generally should consider reviewing and updating these policies and procedures periodically throughout their relationship with a service provider, including updates designed to address any information learned during the course of their monitoring.”

What an examination asks for

The Division of Examinations’ 2023 risk alert on how it scopes adviser examinations lists documents staff may request, and one line reads: “Service providers and the services they perform.” Its fiscal year 2026 priorities say Regulation S-P and S-ID examinations will focus on firms’ policies and procedures, internal controls, “oversight of third-party vendors,” and governance practices.

Redan’s position: depth follows the data and the dependency

Depth follows the data and the dependency. Two questions set it: what is exposed if this vendor is breached, and what stops working if it goes away. A two-hundred-dollar tool holding client names and account numbers gets more scrutiny than a fifty-thousand-dollar tool that never sees client data.

Four tiers. Each vendor is rated low, medium, high or critical on those two questions. The compliance officer can move a vendor’s tier and writes down why. Even the lowest tier keeps the baseline physical security questions.

Uniform diligence is an examination risk, not only wasted time. A firm that tells an examiner all of its vendors are diligenced the same way regardless of risk has given the examiner a reason to test the rest of the program.

Every vendor, every year, scaled by tier. The annual vendor review covers the whole list. What each vendor gets depends on its tier:

TierEach year
Critical and highA full review: the questionnaire goes out again and is answered in full.
MediumA written attestation that nothing material has changed since the last full review, and a separate question on whether there have been any incidents.
LowA confirmation that nothing has changed and that there has been no breach.

An attestation or confirmation that reports a change or an incident ends the short route. The vendor gets a full review and its tier is reassessed.

Events don’t wait for the cycle. A breach or incident notice, a change of ownership, or a change in what data the vendor holds sends it to a full review and a tier check, whenever it happens. A vendor that reports an incident is no longer low risk. A vendor’s breach notice also starts the firm’s own incident response program when it arrives, as Regulation S-P requires.

A short review says why it was short. For a low-risk tool, a handful of questions is enough: who they are, what data they hold, whether they have a SOC 2 report or equivalent, and what happens to the firm’s data at termination. The file adds a note on why that was enough, and that note makes the short review defensible two years later. In a full review, a question the vendor answered badly last time stays in. “Not applicable” on a question that asked for a document, such as a policy or a contract clause, is an unanswered question and goes back.

Why most firms run a looser schedule. In practice, many firms review medium-risk vendors every two or three years and low-risk vendors only when something prompts it. That schedule usually reflects bandwidth. Sending, chasing and filing a questionnaire for every vendor by hand takes more hours than a small compliance team has, so the cycle stretches to fit the team.

Documenting the decision

The decision is what the firm concluded from its due diligence, and it is the part an examiner reads. A good determination says, in the compliance officer’s own words:

  • which vendor, what it does for the firm, and what data it holds;
  • the tier, and the reason for it, especially where the tier differs from what the ratings suggested;
  • what was asked, and what came back;
  • the gaps found, and what the firm accepted and why;
  • anything the vendor must fix, by when, and who checks;
  • when the vendor is next looked at; and
  • who decided, and when.

The record it should leave

For each vendor, the record should let a reader who was not there answer four questions: what the firm knew about this provider, when it knew it, what it decided, and why.

The record starts with the services the provider performs for the firm, the data it holds, and the risk tier assigned to it, with the reasoning behind that tier. It then sets out the questions put to the vendor, its answers as given, and what the firm made of them. The decision comes last, and it records the gaps the firm accepted and its reasons, any fixes the vendor owes with their deadlines and the person checking them, the date of the next review, and who decided and when, in that person’s own words. Where a review was kept short, the record says why that was enough.

Each review is dated and kept, so a later reader can see what the firm knew at the time it decided. Alongside the vendor files, Rule 204-2(a)(25) requires an adviser to keep its written service provider oversight policies and procedures, and any contract or agreement entered into under Rule 248.30(a)(5).

Frequently asked questions

What is vendor due diligence for an investment adviser? The work of assessing a service provider before relying on it, monitoring it during the relationship, and documenting what the firm decided. For providers with access to customer information, Rule 248.30(a)(5)(i) requires policies and procedures for oversight “including through due diligence and monitoring.”

Do investment advisers have to do vendor due diligence? For any service provider that receives, maintains, processes or has access to customer information, yes: Rule 248.30(a)(5). An adviser running an identity theft program must also oversee its service provider arrangements under Rule 248.201(e)(4). An adviser with custody must have a reasonable basis, after due inquiry, for believing the qualified custodian sends quarterly statements (Rule 206(4)-2(a)(3)). For other providers, the compliance rule, Rule 206(4)-7, requires policies reasonably designed to prevent violations. Redan’s reading is that oversight of a provider doing regulated work is part of how that is met, and OCIE’s 2020 observations list “oversight of third-party service providers” among the areas where it found advisers’ policies deficient or weak.

How often should vendors be reassessed? The rules and staff documents cited here set no general reassessment frequency. The nearest case is the custody rule: where the adviser or a related person acts as qualified custodian, it must obtain an accountant’s internal control report at least once each calendar year (Rule 206(4)-2(a)(6)(ii)). Redan’s position is every vendor once a year in the annual vendor review, with the depth set by the tier: a full review for critical and high, an attestation for medium, a no-change and no-breach confirmation for low, and a full review out of cycle on a breach, a change of ownership or a change in the data held. The adopting release for the Regulation S-P amendments says covered institutions generally should consider reviewing and updating their oversight policies periodically throughout the relationship.

What should a vendor due diligence file contain? The vendor, what it does and what data it holds; the tier and why; the questions asked and the answers received; the gaps and what was accepted; conditions to cure and their dates; the next review date; and a signed determination with the compliance officer’s reasoning. Rule 204-2(a)(25)(v) requires keeping any contract or agreement entered into under Rule 248.30(a)(5).

Is a SOC 2 report enough? Not by itself. Regulation S-P names no report. Of the rules cited here, the one that names a report is the custody rule’s internal control report, in the circumstances Rule 206(4)-2(a)(6) covers. The Regulation S-P adopting release says relying solely on a provider’s assurances “may be insufficient depending on the facts and circumstances.” A report is evidence in the file, and the determination is still the firm’s.

Sources

SourceWhat it supports here
17 CFR 248.30(a)(5) and (d)(10), as amended at 89 FR 47786Service provider oversight, the 72-hour notice, the definition of service provider
17 CFR 248.201(a)(3), (c), (d)(1) and (e)(4)Regulation S-ID’s scope and service provider oversight
17 CFR 275.204-2(a)(25)(iv) and (v)The oversight records
17 CFR 275.206(4)-7(a) and (b)The compliance rule and annual review. The rule does not mention vendors.
17 CFR 275.206(4)-2(a)(3), (a)(6) and (a)(6)(ii); 275.204-2(a)(17)(iii)The custody rule’s oversight of custodians
Release No. IA-6604, May 16, 2024Reasonable assurances, and periodic review of oversight
Risk alert, “OCIE Observations: Investment Adviser Compliance Programs,” November 19, 2020Oversight of third-party service providers as an observed weakness
Risk alert on identity theft prevention programs (Regulation S-ID), December 5, 2022The observation on service provider controls
Risk alert, “Investment Advisers: Assessing Risks, Scoping Examinations, and Requesting Documents,” September 6, 2023The document request line on service providers
SEC Division of Examinations, Fiscal Year 2026 Examination PrioritiesThe examination focus on third-party vendors
Redan’s positionsThe passages marked “Redan’s position”. Redan’s recommendations, labeled as such in the text