Third-Party Due Diligence

How Registered Investment Advisers Can Prepare for SEC Outsourcing Expectations

How Registered Investment Advisers Can Prepare for SEC Outsourcing Expectations

How Registered Investment Advisers Can Prepare for SEC Outsourcing Expectations

How RIAs can strengthen vendor oversight through due diligence, monitoring, documentation, and risk-based outsourcing governance practices.

How RIAs can strengthen vendor oversight through due diligence, monitoring, documentation, and risk-based outsourcing governance practices.

Introduction

Registered Investment Advisers rely on outside vendors more than ever. Portfolio accounting platforms, cybersecurity providers, compliance consultants, data vendors, cloud systems, marketing agencies, outsourced chief compliance officers, and technology partners now play a major role in how advisory firms serve clients.

That reliance can improve efficiency, reduce costs, and give firms access to specialized expertise. But it also creates risk. If a vendor fails, mishandles client data, makes a material error, or cannot deliver a critical service, the adviser may still be responsible for the impact on clients.

That is the central message behind the SEC’s proposed outsourcing rule for investment advisers: outsourcing a task does not outsource the adviser’s fiduciary duty.

Although the SEC later withdrew the proposal, the framework remains a practical guide for how RIAs should think about third-party oversight, vendor governance, and compliance documentation. Advisers that build strong outsourcing controls today are better positioned for regulatory exams, operational resilience, and client trust.

What Was the SEC Proposed Outsourcing Rule?

The SEC’s proposed outsourcing rule was designed to require registered investment advisers to conduct due diligence before hiring certain service providers and to monitor those providers on an ongoing basis.

The proposal focused on outsourced services or functions that are necessary for the adviser to provide investment advisory services and that, if performed poorly or not performed at all, could materially harm clients.

In simple terms, the SEC wanted advisers to ask:

  • Are we outsourcing something important to client service, investment advice, operations, records, data, or compliance?

If the answer is yes, the adviser should have a documented process for selecting, reviewing, monitoring, and replacing that provider when necessary.

Why Outsourcing Compliance Matters for RIAs

Many RIAs assume that once a vendor is hired, the responsibility for that function shifts to the vendor. Regulators do not view it that way.

An adviser remains responsible for its obligations to clients. If a third-party provider creates a compliance failure, cybersecurity weakness, billing error, reporting issue, or disruption in client service, the adviser may still be expected to show that it acted reasonably.

Strong outsourcing compliance helps RIAs:

  • Protect client information and assets

  • Reduce operational and cybersecurity risks

  • Improve vendor accountability

  • Prepare for SEC examinations

  • Strengthen internal controls

  • Avoid overreliance on undocumented vendor relationships

  • Demonstrate a culture of compliance

For growing RIAs, vendor oversight should not be treated as an administrative task. It should be part of the firm’s risk management program.

Step 1: Identify Covered Outsourced Functions

The first step is to determine which outsourced services are significant enough to require enhanced oversight.

Examples may include:

  • Portfolio management systems

  • Trading and order management platforms

  • Client reporting tools

  • Compliance consulting

  • Cybersecurity and IT services

  • Cloud storage and data hosting

  • Billing and fee calculation systems

  • Performance reporting providers

  • Data aggregation tools

  • Recordkeeping vendors

  • Client communication or marketing technology

Not every vendor will require the same level of review. A janitorial service and a portfolio accounting platform do not present the same risk. RIAs should use a risk-based approach and focus the most attention on vendors that affect advisory services, client data, regulatory records, trading, billing, reporting, or business continuity.

Step 2: Create a Vendor Inventory

An RIA cannot monitor what it has not identified.

Firms should maintain a centralized vendor inventory that lists all key service providers. This inventory should include:

  • Vendor name

  • Service provided

  • Business owner inside the firm

  • Contract start date and renewal date

  • Type of client data accessed

  • Criticality level

  • Risk rating

  • Due diligence completion date

  • Ongoing monitoring schedule

  • Termination or contingency plan

This inventory should be reviewed regularly and updated whenever the firm adds, removes, or changes a provider.

A clean vendor inventory gives the firm visibility. It also helps during SEC exams because the adviser can quickly explain who its critical vendors are, what those vendors do, and how the firm supervises them.

Step 3: Perform Due Diligence Before Hiring a Vendor

Before hiring a critical service provider, RIAs should evaluate whether the provider is capable, reliable, secure, and appropriate for the outsourced function.

Due diligence should generally cover:

  • The vendor’s experience and qualifications

  • Financial stability

  • Reputation and regulatory history

  • Cybersecurity controls

  • Data privacy practices

  • Business continuity and disaster recovery plans

  • Staffing and service capacity

  • Conflicts of interest

  • Insurance coverage

  • Subcontractor use

  • Ability to meet regulatory and recordkeeping requirements

For technology vendors, cybersecurity review is especially important. RIAs should ask whether the provider has written information security policies, access controls, encryption, incident response procedures, penetration testing, and independent security assessments.

For compliance or operations vendors, the adviser should evaluate whether the provider understands the Advisers Act, fiduciary obligations, recordkeeping rules, and the firm’s specific business model.

Step 4: Document the Decision

Good compliance is not only about doing the right thing. It is also about being able to prove it.

RIAs should document why a vendor was selected and how the firm concluded that outsourcing the function was appropriate.

The file may include:

  • Due diligence questionnaires

  • Security reports

  • SOC reports, if available

  • Vendor presentations

  • Risk assessments

  • Contract reviews

  • References

  • Internal approval notes

  • Compliance sign-off

  • Legal review, if applicable

The goal is to create a clear record showing that the adviser made a thoughtful, informed decision before relying on the provider.

Step 5: Review Vendor Contracts Carefully

Vendor contracts should do more than set pricing. They should protect the adviser, the adviser’s clients, and the firm’s ability to meet regulatory obligations.

Important contract provisions may include:

  • Scope of services

  • Performance standards

  • Confidentiality obligations

  • Data protection requirements

  • Incident notification timelines

  • Business continuity commitments

  • Record access rights

  • Audit or review rights

  • Subcontractor restrictions

  • Termination rights

  • Transition assistance

  • Indemnification

  • Insurance requirements

RIAs should pay close attention to contracts that limit liability too aggressively, restrict access to important records, allow broad subcontracting, or fail to address data security.

The contract should make clear what the vendor is responsible for and what the adviser can do if the vendor fails to perform.

Step 6: Monitor Vendors on an Ongoing Basis

Due diligence should not end after the contract is signed.

RIAs should monitor critical vendors throughout the relationship. The frequency and depth of monitoring should depend on the vendor’s risk level.

Ongoing monitoring may include:

  • Annual due diligence reviews

  • Updated cybersecurity questionnaires

  • Review of SOC reports or security certifications

  • Service-level performance checks

  • Incident reports

  • Complaint tracking

  • Business continuity testing

  • Contract renewal reviews

  • Regulatory or litigation searches

  • Meetings with vendor representatives

If a vendor supports a high-risk or client-facing function, annual review may not be enough. The adviser may need more frequent monitoring, especially if the vendor handles sensitive client data, trading systems, billing, or compliance records.

Step 7: Build a Vendor Risk Rating System

A risk rating system helps RIAs prioritize oversight.

A simple model may classify vendors as high, medium, or low risk.

High-risk vendors may include providers that:

  • Access sensitive client information

  • Support trading or portfolio management

  • Calculate fees or performance

  • Maintain required books and records

  • Provide cybersecurity or IT infrastructure

  • Are difficult to replace quickly

  • Could materially disrupt client service if they fail

Medium-risk vendors may support business operations but have less direct impact on client outcomes.

Low-risk vendors may provide routine services with limited access to client information or regulatory records.

Each risk level should have defined review requirements. For example, high-risk vendors may require annual reviews, cybersecurity documentation, senior management approval, and a written contingency plan.

Step 8: Prepare a Contingency Plan

A key question for every RIA is: What happens if this vendor fails tomorrow?

Firms should create contingency plans for critical vendors. These plans may include:

  • Backup providers

  • Internal workarounds

  • Data retrieval procedures

  • Client communication plans

  • Transition steps

  • Contract termination process

  • Emergency contacts

  • Recovery timelines

A contingency plan does not need to be complicated, but it should be realistic. The adviser should know how it would continue serving clients if a major system, data provider, compliance vendor, or technology partner became unavailable.

Step 9: Update Compliance Policies and Procedures

Vendor oversight should be reflected in the adviser’s written compliance policies and procedures.

The policy should explain:

  • How the firm identifies critical vendors

  • Who is responsible for vendor oversight

  • How due diligence is conducted

  • How vendors are risk-rated

  • How often vendors are reviewed

  • What documentation must be retained

  • How issues are escalated

  • How vendor relationships are terminated

  • How the firm handles service disruptions

This helps turn vendor oversight from an informal practice into a repeatable compliance process.

Step 10: Train Employees on Vendor Oversight

Vendor risk is not only a compliance department issue.

Employees who select, manage, or interact with vendors should understand the firm’s process. This includes operations, technology, portfolio management, client service, finance, marketing, and compliance teams.

Training should help employees recognize when a vendor relationship requires review before engagement. For example, an employee should not be able to sign up for a new software platform that stores client data without compliance, legal, or security review.

Human error is one of the biggest weaknesses in vendor management. Training helps close that gap.

Practical Checklist for RIAs

RIAs can strengthen outsourcing compliance by taking the following steps:

  • Create a complete vendor inventory.

  • Identify vendors that support critical advisory functions.

  • Assign a risk rating to each vendor.

  • Conduct due diligence before engagement.

  • Review cybersecurity and data privacy controls.

  • Evaluate contracts for regulatory and operational protections.

  • Document the approval process.

  • Monitor vendors on a scheduled basis.

  • Maintain contingency plans for high-risk providers.

  • Update compliance policies and train employees.

This checklist can serve as a starting point for a practical vendor oversight program.

Common Mistakes RIAs Should Avoid

Many outsourcing issues come from process gaps rather than bad intentions.

Common mistakes include:

  • Hiring vendors without documented due diligence

  • Failing to review cybersecurity controls

  • Not knowing which vendors access client data

  • Treating all vendors the same regardless of risk

  • Allowing business teams to onboard software without compliance review

  • Forgetting to review vendors after the initial contract

  • Keeping outdated vendor lists

  • Ignoring subcontractor risk

  • Failing to plan for vendor failure

  • Not retaining records of vendor reviews

These mistakes can create regulatory, operational, and reputational risk.

Final Thoughts

The SEC’s proposed outsourcing rule sent a clear message to the advisory industry: RIAs must understand and supervise the third parties they rely on.

Even though the proposal was withdrawn, the underlying principle remains important. Advisers cannot simply hand off critical functions and assume the risk has disappeared. Clients expect their adviser to choose reliable providers, protect sensitive information, maintain service continuity, and respond quickly when something goes wrong.

For RIAs, the best approach is practical and proactive. Build a vendor inventory. Risk-rate service providers. Conduct due diligence. Review contracts. Monitor performance. Keep records. Prepare for disruption.

Outsourcing can help an advisory firm grow, but only when it is managed with discipline. A thoughtful vendor oversight program protects the firm, supports compliance, and reinforces the adviser’s fiduciary commitment to clients.

Subscribe to our newsletter

Join our mailing list and stay updated

Maximize Business Confidence, Minimize Effort.

Sky BlackBox is Intelligent Vendor Risk Management that maximizes business confidence while minimizing effort. With a suite of three integrated apps, it addresses VRM challenges for clients, vendors, and MSPs. Delivering 470x more accurate assessments, 6x lower operational costs, 9x faster results, 90% faster vendor onboarding, continuous vendor visibility, and scalable vendor intelligence across global ecosystems, Sky BlackBox turns risk into opportunity and elevates the entire vendor risk management process.

Sky BlackBox © L5, 100 Market St, Sydney, NSW 2000

Maximize Business Confidence, Minimize Effort.

Sky BlackBox is Intelligent Vendor Risk Management that maximizes business confidence while minimizing effort. With a suite of three integrated apps, it addresses VRM challenges for clients, vendors, and MSPs. Delivering 470x more accurate assessments, 6x lower operational costs, 9x faster results, 90% faster vendor onboarding, continuous vendor visibility, and scalable vendor intelligence across global ecosystems, Sky BlackBox turns risk into opportunity and elevates the entire vendor risk management process.

Sky BlackBox © L5, 100 Market St, Sydney, NSW 2000

Maximize Business Confidence, Minimize Effort.

Sky BlackBox is Intelligent Vendor Risk Management that maximizes business confidence while minimizing effort. With a suite of three integrated apps, it addresses VRM challenges for clients, vendors, and MSPs. Delivering 470x more accurate assessments, 6x lower operational costs, 9x faster results, 90% faster vendor onboarding, continuous vendor visibility, and scalable vendor intelligence across global ecosystems, Sky BlackBox turns risk into opportunity and elevates the entire vendor risk management process.

Sky BlackBox © L5, 100 Market St, Sydney, NSW 2000