Third-Party Due Diligence

Introduction
Registered Investment Advisers rely on outside vendors more than ever. Portfolio accounting platforms, cybersecurity providers, compliance consultants, data vendors, cloud systems, marketing agencies, outsourced chief compliance officers, and technology partners now play a major role in how advisory firms serve clients.
That reliance can improve efficiency, reduce costs, and give firms access to specialized expertise. But it also creates risk. If a vendor fails, mishandles client data, makes a material error, or cannot deliver a critical service, the adviser may still be responsible for the impact on clients.
That is the central message behind the SEC’s proposed outsourcing rule for investment advisers: outsourcing a task does not outsource the adviser’s fiduciary duty.
Although the SEC later withdrew the proposal, the framework remains a practical guide for how RIAs should think about third-party oversight, vendor governance, and compliance documentation. Advisers that build strong outsourcing controls today are better positioned for regulatory exams, operational resilience, and client trust.
What Was the SEC Proposed Outsourcing Rule?
The SEC’s proposed outsourcing rule was designed to require registered investment advisers to conduct due diligence before hiring certain service providers and to monitor those providers on an ongoing basis.
The proposal focused on outsourced services or functions that are necessary for the adviser to provide investment advisory services and that, if performed poorly or not performed at all, could materially harm clients.
In simple terms, the SEC wanted advisers to ask:
Are we outsourcing something important to client service, investment advice, operations, records, data, or compliance?
If the answer is yes, the adviser should have a documented process for selecting, reviewing, monitoring, and replacing that provider when necessary.
Why Outsourcing Compliance Matters for RIAs
Many RIAs assume that once a vendor is hired, the responsibility for that function shifts to the vendor. Regulators do not view it that way.
An adviser remains responsible for its obligations to clients. If a third-party provider creates a compliance failure, cybersecurity weakness, billing error, reporting issue, or disruption in client service, the adviser may still be expected to show that it acted reasonably.
Strong outsourcing compliance helps RIAs:
Protect client information and assets
Reduce operational and cybersecurity risks
Improve vendor accountability
Prepare for SEC examinations
Strengthen internal controls
Avoid overreliance on undocumented vendor relationships
Demonstrate a culture of compliance
For growing RIAs, vendor oversight should not be treated as an administrative task. It should be part of the firm’s risk management program.
Step 1: Identify Covered Outsourced Functions
The first step is to determine which outsourced services are significant enough to require enhanced oversight.
Examples may include:
Portfolio management systems
Trading and order management platforms
Client reporting tools
Compliance consulting
Cybersecurity and IT services
Cloud storage and data hosting
Billing and fee calculation systems
Performance reporting providers
Data aggregation tools
Recordkeeping vendors
Client communication or marketing technology
Not every vendor will require the same level of review. A janitorial service and a portfolio accounting platform do not present the same risk. RIAs should use a risk-based approach and focus the most attention on vendors that affect advisory services, client data, regulatory records, trading, billing, reporting, or business continuity.
Step 2: Create a Vendor Inventory
An RIA cannot monitor what it has not identified.
Firms should maintain a centralized vendor inventory that lists all key service providers. This inventory should include:
Vendor name
Service provided
Business owner inside the firm
Contract start date and renewal date
Type of client data accessed
Criticality level
Risk rating
Due diligence completion date
Ongoing monitoring schedule
Termination or contingency plan
This inventory should be reviewed regularly and updated whenever the firm adds, removes, or changes a provider.
A clean vendor inventory gives the firm visibility. It also helps during SEC exams because the adviser can quickly explain who its critical vendors are, what those vendors do, and how the firm supervises them.
Step 3: Perform Due Diligence Before Hiring a Vendor
Before hiring a critical service provider, RIAs should evaluate whether the provider is capable, reliable, secure, and appropriate for the outsourced function.
Due diligence should generally cover:
The vendor’s experience and qualifications
Financial stability
Reputation and regulatory history
Cybersecurity controls
Data privacy practices
Business continuity and disaster recovery plans
Staffing and service capacity
Conflicts of interest
Insurance coverage
Subcontractor use
Ability to meet regulatory and recordkeeping requirements
For technology vendors, cybersecurity review is especially important. RIAs should ask whether the provider has written information security policies, access controls, encryption, incident response procedures, penetration testing, and independent security assessments.
For compliance or operations vendors, the adviser should evaluate whether the provider understands the Advisers Act, fiduciary obligations, recordkeeping rules, and the firm’s specific business model.
Step 4: Document the Decision
Good compliance is not only about doing the right thing. It is also about being able to prove it.
RIAs should document why a vendor was selected and how the firm concluded that outsourcing the function was appropriate.
The file may include:
Due diligence questionnaires
Security reports
SOC reports, if available
Vendor presentations
Risk assessments
Contract reviews
References
Internal approval notes
Compliance sign-off
Legal review, if applicable
The goal is to create a clear record showing that the adviser made a thoughtful, informed decision before relying on the provider.
Step 5: Review Vendor Contracts Carefully
Vendor contracts should do more than set pricing. They should protect the adviser, the adviser’s clients, and the firm’s ability to meet regulatory obligations.
Important contract provisions may include:
Scope of services
Performance standards
Confidentiality obligations
Data protection requirements
Incident notification timelines
Business continuity commitments
Record access rights
Audit or review rights
Subcontractor restrictions
Termination rights
Transition assistance
Indemnification
Insurance requirements
RIAs should pay close attention to contracts that limit liability too aggressively, restrict access to important records, allow broad subcontracting, or fail to address data security.
The contract should make clear what the vendor is responsible for and what the adviser can do if the vendor fails to perform.
Step 6: Monitor Vendors on an Ongoing Basis
Due diligence should not end after the contract is signed.
RIAs should monitor critical vendors throughout the relationship. The frequency and depth of monitoring should depend on the vendor’s risk level.
Ongoing monitoring may include:
Annual due diligence reviews
Updated cybersecurity questionnaires
Review of SOC reports or security certifications
Service-level performance checks
Incident reports
Complaint tracking
Business continuity testing
Contract renewal reviews
Regulatory or litigation searches
Meetings with vendor representatives
If a vendor supports a high-risk or client-facing function, annual review may not be enough. The adviser may need more frequent monitoring, especially if the vendor handles sensitive client data, trading systems, billing, or compliance records.
Step 7: Build a Vendor Risk Rating System
A risk rating system helps RIAs prioritize oversight.
A simple model may classify vendors as high, medium, or low risk.
High-risk vendors may include providers that:
Access sensitive client information
Support trading or portfolio management
Calculate fees or performance
Maintain required books and records
Provide cybersecurity or IT infrastructure
Are difficult to replace quickly
Could materially disrupt client service if they fail
Medium-risk vendors may support business operations but have less direct impact on client outcomes.
Low-risk vendors may provide routine services with limited access to client information or regulatory records.
Each risk level should have defined review requirements. For example, high-risk vendors may require annual reviews, cybersecurity documentation, senior management approval, and a written contingency plan.
Step 8: Prepare a Contingency Plan
A key question for every RIA is: What happens if this vendor fails tomorrow?
Firms should create contingency plans for critical vendors. These plans may include:
Backup providers
Internal workarounds
Data retrieval procedures
Client communication plans
Transition steps
Contract termination process
Emergency contacts
Recovery timelines
A contingency plan does not need to be complicated, but it should be realistic. The adviser should know how it would continue serving clients if a major system, data provider, compliance vendor, or technology partner became unavailable.
Step 9: Update Compliance Policies and Procedures
Vendor oversight should be reflected in the adviser’s written compliance policies and procedures.
The policy should explain:
How the firm identifies critical vendors
Who is responsible for vendor oversight
How due diligence is conducted
How vendors are risk-rated
How often vendors are reviewed
What documentation must be retained
How issues are escalated
How vendor relationships are terminated
How the firm handles service disruptions
This helps turn vendor oversight from an informal practice into a repeatable compliance process.
Step 10: Train Employees on Vendor Oversight
Vendor risk is not only a compliance department issue.
Employees who select, manage, or interact with vendors should understand the firm’s process. This includes operations, technology, portfolio management, client service, finance, marketing, and compliance teams.
Training should help employees recognize when a vendor relationship requires review before engagement. For example, an employee should not be able to sign up for a new software platform that stores client data without compliance, legal, or security review.
Human error is one of the biggest weaknesses in vendor management. Training helps close that gap.
Practical Checklist for RIAs
RIAs can strengthen outsourcing compliance by taking the following steps:
Create a complete vendor inventory.
Identify vendors that support critical advisory functions.
Assign a risk rating to each vendor.
Conduct due diligence before engagement.
Review cybersecurity and data privacy controls.
Evaluate contracts for regulatory and operational protections.
Document the approval process.
Monitor vendors on a scheduled basis.
Maintain contingency plans for high-risk providers.
Update compliance policies and train employees.
This checklist can serve as a starting point for a practical vendor oversight program.
Common Mistakes RIAs Should Avoid
Many outsourcing issues come from process gaps rather than bad intentions.
Common mistakes include:
Hiring vendors without documented due diligence
Failing to review cybersecurity controls
Not knowing which vendors access client data
Treating all vendors the same regardless of risk
Allowing business teams to onboard software without compliance review
Forgetting to review vendors after the initial contract
Keeping outdated vendor lists
Ignoring subcontractor risk
Failing to plan for vendor failure
Not retaining records of vendor reviews
These mistakes can create regulatory, operational, and reputational risk.
Final Thoughts
The SEC’s proposed outsourcing rule sent a clear message to the advisory industry: RIAs must understand and supervise the third parties they rely on.
Even though the proposal was withdrawn, the underlying principle remains important. Advisers cannot simply hand off critical functions and assume the risk has disappeared. Clients expect their adviser to choose reliable providers, protect sensitive information, maintain service continuity, and respond quickly when something goes wrong.
For RIAs, the best approach is practical and proactive. Build a vendor inventory. Risk-rate service providers. Conduct due diligence. Review contracts. Monitor performance. Keep records. Prepare for disruption.
Outsourcing can help an advisory firm grow, but only when it is managed with discipline. A thoughtful vendor oversight program protects the firm, supports compliance, and reinforces the adviser’s fiduciary commitment to clients.
Latest
From the blog
The latest industry news, interviews, data responsibility, and AI technology.

Subscribe to our newsletter
Join our mailing list and stay updated

