Back to Insights

    Third-Party Service Provider Due Diligence Updates

    Enhanced SEC expectations for vendor oversight, cybersecurity assessments, and ongoing monitoring of outsourced compliance and technology providers.

    By NextReg Compliance Team
    November 1, 2025
    8 min read
    Vendor Due Diligence

    The Evolving Regulatory Landscape

    Investment advisers increasingly rely on third-party service providers for critical functions—portfolio accounting, compliance monitoring, cybersecurity, client communications, and trading execution. The SEC's heightened focus on vendor oversight reflects growing recognition that outsourcing operational functions doesn't outsource regulatory responsibility.

    Recent examination deficiency letters and enforcement actions demonstrate that inadequate vendor due diligence and monitoring can result in significant regulatory consequences, even when the adviser itself hasn't directly caused client harm.

    Initial Due Diligence Framework

    Pre-Engagement Assessment

    Before engaging a service provider, advisers should evaluate:

    • Financial Stability: Review audited financial statements, assess going-concern viability, and understand ownership structure
    • Operational Capabilities: Verify the provider has adequate resources, expertise, and capacity to deliver services reliably
    • Regulatory Compliance: For regulated providers (broker-dealers, transfer agents), review registration status and disciplinary history
    • Business Continuity: Assess disaster recovery plans, backup systems, and contingency arrangements
    • Insurance Coverage: Verify appropriate errors & omissions, cyber liability, and fidelity bond coverage

    Cybersecurity Assessment

    Given the sensitivity of client data, cybersecurity due diligence should include:

    • Review of SOC 2 Type II reports or equivalent third-party security audits
    • Assessment of data encryption standards (in transit and at rest)
    • Evaluation of access controls, multi-factor authentication, and privileged access management
    • Understanding of incident response procedures and breach notification protocols
    • Review of vendor's cybersecurity insurance coverage
    • Verification of employee background checks and security training programs

    Contractual Protections

    Essential Contract Provisions

    Service agreements should address:

    • Performance Standards: Specific service level agreements (SLAs) with measurable metrics and consequences for non-performance
    • Data Ownership and Protection: Clear assignment of data ownership, data handling requirements, and return/destruction obligations upon termination
    • Audit Rights: Adviser's right to audit vendor controls, access records, and review security protocols
    • Regulatory Cooperation: Vendor's obligation to cooperate with regulatory examinations and provide requested documentation
    • Notification Requirements: Timely notification of cybersecurity incidents, operational failures, or material changes in capabilities
    • Subcontracting Restrictions: Limitations on subcontracting critical functions without prior approval
    • Termination Rights: Ability to terminate for cause, with reasonable notice periods and data migration assistance

    Ongoing Monitoring and Oversight

    Periodic Performance Reviews

    Monitoring should be commensurate with the criticality of outsourced functions:

    • High-Risk Providers: Quarterly reviews of performance metrics, error rates, and cybersecurity posture
    • Moderate-Risk Providers: Semi-annual assessments of service delivery and control effectiveness
    • Lower-Risk Providers: Annual reviews of continued competence and regulatory compliance

    Key Performance Indicators

    Track metrics specific to each provider's function:

    • Administrators: Accuracy of NAV calculations, timeliness of reports, data reconciliation issues
    • Compliance Technology: System uptime, alert accuracy, false positive rates, support responsiveness
    • Cybersecurity Providers: Threat detection rates, incident response times, system vulnerability findings
    • Trading Platforms: Execution quality, system availability, pricing accuracy

    Specific Provider Categories

    Outsourced Chief Compliance Officers

    When outsourcing the CCO function, particular scrutiny is required:

    • Verify the designated CCO's qualifications, experience, and ongoing training
    • Ensure sufficient time allocation given the firm's size and complexity
    • Confirm the CCO has adequate authority and direct access to senior management
    • Review the scope of services to ensure all compliance functions are covered
    • Assess potential conflicts if the provider serves competitor firms

    Technology Vendors

    Portfolio management systems, CRM platforms, and compliance tools require:

    • Regular review of SOC reports and security certifications
    • Assessment of software update procedures and version control
    • Testing of data backup and recovery capabilities
    • Evaluation of vendor's product roadmap and ongoing development
    • Understanding of customer support structure and escalation procedures

    Documentation Requirements

    Due Diligence Files

    Maintain organized documentation including:

    • Initial due diligence memoranda supporting vendor selection decisions
    • Service agreements and all amendments
    • SOC reports, audit results, and security certifications
    • Periodic review documentation and performance assessments
    • Incident reports and remediation tracking
    • Board or management committee presentations regarding vendor relationships

    Annual Compliance Review Integration

    The annual compliance program review should specifically address:

    • Comprehensive inventory of all third-party service providers
    • Risk categorization of each vendor relationship
    • Confirmation that due diligence and monitoring occurred per policy
    • Assessment of whether vendor oversight policies remain adequate
    • Evaluation of any vendor-related incidents or deficiencies
    • Recommendations for improved vendor management processes

    SEC Examination Focus Areas

    Based on recent examination trends, the SEC is scrutinizing:

    • Initial Due Diligence: Whether advisers conducted reasonable due diligence before engaging vendors, especially for critical functions
    • Cybersecurity Assessments: Adequacy of vendor cybersecurity evaluation given the sensitivity of data accessed
    • Ongoing Monitoring: Evidence of periodic reviews commensurate with vendor risk profiles
    • Subcontracting Oversight: Whether advisers are aware of and monitoring vendors' subcontractors
    • Incident Management: How vendor-related incidents are identified, assessed, and addressed

    Key Takeaways

    • SEC expectations for vendor due diligence have significantly increased given RIAs' growing reliance on outsourced services
    • Initial due diligence should include financial, operational, regulatory, and cybersecurity assessments
    • Service agreements must include strong contractual protections around performance, data security, and audit rights
    • Ongoing monitoring should be risk-based, with more frequent reviews of critical service providers
    • Documentation of vendor selection, oversight, and incident management is essential for demonstrating regulatory compliance
    • Annual compliance reviews should specifically evaluate the effectiveness of vendor oversight processes