Third-Party Risk for RIAs: Beyond the Annual Questionnaire

August 26, 2026

Registered investment advisers face growing cybersecurity pressure not just from their own systems, but from every vendor and platform they depend on. The SEC’s updated Safeguards Rule now requires third-party service providers to report breaches within 72 hours. An annual questionnaire is a compliance box, not a risk control.

Why It Matters

RIA firms run on a stack of third-party tools. Custodians, portfolio management platforms, financial planning software, CRM systems, and compliance technology all touch client data in some form. When any one of those vendors is breached, the exposure follows the data, not the firewall.

The SEC’s 2024 amendments to Regulation S-P formalized what security professionals have argued for years: third-party relationships are a first-class risk category, not a vendor management footnote. Under the updated rule, covered institutions, including most RIAs, must ensure their service providers contractually commit to reporting security incidents involving customer data within 72 hours.

That single requirement signals a meaningful shift in expectations. Regulators are no longer satisfied with annual reviews and attestation forms. They want firms to have real-time accountability built into vendor relationships from the contract stage forward.

How Third-Party Breaches Actually Happen

Most third-party incidents at financial firms follow one of three patterns.

The first is a compromised client-facing platform. Vendors who host client login pages, document vaults, or reporting dashboards are attractive targets because they sit between the firm and the client. A breach there can expose client credentials, account data, and contact information without the RIA ever being the direct target.

The second is a software supply chain attack. An attacker infiltrates a vendor’s codebase or deployment pipeline and pushes malicious updates to every firm using the platform. By the time the breach is detected, it may have been active for weeks, touching multiple client firms simultaneously.

The third is a subcontractor gap. Many technology vendors subcontract infrastructure, development, or support functions to other companies. RIAs typically have no visibility into those relationships. The annual questionnaire goes to the primary vendor. The breach often originates one layer below.

Firms of every size have experienced breaches traced to compromised third-party systems, including custodians and portfolio reporting platforms. In each case, the firm had completed its standard vendor review. The paperwork was clean. The risk was not.

What Companies Can Do

A complete third-party risk program goes well beyond the annual review cycle. Here is what it actually includes.

Start with vendor tiering. Not every vendor carries the same risk. A platform with read-only access to aggregated reporting data is different from one that processes transactions or stores account credentials. Tiering vendors by access level and data sensitivity lets you apply proportional scrutiny and avoid spending the same review effort on every tool in your stack.

Build incident notification requirements into contracts. The SEC’s 72-hour window is a regulatory floor, not a security benchmark. Contracts with high-tier vendors should include specific notification timelines, escalation contacts, documentation requirements for any security incident, and provisions covering subcontractors that access client data on the vendor’s behalf.

Ask about subcontractors directly. Standard questionnaires rarely surface the full vendor ecosystem. For any vendor handling client data, ask explicitly: who else has access, what infrastructure are you running on, and do you subcontract development or support functions? If the answer is vague, treat that as a signal worth following up on.

Conduct periodic mid-cycle checks, not just annual reviews. A questionnaire captures a moment in time. Between annual cycles, vendors change their cloud infrastructure, their personnel, and their security controls. A brief mid-year check-in or a review of updated SOC 2 reports closes some of that gap without requiring a full reassessment.

For more on how financial firms get targeted through process gaps, see Finance Data Security: The Breach Risk Most Companies Miss.

How an MSP Helps

Most RIA firms do not have dedicated security staff reviewing third-party risk on a rolling basis. That function typically falls to the COO or compliance officer, or it does not get done with much consistency.

An MSP with financial services experience brings structure to what is otherwise an informal process. That includes maintaining a current vendor inventory with assigned risk tiers, tracking SOC 2 report expiration dates and following up when reports go stale, reviewing vendor-issued security advisories, and flagging contract language that lacks appropriate incident notification provisions.

An MSP also provides external perspective on what high-risk vendor relationships actually look like in practice. Firms that have not experienced a third-party incident tend to underestimate the exposure. A provider that has seen how breaches propagate through vendor networks can help set realistic expectations and appropriate controls before a problem occurs.

Read: IT Services for Registered Investment Advisers

Best Practices and Key Takeaways

Third-party risk for RIAs is a continuous process, not an annual event. The controls that matter most are the ones that keep your vendor relationships visible between formal review cycles.

Maintain a live vendor inventory. Know who has access to what, and at what level, at all times. Changes in vendor technology, personnel, and infrastructure happen frequently enough that a static document is outdated within months.

Require contractual incident notification. Regulatory compliance now demands it. Beyond compliance, you need to know when something goes wrong in a vendor environment before it becomes public, and before you are explaining to clients why you found out late.

Review SOC 2 Type II reports annually. A SOC 2 report tells you whether a vendor’s security controls were actually tested over a defined period, not just described. A Type II report covers a span of time, not a single point-in-time assessment. If a vendor cannot provide one, treat that as a risk flag worth investigating further.

Test your own incident response plan with third-party scenarios. The most common gap in RIA incident response plans is that they only model direct attacks on the firm. A scenario where a vendor notifies you of a breach, including what your first 72 hours look like, should be part of your regular planning review.

Read: Core Managed Cyber Risk Assessment

Frequently Asked Questions

What does the SEC’s updated Safeguards Rule require from RIAs on third-party risk?

The SEC’s 2024 amendments to Regulation S-P require covered institutions, including most RIAs, to ensure that service providers handling customer information contractually agree to report security incidents involving that data within 72 hours. Firms must also maintain written policies and procedures for responding to those notifications and for assessing ongoing third-party risk.

Is an annual vendor questionnaire enough to satisfy SEC expectations?

An annual questionnaire satisfies some documentation requirements, but it does not constitute a complete third-party risk program under the updated Safeguards Rule. The SEC expects firms to have ongoing monitoring, contractual notification requirements, and incident response procedures that specifically address vendor breach scenarios, not just direct attacks on the firm’s own systems.

What should a vendor security contract provision include?

At minimum, vendor security provisions should specify a notification timeline for breaches, the types of incidents that trigger notification, escalation contacts on both sides, documentation requirements for the incident, and explicit language covering subcontractors that handle client data on the vendor’s behalf. Blanket indemnification clauses are not a substitute for specific notification and response obligations.

How do RIA firms handle third-party risk without a dedicated IT team?

Many RIA firms manage third-party risk through a combination of their compliance officer and an outside IT partner. An MSP can take on the technical components of vendor monitoring, SOC 2 review, and contract language assessment, while the compliance officer retains responsibility for regulatory documentation and SEC-facing reporting. Splitting those functions clearly prevents gaps from forming between the two roles.

For more on how MSPs turn IT challenges into competitive advantages, read our feature in the Atlanta Business Chronicle.

Protecting your business starts with the right partner. Core Managed helps companies secure their data, scale efficiently, and stay compliant so you can focus on running the business. Give us a call at 888-890-2673 or contact us to schedule a conversation.