Get Reg S-P ready →

Reg S-P overviewService-provider oversight › Vendor checklist

Reg S-P vendor due diligence: what to request from each service provider, category by category

Published September 9, 2026 · official SEC sources linked below

The service-provider obligation is the one small advisory firms most often read, agree with, and then fail to act on — because the rule tells you to conduct due diligence and monitoring without telling you which of your vendors to start with or what to ask them for. This page is the missing operational half. It sorts the vendor categories a typical small RIA actually uses into tiers by whether they touch customer information, and for each one names the evidence to request and the contract term to look for.

The rule itself is covered on our service-provider oversight page. In short: your written policies and procedures must be reasonably designed to require oversight, including through due diligence and monitoring, of service providers — so that they take appropriate measures to protect against unauthorized access to or use of customer information, and so that they notify you as soon as possible and no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system. Those obligations have applied to smaller advisers since the June 3, 2026 compliance date.

Step 1: tier your vendors before you diligence any of them

Not every vendor deserves the same depth of review, and treating them equally is how small firms end up doing none of it. Sort your list into three tiers by a single question: can this vendor see, store, transmit, or dispose of customer information?

TierTestDepth of review
Tier 1Holds or processes customer information as a core function — it is the system of record or has standing access.Full evidence pack, contract term, annual re-review.
Tier 2Touches customer information incidentally, in transit, or only for some clients — often the category that surprises people.Evidence pack, contract term, review on renewal or on material change.
Tier 3No access to customer information at all, and no path to it.Document the determination itself — that is the diligence — and revisit if scope changes.

Write the tier assignment down with a one-line reason. An examiner asking about vendor oversight is asking to see a process, and “we assessed this vendor as having no access to customer information because it never receives client data” is a perfectly good answer — but only if it exists in writing before the question is asked.

Step 2: the category map

Categories below are the ones that recur at solo and small advisory firms. Your stack will not match exactly; the point is the shape of the question, not the list. Named tools appear only as examples of what a category is — nothing here is a statement about, or endorsement of, any vendor’s security posture or compliance.

Vendor categoryTypical tierWhat it touches / why
CustodianTier 1Account numbers, balances, SSNs, statements. Usually your largest concentration of customer information — and the vendor most likely to already have a mature security program you can simply document.
CRMTier 1Names, contact details, notes, often account numbers and scanned documents pasted into records over the years.
Portfolio management, performance reporting & billingTier 1Positions, balances, fee calculations tied to identified accounts. Billing files are frequently exported to spreadsheets — follow where those go.
Financial planning softwareTier 1Held-away account data, income, tax figures, dependents, sometimes aggregator credentials.
Email & productivity suiteTier 1The most under-inventoried Tier 1 vendor at small firms. Client email contains statements, tax documents and account numbers whether or not you intended it to.
Cloud file storage / document vaultTier 1Signed agreements, statements, identity documents. Check retention and deletion behavior, which ties directly to the disposal rule.
Email archiving & surveillanceTier 1By design holds a complete copy of everything above, often for years. Frequently omitted from vendor lists because it runs invisibly.
Outsourced IT / managed service providerTier 1Administrative access to everything. Depth of review should match that, including how their technicians authenticate and whether access is logged.
E-signatureTier 2Documents in transit and at rest, plus signer identity data. Often retains completed envelopes indefinitely by default.
Website forms, scheduling & lead captureTier 2The classic surprise. A “book a call” form collecting name, email and a free-text box is collecting consumer information — see consumer vs. customer.
AI notetakers / meeting transcriptionTier 2Records client meetings verbatim — frequently the single most sensitive unstructured data the firm produces. Ask specifically whether recordings or transcripts are used to train models, and where they are retained.
Outsourced compliance consultant, bookkeeper, or virtual assistantTier 2People, not platforms — but the rule speaks to service providers, not software. A contractor with mailbox or CRM access belongs on the list.

Step 3: the evidence pack to request

For every Tier 1 and Tier 2 vendor, ask for the same short list. Uniformity is the point: it makes the request easy to send, easy to repeat annually, and easy to show an examiner as a process rather than a series of one-offs.

  1. The vendor’s most recent independent security assessment — commonly a SOC 2 Type II report, with a bridge letter if the report period ended more than a few months ago. If the vendor has none, that is not automatically disqualifying; record what you received instead and why you found it reasonable.
  2. A written description of encryption in transit and at rest.
  3. Access controls — whether multi-factor authentication is available and enforced for your firm’s users, and how vendor-side administrative access is controlled.
  4. The subprocessor list — who they hand your data to. Your obligation follows the data, not the invoice.
  5. Breach-notification commitment — in writing, with a timeline (see the next section).
  6. Data return and deletion on termination — what happens to your client data when you leave, and on what timeline.
  7. Data location — where the data is stored and processed.

If a vendor won’t answer. Some small vendors simply will not respond to a security questionnaire. The rule asks for reasonable due diligence and monitoring, not for a guaranteed outcome. Document the request, the non-response, your assessment of the resulting risk, and what you decided to do about it — restrict what data the vendor receives, add a compensating control, or replace them. A documented decision is defensible; silence is not.

Step 4: the contract term that actually matters

Most vendor agreements already contain a security-incident clause. The question is whether it commits the vendor to a timeline that lets you meet your obligations. Two clocks have to line up:

ClockWhoTrigger
72 hoursYour service provider → youAs soon as possible, and no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system.
30 daysYou → affected individualsAs soon as practicable, and no later than 30 days after you become aware that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization — see what the notice must say.

A contract promising notice “promptly” or “within a commercially reasonable period” is the failure mode to look for. If a vendor takes three weeks to tell you, most of your own 30-day window is gone before you know it exists. When a vendor will not amend its standard terms — common with large platforms — record that, and note whether their published incident-response commitments get you there in practice.

The duty you cannot delegate. You may agree in writing that a service provider will send customer notices on your behalf. You remain responsible for whether that notice happens and whether it is adequate. Outsourcing the task never outsources the obligation.

Step 5: what goes in the file, and for how long

Vendor oversight is a recordkeeping obligation as much as a diligence one. For each Tier 1 and Tier 2 vendor keep, in one place:

Advisers keep records required under the amendments for five years, the first two in an easily accessible place. Practically, that means the vendor file should outlive the vendor relationship — do not delete the folder when you switch platforms.

A realistic cadence for a firm of one to ten people

  1. Once, now: build the vendor inventory and assign tiers. Most small firms find between eight and twenty vendors, and are surprised by two or three of them.
  2. Then, per Tier 1 vendor: request the evidence pack. Send them all in the same week; the replies arrive over a month.
  3. Annually: re-request the current security report and confirm the subprocessor list hasn’t materially changed.
  4. On event: re-review when you add a vendor, when a vendor is acquired, when you materially expand what data it receives, or when it discloses an incident.

AdviserLedger tracks your vendor inventory, tiers, evidence dates and review cadence in one place — so the file exists before an examiner asks for it.

See how it works →

Three traps worth naming

1. The vendor that didn’t touch client data until it did. Scheduling links, intake forms and AI notetakers are usually adopted by one person for convenience, without a tiering decision. Re-run the inventory when tools change, not only when clients do.

2. Subprocessors. Diligencing your CRM says nothing about the four services it hands data to. Ask for the list; note that it can change without your involvement, which is precisely why the annual re-check exists.

3. Treating diligence as a one-time project. The rule pairs due diligence with monitoring. A 2026 evidence pack with no review date is a snapshot, not a program — and the missing review date is the easiest thing for an examiner to spot.

Related guides

Official sources