Reg S-P overview › Service-provider oversight › Vendor checklist
Published September 9, 2026 · official SEC sources linked below
The service-provider obligation is the one small advisory firms most often read, agree with, and then fail to act on — because the rule tells you to conduct due diligence and monitoring without telling you which of your vendors to start with or what to ask them for. This page is the missing operational half. It sorts the vendor categories a typical small RIA actually uses into tiers by whether they touch customer information, and for each one names the evidence to request and the contract term to look for.
The rule itself is covered on our service-provider oversight page. In short: your written policies and procedures must be reasonably designed to require oversight, including through due diligence and monitoring, of service providers — so that they take appropriate measures to protect against unauthorized access to or use of customer information, and so that they notify you as soon as possible and no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system. Those obligations have applied to smaller advisers since the June 3, 2026 compliance date.
Not every vendor deserves the same depth of review, and treating them equally is how small firms end up doing none of it. Sort your list into three tiers by a single question: can this vendor see, store, transmit, or dispose of customer information?
| Tier | Test | Depth of review |
|---|---|---|
| Tier 1 | Holds or processes customer information as a core function — it is the system of record or has standing access. | Full evidence pack, contract term, annual re-review. |
| Tier 2 | Touches customer information incidentally, in transit, or only for some clients — often the category that surprises people. | Evidence pack, contract term, review on renewal or on material change. |
| Tier 3 | No access to customer information at all, and no path to it. | Document the determination itself — that is the diligence — and revisit if scope changes. |
Write the tier assignment down with a one-line reason. An examiner asking about vendor oversight is asking to see a process, and “we assessed this vendor as having no access to customer information because it never receives client data” is a perfectly good answer — but only if it exists in writing before the question is asked.
Categories below are the ones that recur at solo and small advisory firms. Your stack will not match exactly; the point is the shape of the question, not the list. Named tools appear only as examples of what a category is — nothing here is a statement about, or endorsement of, any vendor’s security posture or compliance.
| Vendor category | Typical tier | What it touches / why |
|---|---|---|
| Custodian | Tier 1 | Account numbers, balances, SSNs, statements. Usually your largest concentration of customer information — and the vendor most likely to already have a mature security program you can simply document. |
| CRM | Tier 1 | Names, contact details, notes, often account numbers and scanned documents pasted into records over the years. |
| Portfolio management, performance reporting & billing | Tier 1 | Positions, balances, fee calculations tied to identified accounts. Billing files are frequently exported to spreadsheets — follow where those go. |
| Financial planning software | Tier 1 | Held-away account data, income, tax figures, dependents, sometimes aggregator credentials. |
| Email & productivity suite | Tier 1 | The most under-inventoried Tier 1 vendor at small firms. Client email contains statements, tax documents and account numbers whether or not you intended it to. |
| Cloud file storage / document vault | Tier 1 | Signed agreements, statements, identity documents. Check retention and deletion behavior, which ties directly to the disposal rule. |
| Email archiving & surveillance | Tier 1 | By design holds a complete copy of everything above, often for years. Frequently omitted from vendor lists because it runs invisibly. |
| Outsourced IT / managed service provider | Tier 1 | Administrative access to everything. Depth of review should match that, including how their technicians authenticate and whether access is logged. |
| E-signature | Tier 2 | Documents in transit and at rest, plus signer identity data. Often retains completed envelopes indefinitely by default. |
| Website forms, scheduling & lead capture | Tier 2 | The classic surprise. A “book a call” form collecting name, email and a free-text box is collecting consumer information — see consumer vs. customer. |
| AI notetakers / meeting transcription | Tier 2 | Records client meetings verbatim — frequently the single most sensitive unstructured data the firm produces. Ask specifically whether recordings or transcripts are used to train models, and where they are retained. |
| Outsourced compliance consultant, bookkeeper, or virtual assistant | Tier 2 | People, not platforms — but the rule speaks to service providers, not software. A contractor with mailbox or CRM access belongs on the list. |
For every Tier 1 and Tier 2 vendor, ask for the same short list. Uniformity is the point: it makes the request easy to send, easy to repeat annually, and easy to show an examiner as a process rather than a series of one-offs.
If a vendor won’t answer. Some small vendors simply will not respond to a security questionnaire. The rule asks for reasonable due diligence and monitoring, not for a guaranteed outcome. Document the request, the non-response, your assessment of the resulting risk, and what you decided to do about it — restrict what data the vendor receives, add a compensating control, or replace them. A documented decision is defensible; silence is not.
Most vendor agreements already contain a security-incident clause. The question is whether it commits the vendor to a timeline that lets you meet your obligations. Two clocks have to line up:
| Clock | Who | Trigger |
|---|---|---|
| 72 hours | Your service provider → you | As soon as possible, and no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system. |
| 30 days | You → affected individuals | As soon as practicable, and no later than 30 days after you become aware that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization — see what the notice must say. |
A contract promising notice “promptly” or “within a commercially reasonable period” is the failure mode to look for. If a vendor takes three weeks to tell you, most of your own 30-day window is gone before you know it exists. When a vendor will not amend its standard terms — common with large platforms — record that, and note whether their published incident-response commitments get you there in practice.
The duty you cannot delegate. You may agree in writing that a service provider will send customer notices on your behalf. You remain responsible for whether that notice happens and whether it is adequate. Outsourcing the task never outsources the obligation.
Vendor oversight is a recordkeeping obligation as much as a diligence one. For each Tier 1 and Tier 2 vendor keep, in one place:
Advisers keep records required under the amendments for five years, the first two in an easily accessible place. Practically, that means the vendor file should outlive the vendor relationship — do not delete the folder when you switch platforms.
AdviserLedger tracks your vendor inventory, tiers, evidence dates and review cadence in one place — so the file exists before an examiner asks for it.
See how it works →1. The vendor that didn’t touch client data until it did. Scheduling links, intake forms and AI notetakers are usually adopted by one person for convenience, without a tiering decision. Re-run the inventory when tools change, not only when clients do.
2. Subprocessors. Diligencing your CRM says nothing about the four services it hands data to. Ask for the list; note that it can change without your involvement, which is precisely why the annual re-check exists.
3. Treating diligence as a one-time project. The rule pairs due diligence with monitoring. A 2026 evidence pack with no review date is a snapshot, not a program — and the missing review date is the easiest thing for an examiner to spot.