Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Vendor security reviews · Fintech & financial services

Vendor Security Review & Questionnaire Support for Wealth Management & Robo-Advisors

This engagement runs in both directions. We diligence the vendors holding your client book, portfolio-management platforms, custodians, statement and mail-house providers, against what CSA Staff Notice 33-321 expects, and we help you answer the security questionnaires custodians and institutional allocators send back to you. Firms typically call before onboarding a new platform, before an ICPM partnership goes live, or when a DDQ lands with a deadline attached.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The vendor relationships that carry client wealth with them

Every system a registrant plugs into its operation is a custody decision about someone's KYC file or trade history. Review effort follows that sensitivity.

The portfolio-management platform

Croesus- or d1g1t-class platforms hold the consolidated book of record, so their access model, export controls and own security posture get the deepest review of any vendor relationship.

Custodians and carrying brokers

The institutions holding client assets and executing your instructions sit outside your direct control but inside your accountability, making their incident history and reporting commitments essential to understand.

FundSERV and order-flow connectivity

Any intermediary or gateway moving fund orders between your firm and FundSERV needs the same scrutiny applied to a system that can move money, because that is functionally what it does.

Statement and mail-house vendors

Providers producing and distributing client statements handle bulk exports of account data, exactly the kind of concentrated file transfer the MOVEit campaign showed can become an entire sector's weak point.

The robo tech stack behind an ICPM partnership

Where a portfolio manager licenses or white-labels a robo platform, the underlying vendor's onboarding questionnaire, KYC storage and AR-review workflow all become part of the diligence file before the partnership launches.

Regulatory map

Why vendor diligence is the registrant's job, not the vendor's

Outsourcing a system does not outsource accountability. Regulators and privacy law both expect the firm to have looked before it signed.

CSA Staff Notice 33-321's vendor due diligence pillar

The CSA's cyber guidance names vendor due diligence as a core element of a credible program, alongside policy, incident response and training, drawn from a survey of more than 1,000 firms.

Primary source →

NI 31-103 s. 11.1's controls do not stop at the vendor boundary

A system of controls and supervision has to account for functions the firm outsources, since the obligation belongs to the registrant regardless of who operates the underlying system.

Primary source →

PIPEDA accountability for processor-held data

Personal information handed to a portfolio platform, statement vendor or aggregator remains the firm's responsibility, and a vendor's breach becomes the firm's notification duty.

Read our guide →

Rule 3703's reach into third-party incidents

CIRO's incident reporting rule explicitly does not exclude incidents at a third-party service provider, which is exactly why the vendor's own incident-response commitments belong in your diligence file.

Primary source →

What goes wrong

Where unvetted vendors hurt wealth firms

Vendor risk here is concrete: it is the statement vendor moving bulk client files and the platform that concentrates your entire book behind one login.

  • A statement vendor exposed the way MOVEit exposed its users

    The 2023 MOVEit campaign showed how a widely used file-transfer tool exposed bulk personal data across many organizations at once, including government use affecting roughly 100,000 Nova Scotians. A statement or mail-house vendor moving your client files through similar tooling carries the same exposure.

    Source →

  • A portfolio platform with weak export controls

    A vendor that allows unrestricted bulk export of client data, without logging or approval, turns a single compromised advisor credential into a full book-of-record theft.

  • An ICPM partnership inheriting an unreviewed stack

    Licensing or white-labelling a robo platform without reviewing its KYC storage, consent flow and AR-review workflow means inheriting that vendor's weaknesses as your own regulatory exposure.

  • Vendor incident notice arriving too late for 3703

    Without a contractual notice window, a vendor may disclose an incident well after your own Rule 3703 clock should have started, leaving the firm exposed to a late-filing finding for a breach it did not cause.

Our vendor security reviews for wealth management & robo-advisors

What our review covers for a registrant

One engagement, two deliverable streams: a defensible vendor file for the systems you rely on, and credible answers for the custodians and allocators reviewing you.

Business performance checklist, Businessman using laptop online survey filling out check digital form task, business performance monitoring and evaluation. online survey question f
  1. Vendor due-diligence assessments

    Structured reviews of your portfolio platform, custodian, FundSERV connectivity and statement vendors, covering hosting, encryption, access controls, breach history and termination terms.

  2. Evidence evaluation

    We read the SOC 2 reports, security overviews and questionnaire responses vendors provide, translate what they actually attest to, and flag gaps marketing language tends to paper over.

  3. Contract terms guidance

    Recommended clauses for vendor agreements: breach-notification windows aligned to Rule 3703's clock, data residency, subcontractor disclosure and data return or destruction on exit.

  4. Custodian and allocator questionnaire support

    Gap review against what custodian diligence and allocator or consultant DDQs ask, plus internal review of draft answers before they go out.

  5. A reusable review framework

    A tiering model and templates the compliance team can apply the next time a platform or vendor relationship comes up for renewal.

How the engagement runs

How a review engagement runs for a wealth firm

  1. Step 1

    Build the vendor map

    We list every system touching client records, from the portfolio platform to the mail-house vendor, tier them by sensitivity, and pull existing contracts and security documentation.

  2. Step 2

    Assess the critical tier

    Platforms holding the book of record, custody relationships and statement distribution get full assessments, with vendor follow-ups where documentation is thin.

  3. Step 3

    Report and decide

    Findings arrive as decisions the firm can act on: accept, tighten the contract, adjust configuration or plan an exit, each with the reasoning recorded.

  4. Step 4

    Answer the other side

    With the vendor file in order, we help complete custodian diligence and allocator DDQs accurately, attaching evidence and handling follow-up questions.

What it costs

What determines vendor review pricing for a registrant

Scope drivers are the length of your vendor list, how many custodians and carrying brokers you work with, whether an ICPM partnership or new robo platform is under review, and the volume of DDQs your firm receives.

Vendor and third-party compliance oversight also comes standing inside the Virtual Privacy Office retainer. Share your vendor list and a sample questionnaire and we will scope the work.

Wealth Management & Robo-Advisors: Vendor security reviews questions, answered

Start with what the vendor can show in writing: hosting location, encryption at rest and in transit, access controls and export logging, incident history, and breach-notification commitments. For a custodian, add clarity on how incidents affecting your clients' assets are communicated to you and on what timeline, since that timeline feeds directly into your own Rule 3703 clock. We document the answers and flag anything the vendor cannot evidence.

Ask specifically about the file-transfer mechanism they use to move bulk statement data, whether it has been patched and monitored for known vulnerabilities, what encryption protects data in transit, and how quickly they would notify you of a compromise. MOVEit demonstrated that the transfer tool itself, not just the vendor's main platform, can be the weak point, so the diligence question has to reach that layer specifically.

Treat the licensed or white-labelled platform as an extension of your own regulated obligations. Review how the onboarding questionnaire collects and stores KYC data, how the workflow routes files to an advising representative for review under CSA Staff Notice 31-342, what access the platform vendor retains, and whether its incident-response commitments meet your Rule 3703 needs. The review should conclude before client onboarding starts, not after.

Ask for a current SOC 2 report or equivalent independent assessment where available, a security overview describing encryption and access controls, a data-residency statement, and a written breach-notification commitment with a specific timeline. Read the SOC 2 scope carefully: a report covering a different product line or an earlier version of the platform proves less than it appears to.

Priority terms include a breach-notification window fast enough to support your own Rule 3703 filing, data residency and subcontractor disclosure, restrictions on administrative access, confidentiality covering client personal information specifically, and a clear process for data return or destruction if the relationship ends. Many vendor relationships run on outdated agreements that predate current CSA guidance, and a review usually finds the contract is the biggest gap.

The questionnaire is about your firm's controls, and using an outside provider does not remove that responsibility. We work with your IT provider or MSP to pull specifics on what is configured and monitored, then translate that into answers you can sign honestly. Where the provider cannot evidence something the custodian requires, we turn it into a dated remediation item rather than an overstated answer that unravels under follow-up questions.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.