Vendor security reviews · Fintech & financial services
Vendor Security Review & Questionnaire Support for Wealth Management & Robo-Advisors
This engagement runs in both directions. We diligence the vendors holding your client book, portfolio-management platforms, custodians, statement and mail-house providers, against what CSA Staff Notice 33-321 expects, and we help you answer the security questionnaires custodians and institutional allocators send back to you. Firms typically call before onboarding a new platform, before an ICPM partnership goes live, or when a DDQ lands with a deadline attached.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The vendor relationships that carry client wealth with them
Every system a registrant plugs into its operation is a custody decision about someone's KYC file or trade history. Review effort follows that sensitivity.
The portfolio-management platform
Croesus- or d1g1t-class platforms hold the consolidated book of record, so their access model, export controls and own security posture get the deepest review of any vendor relationship.
Custodians and carrying brokers
The institutions holding client assets and executing your instructions sit outside your direct control but inside your accountability, making their incident history and reporting commitments essential to understand.
FundSERV and order-flow connectivity
Any intermediary or gateway moving fund orders between your firm and FundSERV needs the same scrutiny applied to a system that can move money, because that is functionally what it does.
Statement and mail-house vendors
Providers producing and distributing client statements handle bulk exports of account data, exactly the kind of concentrated file transfer the MOVEit campaign showed can become an entire sector's weak point.
The robo tech stack behind an ICPM partnership
Where a portfolio manager licenses or white-labels a robo platform, the underlying vendor's onboarding questionnaire, KYC storage and AR-review workflow all become part of the diligence file before the partnership launches.
Regulatory map
Why vendor diligence is the registrant's job, not the vendor's
Outsourcing a system does not outsource accountability. Regulators and privacy law both expect the firm to have looked before it signed.
CSA Staff Notice 33-321's vendor due diligence pillar
The CSA's cyber guidance names vendor due diligence as a core element of a credible program, alongside policy, incident response and training, drawn from a survey of more than 1,000 firms.
NI 31-103 s. 11.1's controls do not stop at the vendor boundary
A system of controls and supervision has to account for functions the firm outsources, since the obligation belongs to the registrant regardless of who operates the underlying system.
PIPEDA accountability for processor-held data
Personal information handed to a portfolio platform, statement vendor or aggregator remains the firm's responsibility, and a vendor's breach becomes the firm's notification duty.
Rule 3703's reach into third-party incidents
CIRO's incident reporting rule explicitly does not exclude incidents at a third-party service provider, which is exactly why the vendor's own incident-response commitments belong in your diligence file.
What goes wrong
Where unvetted vendors hurt wealth firms
Vendor risk here is concrete: it is the statement vendor moving bulk client files and the platform that concentrates your entire book behind one login.
A statement vendor exposed the way MOVEit exposed its users
The 2023 MOVEit campaign showed how a widely used file-transfer tool exposed bulk personal data across many organizations at once, including government use affecting roughly 100,000 Nova Scotians. A statement or mail-house vendor moving your client files through similar tooling carries the same exposure.
A portfolio platform with weak export controls
A vendor that allows unrestricted bulk export of client data, without logging or approval, turns a single compromised advisor credential into a full book-of-record theft.
An ICPM partnership inheriting an unreviewed stack
Licensing or white-labelling a robo platform without reviewing its KYC storage, consent flow and AR-review workflow means inheriting that vendor's weaknesses as your own regulatory exposure.
Vendor incident notice arriving too late for 3703
Without a contractual notice window, a vendor may disclose an incident well after your own Rule 3703 clock should have started, leaving the firm exposed to a late-filing finding for a breach it did not cause.
Our vendor security reviews for wealth management & robo-advisors
What our review covers for a registrant
One engagement, two deliverable streams: a defensible vendor file for the systems you rely on, and credible answers for the custodians and allocators reviewing you.

Vendor due-diligence assessments
Structured reviews of your portfolio platform, custodian, FundSERV connectivity and statement vendors, covering hosting, encryption, access controls, breach history and termination terms.
Evidence evaluation
We read the SOC 2 reports, security overviews and questionnaire responses vendors provide, translate what they actually attest to, and flag gaps marketing language tends to paper over.
Contract terms guidance
Recommended clauses for vendor agreements: breach-notification windows aligned to Rule 3703's clock, data residency, subcontractor disclosure and data return or destruction on exit.
Custodian and allocator questionnaire support
Gap review against what custodian diligence and allocator or consultant DDQs ask, plus internal review of draft answers before they go out.
A reusable review framework
A tiering model and templates the compliance team can apply the next time a platform or vendor relationship comes up for renewal.
How the engagement runs
How a review engagement runs for a wealth firm
Step 1
Build the vendor map
We list every system touching client records, from the portfolio platform to the mail-house vendor, tier them by sensitivity, and pull existing contracts and security documentation.
Step 2
Assess the critical tier
Platforms holding the book of record, custody relationships and statement distribution get full assessments, with vendor follow-ups where documentation is thin.
Step 3
Report and decide
Findings arrive as decisions the firm can act on: accept, tighten the contract, adjust configuration or plan an exit, each with the reasoning recorded.
Step 4
Answer the other side
With the vendor file in order, we help complete custodian diligence and allocator DDQs accurately, attaching evidence and handling follow-up questions.
What it costs
What determines vendor review pricing for a registrant
Scope drivers are the length of your vendor list, how many custodians and carrying brokers you work with, whether an ICPM partnership or new robo platform is under review, and the volume of DDQs your firm receives.
Vendor and third-party compliance oversight also comes standing inside the Virtual Privacy Office retainer. Share your vendor list and a sample questionnaire and we will scope the work.
Wealth Management & Robo-Advisors: Vendor security reviews questions, answered
Start with what the vendor can show in writing: hosting location, encryption at rest and in transit, access controls and export logging, incident history, and breach-notification commitments. For a custodian, add clarity on how incidents affecting your clients' assets are communicated to you and on what timeline, since that timeline feeds directly into your own Rule 3703 clock. We document the answers and flag anything the vendor cannot evidence.
Ask specifically about the file-transfer mechanism they use to move bulk statement data, whether it has been patched and monitored for known vulnerabilities, what encryption protects data in transit, and how quickly they would notify you of a compromise. MOVEit demonstrated that the transfer tool itself, not just the vendor's main platform, can be the weak point, so the diligence question has to reach that layer specifically.
Treat the licensed or white-labelled platform as an extension of your own regulated obligations. Review how the onboarding questionnaire collects and stores KYC data, how the workflow routes files to an advising representative for review under CSA Staff Notice 31-342, what access the platform vendor retains, and whether its incident-response commitments meet your Rule 3703 needs. The review should conclude before client onboarding starts, not after.
Ask for a current SOC 2 report or equivalent independent assessment where available, a security overview describing encryption and access controls, a data-residency statement, and a written breach-notification commitment with a specific timeline. Read the SOC 2 scope carefully: a report covering a different product line or an earlier version of the platform proves less than it appears to.
Priority terms include a breach-notification window fast enough to support your own Rule 3703 filing, data residency and subcontractor disclosure, restrictions on administrative access, confidentiality covering client personal information specifically, and a clear process for data return or destruction if the relationship ends. Many vendor relationships run on outdated agreements that predate current CSA guidance, and a review usually finds the contract is the biggest gap.
The questionnaire is about your firm's controls, and using an outside provider does not remove that responsibility. We work with your IT provider or MSP to pull specifics on what is configured and monitored, then translate that into answers you can sign honestly. Where the provider cannot evidence something the custodian requires, we turn it into a dated remediation item rather than an overstated answer that unravels under follow-up questions.
More for wealth management & robo-advisors
Other services for this niche
About this service
Answers & guides
- How do we prepare for a customer security questionnaire?
- Do you need a TRA before moving sensitive data to a new cloud provider?
- How do you assess the privacy and security risk of an AI vendor?
- Building a Third-Party Vendor Risk Assessment Program That Scales
- Before You Move Sensitive Data to a New Cloud: The Case for a TRA
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.