Aboutwhy sjkplawyerspracticesInsightsCase StudyNewsLocations
Digital Evidence

Third Party Risk Management Compliance

A vendor onboarded long ago now holds customer data, connects to your network, and relies on its own subcontractors. If something goes wrong there, regulators will still ask what you did to oversee it.

Reviewed

01 GUIDE

Third Party Risk Management Compliance: what usually happens

Regulators treat vendor risk as your risk

Federal banking agencies have issued joint guidance on managing third-party relationships, New York's financial regulator requires covered companies to maintain a written security policy for their service providers, and federal health privacy rules require business associate agreements with vendors handling protected health information. State privacy laws also expect particular contract terms with service providers that process personal data. The common thread is that outsourcing a function does not outsource responsibility for it. Third party risk management compliance is therefore judged by whether oversight was proportionate to the vendor's access and importance.

Diligence, contracts, and the long middle

Diligence at onboarding usually gets the attention, but most risk develops afterward as vendors change systems, subcontractors, or ownership. Contracts should at least address security obligations and prompt notice to you of incidents, along with what happens to your data when the relationship ends. Critical vendors deserve periodic review based on actual evidence, such as independent assessment reports, rather than questionnaires alone. Concentration risk, where many functions depend on a single provider, is drawing growing regulatory attention. When a vendor has an incident, your own notice obligations may be triggered even though the systems involved were never yours, which is why the contract's incident clause deserves attention.

Building a program that fits

We help companies inventory their vendors, tier them by the access and data they hold, update template contracts, and set review cycles that can actually be maintained. Where a regulator has raised vendor oversight, we review the existing records against what the applicable guidance expects. For a smaller company the program can be modest, provided it is applied consistently. We often start with the handful of vendors whose failure would hurt most and work outward from there, because a program that covers the critical relationships well is more defensible than one that covers every vendor thinly. Offboarding deserves the same care as onboarding, including confirming that access is removed and data is returned or deleted.

02 ATTORNEYS

Who you would be working with

Attorneys at our New York and Washington, D.C. offices handle matters like this one.

03 CASE RESULTS

Matters we have handled

Prior results do not guarantee a similar outcome.

04 HOW WE WORK

Client-centered service across jurisdictions

Global Coordination & Expertise

We deliver coordinated and effective legal services to our clients, utilizing our extensive legal resources and experienced attorneys in our well-integrated global network. Through our Washington D.C. and New York offices, together with our alliance

Multilingual & Cross-Border Communication

Our attorneys are experienced in both domestic and international matters and, with fluency in various languages, provide clear and consistent communication at every stage of your legal process.

Client-Centered Approach

Client service lies at the heart of our operations. From the initial consultation, we prioritize understanding your situation, listening to your goals, and providing regular updates and strategies tailored to your individual case.

Multidisciplinary & Efficient Solutions

Our multidisciplinary approach and established processes enable us to address cross-border challenges with efficiency.

05 OFFICES

Where we meet clients

Consultations are available in person or remotely.

New York

285 Fulton Street, New York, NY 10007
(855) 529-7557

Washington, D.C.

Suite 985, 1717 K Street NW, Washington, DC 20006
(855) 529-7557

Los Angeles

1901 Avenue of the Stars, Suite 820, Los Angeles, CA 90067
(424) 561-7557

Attorney Advertising. This page is general information about third party risk management compliance and is not legal advice. Reading it does not create an attorney-client relationship. Outcomes depend on the facts of each matter, and prior results do not guarantee a similar outcome. Laws differ by state and change over time.