Regulators treat vendor risk as your risk
Federal banking agencies have issued joint guidance on managing third-party relationships, New York's financial regulator requires covered companies to maintain a written security policy for their service providers, and federal health privacy rules require business associate agreements with vendors handling protected health information. State privacy laws also expect particular contract terms with service providers that process personal data. The common thread is that outsourcing a function does not outsource responsibility for it. Third party risk management compliance is therefore judged by whether oversight was proportionate to the vendor's access and importance.
Diligence, contracts, and the long middle
Diligence at onboarding usually gets the attention, but most risk develops afterward as vendors change systems, subcontractors, or ownership. Contracts should at least address security obligations and prompt notice to you of incidents, along with what happens to your data when the relationship ends. Critical vendors deserve periodic review based on actual evidence, such as independent assessment reports, rather than questionnaires alone. Concentration risk, where many functions depend on a single provider, is drawing growing regulatory attention. When a vendor has an incident, your own notice obligations may be triggered even though the systems involved were never yours, which is why the contract's incident clause deserves attention.
Building a program that fits
We help companies inventory their vendors, tier them by the access and data they hold, update template contracts, and set review cycles that can actually be maintained. Where a regulator has raised vendor oversight, we review the existing records against what the applicable guidance expects. For a smaller company the program can be modest, provided it is applied consistently. We often start with the handful of vendors whose failure would hurt most and work outward from there, because a program that covers the critical relationships well is more defensible than one that covers every vendor thinly. Offboarding deserves the same care as onboarding, including confirming that access is removed and data is returned or deleted.