Vendor Due Diligence Questionnaire — Reg S-P 30-Day Clock, GLBA Safeguards, NY DFS Part 500
The vendor scorecard (L4 Ch2 L1) tells the practice whether to consider a vendor. The vendor due diligence questionnaire is what gets sent to the vendor before any byte of client NPI moves. Forty questions, templated to NY DFS 23 NYCRR 500, the May 2024 Reg S-P 17 CFR Part 248 amendments (30-day customer / 72-hour DFS clocks), FINRA's 2026 cyber expectations, and the SEC's cyber proposals — covering the regulatory floor every vendor must clear and the operational details a defensible deployment requires. The completed questionnaire becomes a permanent compliance artifact under SEC Rule 204-2 and FINRA Rule 4511; the act of sending it triggers the practice's own ADV Part 2A disclosure assessment under L5 Ch7. This lesson installs the questionnaire in full, organized in nine sections aligned to the regulatory regimes, with the trap questions named, the acceptance thresholds documented, and the path to remediation for "no" answers.
Why Forty Questions — Not Twenty, Not Eighty
Twenty questions leave material risk areas uncovered. Eighty questions exceed the patience of mid-stage vendor sales engineers and lose the practice the credibility it needs to negotiate. Forty is the empirical sweet spot established by the ACA Group / NRS-style vendor management playbooks and the major aggregators' (Focus Financial, Hightower, CI / Corient before brand changes) standardized AI vendor DD lists. Forty questions across nine sections, each answerable in 1-3 sentences, with most "yes/no" and the rest short-narrative, fit a 30-minute vendor security-team call or an asynchronous fill-out.
The questionnaire is sent under NDA. The vendor's response is reviewed by the CCO (or outsourced compliance equivalent), the practice's IT/MSP lead, and the head of advisory. Material "no" answers either kill the deal or initiate a documented remediation negotiation — both are valid outcomes; what is not valid is accepting a "no" without analysis. The completed questionnaire, the response analysis, and the disposition memo are retained per the vendor's relationship duration plus three years under SEC Rule 204-2 and FINRA Rule 4511. The questionnaire is one of the artifacts the SEC Division of Examinations and FINRA examiners increasingly request during 2026 exams when assessing the firm's vendor oversight under Reg S-P.
Section 1 — Corporate and Financial (Q1-Q5)
Q1. Provide your full legal entity name, state of incorporation, primary place of business, and any DBAs. Acceptance: a clear, single legal entity that contracts with you. Trap: vendors that "are in the process of restructuring" — get clarity before signature.
Q2. Identify your last three years of audited or reviewed financial statements. If not available, provide management-prepared financials and explain. Acceptance: audited financials for any vendor handling 50+ advisor seats; reviewed acceptable for early-stage; management-only flagged for risk.
Q3. Disclose any material legal proceedings, regulatory actions, or settlements in the last 60 months. Acceptance: clean record or fully disclosed and substantively closed matter. Trap: "we are not at liberty to discuss" — fails the dimension.
Q4. Identify your funding history (round, date, amount, lead investor), your current runway (in months), and your path to profitability. Acceptance: minimum 18-month runway or profitability; sub-12-month flagged per L4 Ch2 L1 scorecard.
Q5. Identify your ownership structure — public, private (VC/PE), founder-owned, employee-owned, strategic backing (custodian, BD, asset manager). Acceptance: clear understanding of decision-maker accountability. Trap: hidden majority owners — push for transparency.
Section 2 — SOC 2 and Certifications (Q6-Q10)
Q6. Provide your most recent SOC 2 Type II report. Confirm the audit period, audit firm, and that the report is no older than 12 months. Acceptance: current Type II with clean opinion from Big Four or comparable second-tier auditor.
Q7. Identify all Trust Service Criteria categories tested in the audit (Security, Availability, Processing Integrity, Confidentiality, Privacy). Acceptance: Security, Confidentiality, Availability minimum; Privacy and Processing Integrity strongly recommended.
Q8. List any control deviations identified in the SOC 2 Type II report, their remediation status, and the auditor's response. Acceptance: documented deviations with closed remediation; unresolved deviations material to the use case are a flag.
Q9. Identify any other security certifications maintained (ISO 27001, ISO 27017, ISO 27018, HITRUST, FedRAMP, Cyber Essentials Plus, NIST CSF self-assessment). Acceptance: SOC 2 Type II is sufficient; additional certifications are positive signals.
Q10. Provide the date of your last penetration test by an independent third party, the firm that conducted it, and the high-level findings. Acceptance: pen test within last 12 months, findings remediated or in-progress.
Section 3 — Data Handling and Reg S-P (Q11-Q18)
Q11. Describe how customer (advisor practice) data is encrypted at rest. State the algorithm, key length, key management approach, and key rotation cadence. Acceptance: AES-256, customer-managed keys available, documented rotation.
Q12. Describe how customer data is encrypted in transit. State protocols, cipher suites, and certificate authority. Acceptance: TLS 1.2 minimum, 1.3 preferred, valid CA, no deprecated cipher suites.
Q13. Identify all geographic locations where customer data is stored or processed. Identify cloud providers (AWS, GCP, Azure, other) and specific regions. Acceptance: US-only by default for US advisor practices; explicit naming of regions; cross-border flow requires documented controls per state cyber rules (NY DFS 23 NYCRR 500, California CPRA, Texas DIR).
Q14. Identify all third-party sub-processors that may access customer data (cloud infrastructure, foundation model providers, analytics tools, customer support tools). Acceptance: complete named list with SOC 2 Type II for material sub-processors; the May 2024 Reg S-P vendor oversight extends to sub-processors.
Q15. Confirm your training data posture: do you use customer prompts or outputs to train your models? If yes, can the customer opt out? Acceptance: "we do not train on customer data" or "customer-controlled opt-in only with default off"; default-on training fails the dimension.
Q16. Describe your data retention and deletion policies. What is retained, for how long, and what is the deletion process upon customer request or contract termination? Acceptance: customer-controlled retention with explicit deletion process; retention aligned with FINRA Rule 4511 and SEC Rule 204-2 minimums where applicable.
Q17. Confirm your incident response program: do you have a written IRP, do you test it, and how do you classify incidents? Acceptance: written IRP, annual tabletop testing minimum, documented incident classification per the May 2024 Reg S-P amendments framework.
Q18. Describe your breach notification process to customers. What is your SLA, what triggers notification, and what information do you provide? Acceptance: 24-72 hour notification SLA (tighter than the regulatory minimum), clear trigger criteria, comprehensive information disclosure. Required: alignment with the May 2024 Reg S-P 30-day customer / 72-hour NY DFS clocks.
Section 4 — GLBA Safeguards and NY DFS Part 500 (Q19-Q24)
Q19. Confirm your alignment with the GLBA Safeguards Rule. Identify the Information Security Program elements, the qualified individual responsible, and the periodic risk assessment cadence. Acceptance: documented IS Program with named accountable individual, annual risk assessment.
Q20. Confirm your alignment with NY DFS 23 NYCRR 500 if you serve NY-licensed customers. Identify CISO, cybersecurity policy, multi-factor authentication, training, encryption, incident reporting, third-party service provider security. Acceptance: explicit Part 500 mapping for vendors serving NY-licensed customers; cited 72-hour cybersecurity event reporting obligation acknowledged.
Q21. Describe your multi-factor authentication enforcement for customer access. Required protocols, exception handling, and audit logging. Acceptance: MFA mandatory by default, phishing-resistant factors (FIDO2, hardware tokens) supported, audit log retained.
Q22. Describe your access controls for internal personnel accessing customer data — role-based access controls, least-privilege principles, access review cadence, offboarding process. Acceptance: documented RBAC, quarterly access review minimum, automated offboarding tied to HR system.
Q23. Describe your employee background checks, training requirements, and acceptable use policies. Acceptance: pre-employment background checks, annual security training, AUP signed by all personnel with access to customer data.
Q24. Describe your security monitoring (SIEM, MDR/MSSP, SOC), threat intelligence integration, and 24x7 monitoring posture. Acceptance: documented SOC / SIEM / MDR with 24x7 monitoring for vendors handling sensitive data.
Section 5 — FINRA 2026 Cyber and Recordkeeping (Q25-Q29)
Q25. Describe how your product supports FINRA Rule 4511 retention requirements. Native archive integration, tamper-proof export, timestamped metadata, retention duration aligned with rule minimum. Acceptance: documented Smarsh / Global Relay integration or equivalent native export with required metadata. Cross-reference to L3 Ch10 L1 pipeline.
Q26. Describe how your product supports SEC Rule 204-2 books and records requirements. Specifically how AI-generated content (drafts, outputs, prompts, edits, signoffs) are retained and retrievable. Acceptance: AI-artifact-aware retention with the prompt-output-edit-signoff chain captured per L3 Ch10 L2 retention decision tree.
Q27. Describe how your product addresses the FINRA 2026 Annual Regulatory Oversight Report's GenAI section. Particularly the Rule 3110 reasonable-design supervisory expectations for action-taking AI and the shadow-AI risks. Acceptance: vendor demonstrates explicit awareness of the 2026 Oversight Report; named controls for agentic supervision if vendor offers action-taking capabilities.
Q28. If your product supports communication archiving or pre-use review, describe how it integrates with the practice's FINRA Rule 2210 principal review workflow. Acceptance: integration with the practice's existing review queue or documented workflow alignment.
Q29. Confirm your awareness of FINRA Regulatory Notice 24-09 on GenAI. Describe how your product or controls address the issues raised. Acceptance: explicit Notice 24-09 reference with named controls.
Section 6 — SEC, Marketing Rule, and Reg BI (Q30-Q34)
Q30. If your product produces client-facing content, describe how you support the SEC Marketing Rule 206(4)-1's "clear and prominent" disclosure standard, the January 2026 staff FAQs on third-party ratings, hypothetical performance, and testimonial mechanics. Acceptance: explicit Marketing Rule awareness with documented disclosure-language support; awareness of January 2026 FAQs.
Q31. Describe your controls preventing AI-washing claims in marketing materials, training, and customer-facing communications. Specifically referencing the 2024-2025 SEC enforcement (Delphia, Global Predictions, the 2025 enforcement cluster). Acceptance: vendor's own marketing has substantiation file, documented capability claims, no "AI-powered" overstatements relative to actual product behavior.
Q32. If your product supports recommendation drafting, describe how you handle Reg BI's four obligations (Disclosure, Care, Conflict, Compliance) under §240.15l-1. Specifically the Care Obligation's documented-consideration-of-alternatives for rollovers (the 2025-2026 FINRA AWC pattern). Acceptance: explicit Reg BI awareness; recommendation drafts include alternatives-consideration framework.
Q33. Describe how you handle the SEC Compliance Rule 206(4)-7 for IA-side compliance. Acceptance: vendor demonstrates awareness of the IA compliance program rule and how customer compliance programs interact with vendor controls.
Q34. Describe how your product handles or supports ADV Part 2A disclosure obligations when a new tool is added to the practice's stack. Acceptance: vendor provides disclosure-language template or guidance per the L5 Ch7 off-cycle amendment workflow.
Section 7 — State and NAIC (Q35-Q37)
Q35. Describe your alignment with state-level cybersecurity rules — California CPRA, Texas DIR, and the broader state patchwork. Acceptance: documented multi-state cyber posture with named state-specific controls where applicable.
Q36. If your product serves annuity-licensed advisors, describe your alignment with the NAIC AI Model Bulletin and NAIC Model #275 (annuity suitability and best interest). Acceptance: explicit NAIC framework reference; documented controls for AI-generated annuity recommendation drafts where applicable.
Q37. Identify any state-level data residency, breach notification, or AI-specific rules that affect your service delivery to the customer's state of operation. Acceptance: vendor proactively identifies state-specific obligations relevant to the customer's footprint.
Section 8 — AI-Specific Risk and Governance (Q38-Q40)
Q38. Describe your model governance program. Acceptance: documented model risk management — including model validation, drift monitoring, version control, change management — aligned to NIST AI Risk Management Framework (RMF) or equivalent. Cross-reference to the practice's L4 Ch6 L1 AI governance committee for vendor oversight.
Q39. Describe your prompt-injection resistance, jailbreak defenses, and adversarial input handling for the use cases relevant to advisor workflow. Acceptance: documented controls; awareness of advisor-specific attack vectors (e.g., a crafted client email attempting to make the model produce non-compliant output).
Q40. If your product offers agentic capabilities (action-taking AI), describe the supervisory architecture: pre-action compliance checks, post-action review, kill-switch design, Rule 4511 supervisory log alignment, and the customer's controls over agentic behavior. Acceptance: explicit alignment with FINRA Rule 3110 reasonable-design framework and the L4 Ch3 L3 agentic-AI WSP framing.
Response Analysis and Disposition
After the vendor returns responses, the CCO + IT/MSP lead + head of advisory review the 40 answers against the acceptance criteria. Each question is scored: Pass (meets acceptance criteria, no follow-up), Conditional Pass (meets criteria with documented caveat), Remediation Required (vendor must close gap before signing), or Fail (vendor cannot or will not close gap). A vendor with five or more Fails on Sections 2 (SOC 2), 3 (Data Handling / Reg S-P), 4 (GLBA / NY DFS), or 5 (FINRA 2026) is declined regardless of other dimensions. A vendor with Remediation Required answers gets a documented timeline (typically 30-90 days) before final signature; the remediation is tracked under the vendor management log.
The disposition memo records: the questionnaire date, the responder (vendor security team contact and title), the reviewer team (CCO, IT lead, head of advisory), the question-by-question score, the material findings, the remediation plan if applicable, and the final disposition (signed, declined, deferred pending remediation). The memo is signed by the CCO and the managing partner (or the practice principal for the solo). Retained under WSP per SEC Rule 204-2 and FINRA Rule 4511 for the vendor relationship duration plus three years. The disposition memo plus the underlying questionnaire becomes part of the L4 Ch8 L2 M&A diligence pack — buyers will request the vendor management history as evidence of AI maturity.
The act of sending the questionnaire also triggers an ADV Part 2A disclosure assessment under L5 Ch7: if the practice adds the vendor and the vendor processes NPI in a way that materially changes the firm's data handling, the practice updates ADV Part 2A promptly under SEC prompt-amendment rules. The engagement letter language is checked for alignment. The Marketing Rule audit (L4 Ch7 L1) adds the vendor's capability claims to its scope. The cyber playbook (L4 Ch4 L1) adds the vendor to the vendor inventory with MFA, encryption, and IAM controls verified.
Key Takeaways
- Forty questions across nine sections: corporate/financial, SOC 2 / certifications, data handling / Reg S-P, GLBA / NY DFS Part 500, FINRA 2026 cyber, SEC / Marketing Rule / Reg BI, state / NAIC, AI-specific governance.
- Templated to the regulatory floor: May 2024 Reg S-P amendments (30-day customer / 72-hour DFS clocks), NY DFS 23 NYCRR 500, GLBA Safeguards, FINRA 2026 Annual Regulatory Oversight Report, FINRA Reg Notice 24-09, SEC Marketing Rule 206(4)-1 + January 2026 staff FAQs, Reg BI §240.15l-1, NAIC Model #275 + AI Model Bulletin.
- Sent under NDA, returned in 1-3 sentences per question, reviewed by CCO + IT/MSP lead + head of advisory.
- Four-tier scoring per question: Pass / Conditional Pass / Remediation Required / Fail. Five+ Fails in Sections 2-5 = decline.
- Specific trap questions: Q15 (training data posture — default-on training fails), Q14 (sub-processors — opaque list fails), Q3 (legal proceedings — "not at liberty" fails), Q18 (breach notification — best-effort fails).
- Disposition memo signed by CCO + managing partner, retained per SEC Rule 204-2 and FINRA Rule 4511 for vendor duration plus three years.
- The questionnaire chains with the L4 Ch2 L1 scorecard and the L4 Ch2 L3 POC pilot to produce the defensible three-step vendor onboarding artifact set examined by regulators and required by M&A buyers (L4 Ch8 L2 diligence pack).
- Sending the questionnaire triggers ADV Part 2A disclosure assessment (L5 Ch7 off-cycle amendment), Marketing Rule audit scope addition (L4 Ch7 L1), and cyber inventory addition (L4 Ch4 L1) — vendor onboarding is a multi-touchpoint compliance event, not just a procurement decision.
Skill.re