Vendor due diligence,
that stays on schedule.
The service-provider oversight Reg S-P expects, proven without chasing vendors by email. SOC 2 reports, signed due-diligence questionnaires (DDQs), financial-health checks, and renewal dates stay current on every vendor record, and on your internal systems under the same framework. Renewals queue themselves; a material-change alert surfaces the moment a SOC report drifts past its window or a contract nears expiry.
Vendor due diligence software built for RIAs, not enterprise TPRM.
Vendor due diligence and third-party risk management for RIAs centralizes SOC 2 reports, signed due-diligence questionnaires (DDQs), and renewal dates on each vendor record, so your Reg S-P service-provider oversight and Rule 206(4)-7 vendor oversight stay current and examiner-ready.
Vendor oversight that actually stays current.
Most firms have a vendor list. Few have one that examiners can rely on. RegFin makes vendor tracking the workflow, not a snapshot in a binder.
The vendor spreadsheet, frozen in time.
One registry. Reviews on schedule.
Every line item your vendor oversight policy promises.
Built-in DDQ + form builder
Ships with a thoughtful baseline vendor DDQ that covers the things examiners actually ask about. Need something different (cyber-only, asset-manager-specific, a private-fund supplemental)? Open the form builder and build any questionnaire your firm needs. Versioned, branded, sent & signed inside RegFin.
Risk tiering
Every vendor is scored on data sensitivity, service criticality, financial health, and concentration. Tier determines DDQ scope, review cadence, and whether material changes escalate to the IC or the board.
Renewal & window tracking
Every DDQ, SOC 2, attestation, and contract renewal has a date. RegFin tracks the window and queues the next review 60 days early. No more spreadsheet of expiration dates, no more renewals that lapse silently between annual cycles.
Renewal calendar
Annual reviews, contract renewals, SOC 2 windows, and insurance certificates queue 60 days in advance. Auto-reminders go to vendor contacts; nothing reaches expiry without three nudges and a CCO escalation.
The controls, read for you
The vendor's controls read and flagged for you, not another PDF to study. Drop in a SOC 2, ISO 27001 cert, or data-handling policy; RegFin pulls the test results, exceptions, scope, and report dates, and flags the deltas from last year's report side-by-side.
Evidence vault
Every SOC report, certificate, contract, and signed DDQ lives on the vendor record with hash, timestamp, and access log. Examiner pulls the binder in one click; everything cited is verifiable.
Material change alerts
Every named trigger from your IMA / MSA / DPA generates a same-day alert with the contract clause attached: ownership change, M&A activity, named-party breach disclosure, SOC 2 drift, BCP test failure.
Tier-driven cadence
Critical vendors get annual full reviews plus quarterly health checks. Non-critical vendors get a lighter pulse. Cadence follows the tier. Set the cadence rule once and the calendar reshapes for every vendor.
Examiner-ready binder
Every vendor with the DDQ, SOC reports, contract, alerts log, and signed attestations in one export. Hash manifest and chain-of-custody log included so the evidence holds up under deposition.
One view. Every vendor your firm tracks.
Tier, status, missing evidence, next review: all in one row.
| Vendor | Tier | Evidence | Status | Next review |
|---|---|---|---|---|
| Atlas Custody Servicescustodian · client PII | Tier 1 | SOC 2DPABCPDDQ v3 | Action · 12 d | Mar 04, 2026 |
| Northpoint Portfolio TechPMS · holdings data | Tier 1 | SOC 2DPABCPDDQ v3 | Current | Jul 22, 2026 |
| Beacon CRMCRM · client PII, comms | Tier 1 | SOC 2DPAInsurance certDDQ v3 | Action · 5 d | Feb 26, 2026 |
| Lighthouse Performance Reportingrecordkeeper · holdings | Tier 2 | SOC 2DDQ v2 | Current | May 11, 2026 |
| Meridian Cyber InsuranceE&O carrier | Tier 2 | CertificateRenewal | Current | Oct 30, 2026 |
| Praxis Marketing Co.marketing · campaign assets | Tier 3 | DDQ v2SOC 2 | Stale · 47 d | Overdue |
| Quartz HR CloudHR · employee PII | Tier 3 | SOC 2DDQ v2 | Current | Sep 18, 2026 |
Not just vendors. Your internal systems, too.
SEC examiners don't only ask about your vendors. They ask for a complete inventory of every system that touches client data. Proprietary tools, internal databases, shared drives, and homegrown applications all fall under Rule 206(4)-7 and Reg S-P. Most firms miss this entirely.
RegFin treats internal systems as first-class citizens. Same risk scoring, same access reviews, same evidence tracking. No separate spreadsheet.
-
Unified inventory
Internal tools and vendor products in one registry, with the same data classification, owner assignments, and review cadence.
-
Access reviews
Track who has access to each internal system. Periodic certification ensures former employees and role changes don't leave stale permissions behind.
-
Data sensitivity flags
Tag every system with what it holds: client PII, financial data, communications, employee records. Sensitivity drives the review tier automatically.
Scored on the four dimensions examiners ask about.
Each vendor gets a current score across four dimensions, with the underlying evidence linked from every number.
- Security posture: SOC 2 status, penetration testing, certifications on file
- Privacy & data handling: data classification, PII access, processing controls
- Operational resilience: business continuity plan, disaster recovery, uptime track record
- Financial stability: credit rating, insurance verification, going-concern signals
Your questions, answered.
See annual review week run in one workflow.
A demo walks the full workflow against a demo firm: selecting vendors, assigning risk tiers, sending a DDQ, and tracking SOC 2 windows in one place.
Book a demo →