Home Features RIA Compliance Software Archiving iMessage Archiving Trade Monitoring Vendor Due Diligence Marketing Reviews Content Library Form ADV Forms & Tasks AI Consultant Reporting Documents For Consultants Pricing Blog About Sign in Request demo

Vendor due diligence,
that stays on schedule.

The service-provider oversight Reg S-P expects, proven without chasing vendors by email. SOC 2 reports, signed due-diligence questionnaires (DDQs), financial-health checks, and renewal dates stay current on every vendor record, and on your internal systems under the same framework. Renewals queue themselves; a material-change alert surfaces the moment a SOC report drifts past its window or a contract nears expiry.

vendor record · due diligence
Atlas Custody Services, Inc.
Custodian· Active· Review due in 12 days
Critical
risk tier
Critical · 82/100
data classification
Restricted · PII
contract renewal
Sep 30, 2026
Risk assessment · annual
Security posture72
Privacy & data handling85
Operational resilience64
Financial stability28
Certifications on file 3 of 4 verified
SOC 2 Type IIJan 14
Penetration test completedNov 20
Business continuity planFeb 08
×ISO 27001Not on file
Pending review Annual DDQ submitted by vendorFeb 18
Active Master services agreementAuto-renew · 60d notice
206(4)-7
Advisers Act compliance program rule
DDQ
Built-in template + custom form builder
365d
Default annual review cadence · per tier
0
Renewal reminders to set yourself

Vendor due diligence software built for RIAs, not enterprise TPRM.

Vendor due diligence and third-party risk management for RIAs centralizes SOC 2 reports, signed due-diligence questionnaires (DDQs), and renewal dates on each vendor record, so your Reg S-P service-provider oversight and Rule 206(4)-7 vendor oversight stay current and examiner-ready.

Vendor oversight that actually stays current.

Most firms have a vendor list. Few have one that examiners can rely on. RegFin makes vendor tracking the workflow, not a snapshot in a binder.

The way most firms do it

The vendor spreadsheet, frozen in time.

1CCO inherits a 3-year-old vendor list from prior counselDay 0
2Emails each vendor a DDQ Word doc; chases for weeks4–8 wks
3Files SOC 2 PDFs in a shared drive; loses track of which is currentongoing
4Misses the renewal date · SOC 2 lapses past its windowsilent fail
5Annual review week becomes 3 weeks of forensic reconstruction+ deflection
~18 hrs
Per vendor · per year
~40%
Of registries miss a renewal window
The RegFin workflow

One registry. Reviews on schedule.

1Select from common vendors or add your own to build your list in minutesDay 1
2Assign risk tiers & attach the appropriate DDQ templateDay 1
3Send DDQs from RegFin; vendors sign, upload evidence & SOC 2 directly2 wks median
4SOC 2 windows tracked; report drift alerts CCO same dayT+0
5Renewals & annual reviews queue 60 days early · auto-remindedHands-off
~45 min
Per vendor · per year
Same day
SOC 2 drift alert

Every line item your vendor oversight policy promises.

Built-in DDQ + form builder

Ships with a thoughtful baseline vendor DDQ that covers the things examiners actually ask about. Need something different (cyber-only, asset-manager-specific, a private-fund supplemental)? Open the form builder and build any questionnaire your firm needs. Versioned, branded, sent & signed inside RegFin.

Risk tiering

Every vendor is scored on data sensitivity, service criticality, financial health, and concentration. Tier determines DDQ scope, review cadence, and whether material changes escalate to the IC or the board.

Renewal & window tracking

Every DDQ, SOC 2, attestation, and contract renewal has a date. RegFin tracks the window and queues the next review 60 days early. No more spreadsheet of expiration dates, no more renewals that lapse silently between annual cycles.

Renewal calendar

Annual reviews, contract renewals, SOC 2 windows, and insurance certificates queue 60 days in advance. Auto-reminders go to vendor contacts; nothing reaches expiry without three nudges and a CCO escalation.

The controls, read for you

The vendor's controls read and flagged for you, not another PDF to study. Drop in a SOC 2, ISO 27001 cert, or data-handling policy; RegFin pulls the test results, exceptions, scope, and report dates, and flags the deltas from last year's report side-by-side.

Evidence vault

Every SOC report, certificate, contract, and signed DDQ lives on the vendor record with hash, timestamp, and access log. Examiner pulls the binder in one click; everything cited is verifiable.

Material change alerts

Every named trigger from your IMA / MSA / DPA generates a same-day alert with the contract clause attached: ownership change, M&A activity, named-party breach disclosure, SOC 2 drift, BCP test failure.

Tier-driven cadence

Critical vendors get annual full reviews plus quarterly health checks. Non-critical vendors get a lighter pulse. Cadence follows the tier. Set the cadence rule once and the calendar reshapes for every vendor.

Examiner-ready binder

Every vendor with the DDQ, SOC reports, contract, alerts log, and signed attestations in one export. Hash manifest and chain-of-custody log included so the evidence holds up under deposition.

One view. Every vendor your firm tracks.

Tier, status, missing evidence, next review: all in one row.

Vendor registry
AllCriticalAction neededUp to date
38 vendors3 action needed
VendorTierEvidenceStatusNext review
Atlas Custody Servicescustodian · client PII Tier 1 SOC 2DPABCPDDQ v3 Action · 12 d Mar 04, 2026
Northpoint Portfolio TechPMS · holdings data Tier 1 SOC 2DPABCPDDQ v3 Current Jul 22, 2026
Beacon CRMCRM · client PII, comms Tier 1 SOC 2DPAInsurance certDDQ v3 Action · 5 d Feb 26, 2026
Lighthouse Performance Reportingrecordkeeper · holdings Tier 2 SOC 2DDQ v2 Current May 11, 2026
Meridian Cyber InsuranceE&O carrier Tier 2 CertificateRenewal Current Oct 30, 2026
Praxis Marketing Co.marketing · campaign assets Tier 3 DDQ v2SOC 2 Stale · 47 d Overdue
Quartz HR CloudHR · employee PII Tier 3 SOC 2DDQ v2 Current Sep 18, 2026

Not just vendors. Your internal systems, too.

SEC examiners don't only ask about your vendors. They ask for a complete inventory of every system that touches client data. Proprietary tools, internal databases, shared drives, and homegrown applications all fall under Rule 206(4)-7 and Reg S-P. Most firms miss this entirely.

RegFin treats internal systems as first-class citizens. Same risk scoring, same access reviews, same evidence tracking. No separate spreadsheet.

  • Unified inventory

    Internal tools and vendor products in one registry, with the same data classification, owner assignments, and review cadence.

  • Access reviews

    Track who has access to each internal system. Periodic certification ensures former employees and role changes don't leave stale permissions behind.

  • Data sensitivity flags

    Tag every system with what it holds: client PII, financial data, communications, employee records. Sensitivity drives the review tier automatically.

internal systems Internal
Advisor Portal (Custom)
Internal tool · client PII, financial data · MFA enforced
Restricted
Compliance File Share
File share · employee data, firm financials · SSO integrated
Confidential
Client Onboarding Database
Database · client PII, KYC documents · Role-based access
Restricted
Performance Reporting Scripts
Internal tool · holdings data · 2 users
Confidential
Shared Drive (Marketing)
File share · campaign assets, client testimonials
Internal

Scored on the four dimensions examiners ask about.

Each vendor gets a current score across four dimensions, with the underlying evidence linked from every number.

  • Security posture: SOC 2 status, penetration testing, certifications on file
  • Privacy & data handling: data classification, PII access, processing controls
  • Operational resilience: business continuity plan, disaster recovery, uptime track record
  • Financial stability: credit rating, insurance verification, going-concern signals
Atlas Custody Services — risk profileCritical
Security postureSOC 2 · pen test72
Privacy & data handlingrestricted · PII85
Operational resilienceBCP on file64
Financial stabilityinsured · stable28

Your questions, answered.

RegFin ships with a list of common industry vendors: custodians, portfolio management systems, CRMs, recordkeepers, and other providers RIAs typically work with. Select the ones your firm uses and they're added to your vendor list with the basic profile pre-filled. For any vendor not in our list, add them manually in a few clicks. Either way, the due diligence work (sending DDQs, collecting evidence, tracking renewals) is done by your firm inside the platform.
RegFin ships with a baseline vendor DDQ: the questions examiners actually expect to see for a typical RIA technology, custodian, or service vendor. For anything beyond that, our form builder lets you compose your own DDQs from scratch, whether cyber-only, asset-manager-specific, or a private-fund supplemental. Build it once, version it, send it, sign it, all inside RegFin.
By default: ownership change, M&A activity, named-party breach disclosure, SOC 2 report drift past its window, BCP test failure or absence, insurance certificate lapse, and any contract-clause-named trigger from your MSA/DPA. Each firm can add custom triggers. Alerts cite the contract clause that's implicated so the action is obvious.
No. Your consultant still helps with the policy questions: what tier a vendor should be in, whether a given contract clause is acceptable, how to handle a real escalation. What RegFin replaces is the recordkeeping work that's the actual bottleneck: sending DDQs, chasing signatures, filing evidence, reconciling sub-processor lists, surfacing material changes. Most firms keep the consultant for strategy and lose the spreadsheet.
Drop a SOC 2 Type II report into the vendor record (or have the vendor upload it directly through their portal link). RegFin extracts the report period, auditor, scope, controls tested, exceptions noted, and sub-processor list. Year-over-year diffs are shown side-by-side: new exceptions, dropped controls, scope changes. The PDF stays attached with hash and chain-of-custody log.
A PDF or ZIP per vendor, or a single binder for the whole registry. Each vendor section contains the current DDQ, prior versions with diffs, SOC reports, contract and DPA, sub-processor reconciliation log, all alerts triggered in the period, and the firm's review notes. Every artifact carries a SHA-256 hash and access log. The same export is what your auditor sees in an annual review.

See annual review week run in one workflow.

A demo walks the full workflow against a demo firm: selecting vendors, assigning risk tiers, sending a DDQ, and tracking SOC 2 windows in one place.

Book a demo