- Your cloud provider stores sensitive files.
- Your copier vendor may access scanned documents.
- Your IT provider holds administrative credentials.
- Your billing platform processes client or patient information.
- Your cleaning staff may walk through offices after hours.
- Your employees assume someone else checked the risk.
That last assumption is where trouble begins.
A vendor does not need to be malicious to become a security liability. One compromised account, unpatched system, careless subcontractor, or poorly written contract can create a path into your firm.
For law firms, medical practices, accounting firms, and businesses subject to the FTC Safeguards Rule or GLBA compliance obligations, third-party risk management is not an administrative detail. It is part of protecting the information your clients trust you to handle.
The Overlooked Gap in Your Security Program
Policies. Passwords. MFA. Backups.
You may have invested in each of these controls and still have a significant gap: vendors with access to your data or facilities.
Consider the familiar scenario.
“Hey Margaret, the copier technician is here. Can you let him into the records room?”
He is friendly. He has worked with the firm for years. Nobody questions whether his access is limited, whether his company screens employees, or whether the service agreement contains security requirements.
The same thing happens with the “I got a guy” IT provider who has global administrator access to Microsoft 365, the billing vendor that exports patient information, or the software company that stores tax documents in the cloud.
The issue is not whether these vendors are trustworthy. The issue is whether your organization has verified, documented, and monitored the risks they introduce.
That is the difference between trust and governance.
What the FTC Safeguards Rule Requires of Service Providers
The FTC Safeguards Rule implements portions of the Gramm-Leach-Bliley Act for covered financial institutions. Accounting firms and tax preparers are commonly within scope, although applicability depends on the services your organization provides and the information it handles.
Under FTC guidance on the Safeguards Rule, covered organizations must:
- Take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards.
- Require those service providers by written contract to implement and maintain safeguards.
- Periodically assess the provider based on the risk it presents and the continued adequacy of its safeguards.
This is more than obtaining a signature during onboarding. Your firm needs a repeatable process for understanding who has access to customer information, what protections are in place, and whether those protections remain effective.
A vendor contract that says “we take security seriously” is not enough. Your agreement should address practical requirements such as:
- Access control and least privilege
- Multi-factor authentication
- Encryption
- Secure data disposal
- Incident and breach notification
- Cooperation during investigations
- Subcontractor management
- Backup and recovery expectations
- Return or destruction of data when the relationship ends
For accounting firms, these responsibilities should be reflected in your written information security plan, or WISP. The AICPA’s GLBA and Safeguards Rule resources provide additional context for CPA and tax practices.
Even if your organization qualifies for a partial exemption from certain Safeguards Rule requirements, vendor oversight may still apply. Smaller firms are not automatically excused from selecting capable providers, requiring safeguards by contract, and reassessing those providers.
HIPAA Adds Another Layer for Medical Practices
Medical practices have a parallel obligation under HIPAA.
If a vendor creates, receives, maintains, or transmits protected health information on your practice’s behalf, that vendor may be a business associate. Examples include:
- Cloud hosting providers
- Electronic health record platforms
- Medical billing companies
- Practice management software vendors
- IT support providers
- Data backup providers
- Patient communication platforms
In these situations, HIPAA generally requires a written Business Associate Agreement, or BAA, before the vendor handles protected health information.
The U.S. Department of Health and Human Services guidance on business associate contracts explains that a BAA should define permitted uses and disclosures, require safeguards, address breach reporting, manage subcontractors, and establish what happens to protected health information when the agreement ends.
A BAA is important. It is not a substitute for technical controls.
Think of it like a medical referral. A physician does not refer a patient to a specialist simply because the specialist signed a form. The physician considers qualifications, experience, procedures, and follow-up.
Your vendor process should work the same way. Contracts establish accountability. Due diligence verifies capability. Ongoing monitoring confirms that the relationship remains safe.

Which Vendors Should Be in Your Review?
Start with every third party that can access sensitive information, systems, credentials, or restricted areas.
That includes obvious providers:
- Cloud platforms: Microsoft 365, file storage, email hosting, virtual servers, and backup services.
- IT providers: Managed services providers, consultants, remote support technicians, and software integrators.
- Business applications: Billing, accounting, tax, case management, EHR, payroll, document management, and CRM platforms.
- Copier and printer vendors: Multifunction devices may store documents locally, transmit scans, retain address books, or connect directly to your network.
- Payment and communication providers: Merchant processors, secure portals, texting platforms, mailing services, and e-signature tools.
- Hardware and maintenance vendors: Network installers, alarm companies, camera providers, and building automation contractors.
- Physical service providers: Cleaning crews, shredding companies, couriers, temporary staffing agencies, and facilities personnel.
Not every vendor falls under the exact same regulatory definition. A cleaner who never handles information may not be a “service provider” under the FTC Safeguards Rule. However, that person may still have physical access to unlocked workstations, paper files, server rooms, or unattended devices.
Security is not limited to the network.
A locked server room, clean-desk policy, visitor log, escort requirement, and secure document disposal process can be just as important as endpoint security and email security.

Your Vendor Vetting Checklist
Your process does not need to be complicated. It does need to be consistent and documented.
Use this checklist before granting access:
1. Identify the data and access involved
Ask:
- What information will the vendor receive, store, transmit, or view?
- Does the vendor handle financial information, tax records, legal files, PHI, or credentials?
- Is access continuous, occasional, or emergency-only?
- Can the vendor’s subcontractors access the same information?
- Can the vendor download or export your data?
Classify the vendor as low, moderate, or high risk based on data sensitivity and access level.
2. Verify the vendor’s security capabilities
Request and review appropriate evidence, such as:
- SOC 2 Type II or ISO 27001 reports
- Security policies and summaries
- Penetration test results or executive summaries
- Encryption standards
- MFA and access-control practices
- Backup and disaster recovery procedures
- Incident response documentation
- Employee screening and security training practices
- Cyber insurance coverage
You do not need every document from every vendor. A local office-supply company should not face the same process as a cloud platform storing thousands of client records. Your review should be risk-based.
3. Review the contract
Confirm that the agreement includes:
- Confidentiality obligations
- Specific security requirements
- Breach notification timelines
- Cooperation with investigations and regulatory inquiries
- Restrictions on subcontractors
- Data ownership and approved uses
- Secure return or destruction of information
- Termination rights for material security failures
- Reasonable rights to receive security information or audit evidence
For medical practices, confirm that a BAA is executed where required. For accounting firms, ensure vendor oversight is incorporated into your WISP. For law firms, address client-driven security requirements and confidentiality obligations directly.
4. Monitor the relationship
Vendor risk changes.
Review high-risk vendors at least annually, and reassess others on a schedule appropriate to their risk. Revisit the review after:
- A security incident
- A major product or ownership change
- A new subcontractor
- A change in data handled
- A significant technology migration
- A contract renewal
Maintain a vendor register showing the provider, services, data involved, risk rating, contract status, review date, and outstanding issues.
An IT audit or independent IT assessment can help identify vendors that were overlooked, excessive permissions that were never removed, and contracts that lack meaningful security terms.
Should You Manage Vendor Risk Internally or Use an MSP?
You can build this process internally. Many firms begin with a spreadsheet and a designated administrator.
Internal management: Pros and cons
Pros:
- Direct control over vendor relationships
- Familiarity with business processes
- No additional managed service fee
- Easier coordination with procurement and legal teams
Cons:
- Requires ongoing training
- Vendor security reviews can be inconsistent
- Staff may lack cybersecurity expertise
- Reviews are often postponed during busy seasons
- Employee turnover can interrupt institutional knowledge
- Technical evidence may be difficult to interpret
Managed oversight: Pros and cons
A qualified managed services provider can centralize vendor inventories, review security documentation, manage access, and coordinate remediation.
Pros:
- Predictable costs
- Specialized security expertise
- Economies of scale
- Better documentation
- Continuous visibility into accounts, endpoints, and cloud systems
- Stronger alignment between compliance and daily operations
Cons:
- You must carefully vet the MSP itself
- Implementation takes planning
- Your leadership team remains accountable
- A provider cannot replace informed business decisions or legal advice
If your IT provider has broad administrative access, that provider belongs at the top of your vendor risk list. Ask who can access your environment, how access is logged, how credentials are protected, and what happens if the relationship ends.

Questions to Ask Every High-Risk Vendor
Use these questions during onboarding and renewal:
- Where is our data stored, and in what regions?
- Is our information encrypted at rest and in transit?
- Is MFA required for employees and administrators?
- How do you limit and review privileged access?
- Do you use subcontractors, and can they access our data?
- How quickly will you notify us of a suspected breach?
- When was your last independent security assessment?
- How are backups protected from ransomware?
- How do you test disaster recovery?
- How will our data be returned or destroyed when services end?
- What evidence can you provide that your controls are operating?
- Who is responsible for answering our security questions?
Vague answers are useful information. They tell you where to investigate further.
Final Word
Your vendor ecosystem is part of your security perimeter.
The cloud application. The copier. The billing platform. The IT provider. The person with a key to the office.
Each one can affect your confidentiality, availability, compliance posture, and reputation.
For accounting firms, vendor oversight is a central part of FTC Safeguards and GLBA compliance. For medical practices, BAAs and HIPAA-aligned controls are essential. For law firms, vendor governance supports confidentiality, client trust, and modern law firm cybersecurity expectations.
Do not wait for a ransomware incident, client questionnaire, or regulatory review to reveal the gap.
Create a vendor inventory. Classify the risk. Put safeguards in writing. Monitor the relationship. Remove access when it is no longer needed.
If you need help building a defensible process, A PC of Mind can support your firm with an IT assessment, vendor oversight, endpoint security, ransomware protection, secure cloud environments, and reliable IT support for small business.
Your vendors should extend your capabilities: not quietly extend your attack surface.
This article is for general informational purposes and is not legal advice. Consult qualified legal and compliance counsel to determine which requirements apply to your organization.