The Shadow Chain: You Hire One Vendor But You Get All Their Mistakes
Written by Team WEBDYNASTY
We often think our responsibility ends where our contract ends. In compliance, that is no longer true.
Think of it like this. You hire a fund admin you trust. That fund admin stores your client data on a cloud service. That cloud service uses another company to fix problems. You never met that last company. You never signed anything with them. But if they make a mistake, regulators will come to you.
That hidden line of companies is called the shadow chain. And now regulators are very clear that you must manage it.
What changed
For many years, the rule was simple. Have a written policy and check it once a year. That was Advisers Act Rule 206 4 7. Most firms thought a vendor form at the start was enough.
Now three regulators have made it stricter.
First, the SEC. In May 2024 it updated Regulation S P for the first time since 2000. Now every covered firm needs a written plan for how to respond to a breach. Your vendor must tell you within 72 hours if something goes wrong. And you must tell your clients within 30 days. Big firms had to follow this by December 2025 and small firms by June 2026. So this rule applies today.
Second, FINRA. FINRA looks after broker dealers. In its notices 05 48 and 21 29 it said outsourcing does not remove your duty to supervise. If your vendor keeps your books on its system, that system must still meet the rules.
Third, NFA. NFA looks after CPOs and CTAs. Its Rule 2 9 and Notice 9079 say the same thing. If you outsource a compliance job, you still need to show how you checked the vendor at the start, how you check them regularly, and how you will exit if needed.
All three are asking the same question. How do you watch your vendors after you hire them.
Where firms actually get into trouble
If you look at SEC cases, the problem rarely starts inside the firm.
One pattern is email. Hackers got into a contractor email account that was connected to the firm and stole client data from there.
Another pattern is disposal. In 2022 Morgan Stanley had to pay 35 million dollars because a company it hired to destroy servers did not destroy them properly. That company gave the work to another company and hard drives with 15 million client records were found for sale online.
A third pattern is system connections. In January 2025 Robinhood paid 45 million dollars in part because outside tools had too much access to its internal systems.
In each case the firm did not plan to be careless. It just stopped checking after the first vendor.
How to fix it in a simple way
Do not treat vendor management as just buying a service. Treat it as mapping a small network.
First, map more than one layer. Do not just write firm to vendor. Write firm to vendor, vendor to its cloud host, cloud host to who can access data, and how your own team connects their own tools to the firm system. If you cannot write the second layer, you have a blind spot.
Second, sort by risk not by price. A 500 dollar per month archiving tool that holds every client email is high risk. A 50 thousand dollar per year office cleaning service is low risk. Sort by who can see private client information and who can cause harm to clients.
Third, make it a continuous cycle. Check a vendor when you hire them. Check their security report and who they work with. Then check again every quarter if they are high risk. If they launch a new AI tool or move data to a new place, check again right away. And decide at the start how you will get your data back and how they will delete it when you leave.
That is what examiners want to see now.
Last thought
Compliance is no longer only about what happens inside your office. It is about your whole network.
If you still manage vendors with a spreadsheet and an old form, you will miss the weak link. The question today is not do you have a vendor list. The question is can you show your network, how you sorted it by risk, and when you last checked the company that your vendor hired.
If you cannot answer that last part quickly, that is where your risk lives.