Home › Industries › Wealth Management
Third-Party and Vendor Risk for Canadian Wealth-Management Firms
Last updated: May 2026 · Reviewed by Mike Pearlstein, CISSP
Wealth-management firms run on vendors: custodians, portfolio platforms, and outsourced IT. CIRO expects firms to understand and manage the risk those vendors introduce. This is what a practical vendor-risk posture looks like for a small or mid-size Canadian firm.
- CIRO named third-party risk in its Compliance Report for 2026 and pointed dealers at Guidance Note GN-2300-21-003 on outsourcing arrangements.
- Assess a vendor at all three stages: before, during, and after the engagement. Most firms only do the first.
- The core artifacts are vendor due diligence, a clear answer on where client data is processed, and current access records.
- CIPF coverage is custodial only. It will not make a client whole after a vendor breach, so do not let anyone treat it as a backstop.
- A firm of 8 to 40 people can meet the expectation without a compliance team, provided the evidence stays current rather than being rebuilt at exam time.
When a wealth firm hands me its vendor list during onboarding, the surprise is almost always the gap between the list and reality. Across our Canadian client base the written list runs to six or eight names. The real count, once we trace who can actually reach client data, usually lands closer to twenty. The extra ones are e-signature tools, a marketing platform holding contact records, and whoever the previous IT provider left standing.
Why vendor risk is a regulator question
CIRO put third-party risk in writing. Its Compliance Report for 2026 is bulletin 26-0034, published February 17, 2026. It records “an increase in cases involving third-party service providers affecting our dealers.” It then sets the standard. Firms must “assess risks at all stages: before, during, and after the engagement.”
That last clause is the part most firms miss. Due diligence at signing is common. Due diligence during the relationship, and an exit plan for after it, is rare. CIRO points dealers at Guidance Note GN-2300-21-003: Outsourcing Arrangements, which sets out what functions may be outsourced and what the firm is expected to manage.
The reporting duty is the part I make sure owners understand. IDPC Rule 3703 requires investment dealers to report cybersecurity incidents that meet defined criteria, and a vendor incident that reaches your systems is your incident to report. CIRO also says it will run another cybersecurity table-top exercise in 2026, aimed particularly at small and mid-sized dealers.
According to the Canadian Centre for Cyber Security (2025), ransomware remains the top cybercrime threat to Canadian critical infrastructure. The Canadian Anti-Fraud Centre reports business losses in the hundreds of millions each year, led by business email compromise, and notes most fraud is never reported at all.
A wealth firm’s data and operations depend on third parties. CIRO expects registered firms to understand and oversee that dependency, because a vendor incident becomes the firm’s incident.
The point is not to eliminate vendors. It is to know what each one does, what data it holds, and what the firm would do if that vendor failed or was breached.
What is third-party risk for an advisory firm, explained
Third-party risk is the exposure a firm keeps after it hands work to someone else. The custodian, the portfolio platform, the CRM, the e-signature tool and the outsourced IT provider each hold or touch client information. Regulators treat that exposure as the firm’s own, because the client relationship, the records duty and the supervision obligation never transfer with the work.
Three misreadings cost firms the most, and I hear all of them in my first meeting with a new advisory client.
“Our custodian is regulated, so we are covered”
A regulated custodian reduces custody risk. It does nothing about the marketing platform holding your client list, and it does not answer for your own systems. Scope your inventory to everything that touches client data, not just the balance sheet.
“CIPF protects the client anyway”
CIPF is explicit that its coverage “is custodial in nature” and “does not provide protection against any other type of risk or loss.” It answers member insolvency. It does not answer a vendor breach, a wire redirected by fraud, or an outage that stops you trading.
“OSFI B-13 does not apply to us”
Strictly true for most advisory firms. Guideline B-13, effective July 31, 2022, applies to federally regulated financial institutions, including foreign bank and insurance branches. It still reaches you sideways, because the bank or insurer you partner with pushes B-13 expectations down through its own vendor questionnaire. Answering B-13-shaped questions is often the real trigger for this work.
Want this reviewed against your firm’s current setup?
The artifacts to keep: the criteria an examiner actually asks for
Four documents carry most of the weight. First, a vendor inventory naming every third party that touches client data. Second, due-diligence records showing what each attests to. Third, a written answer on where that data is processed. Fourth, current access records showing who can reach what. The Canadian Centre for Cyber Security Baseline Controls map cleanly onto a small firm.
1. The vendor inventory
One row per third party. What it does, what data it holds, who owns the relationship, and the renewal date. If a vendor cannot be described in one sentence, that is itself a finding.
2. Due diligence, dated
What the vendor attests to, and when you last checked. CIRO’s own examinations found dealers who assessed a counterparty at onboarding and never revisited it. The regulator flagged the same pattern in referral arrangements, where firms “failed to conduct due diligence, including assessing potential conflicts of interest prior to onboarding referral entities.”
3. Where the data is processed
Answer it honestly rather than aspirationally. Canadian residency is not a legal requirement here. The Office of the Privacy Commissioner is direct about it. PIPEDA “does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.” Schedule 1, Principle 4.1.3 sets the duty as comparable protection by contract. So record where the data goes and what contract protects it. A Canadian data centre is not the test.
4. Access records
Who at the vendor can reach your environment, who at your firm can reach theirs, and when that was last reviewed. This is the artifact firms most often cannot produce on the day it is asked for.
These are what a firm hands over during a CIRO examination or an institutional partner’s vendor review. Kept current, the request turns from a scramble into a retrieval.
Making it manageable for a small firm: what the rule requires, explained
Size does not lower the bar, and the usual scare statistic is backwards. Statistics Canada found 16% of Canadian businesses were impacted by a cyber security incident in 2023, and large businesses were the most likely to be hit, at 30%. Small firms are not targeted disproportionately. They are simply thinner on the people who would notice.
I want to be blunt about that number, because the inverted version of it gets quoted at wealth firms constantly. The honest case for doing this work is simpler. A 12-person advisory firm has nobody whose job is to check. CIRO sets the same expectations whatever your headcount.
A small firm does not need an enterprise vendor-management platform. A maintained list of vendors, their data access, and their attestations, reviewed once or twice a year, covers most of the expectation.
A vendor list you rebuild for an examination is not a control. It is a performance. The one that protects clients is the one somebody updates when a contract is signed.
Mike Pearlstein, CISSP, Fusion Computing
Fusion Computing manages much of this for clients. We audit the vendor list, produce the control summaries, and run the access reviews, so my clients have the evidence ready before anyone asks for it.
Outsourced versus in-house: how to compare the answers you get back
Compare vendors on evidence rather than assurance. Ask each one for its incident-notification window in hours, its subcontractor list, where client data is processed, its most recent independent assessment, and what happens to your data at termination. A vendor that answers four of five in writing is usually a better partner than one that answers five verbally.
AI has now joined that list. In the same 2026 report CIRO says examiners “will be enquiring about the use of AI in dealers’ operations.” They will be “reviewing the operational controls they implemented.” If a vendor quietly added AI features to a platform touching client records, that is now an examination topic.
Two follow-ups are worth putting to every incumbent this year.
- Does any part of your service now use AI on our client data?
- Did that change require us to notify CIRO of a material business change?
The regulator points firms to Form 33-109F5 and Guidance Notice GN-2200-21-001 for exactly that question. Want these questions put to your vendors in writing? Book a vendor-risk review.
If you are still choosing that provider, our buyer comparison of IT providers for Canadian financial-services firms sets out the 10 CCCS ITSM.50.030 areas to put to every shortlisted vendor in writing.
Free download
The Wealth-Management Cybersecurity Controls Checklist (2026)
The vendor inventory, access records, and control evidence described above, written as 42 yes/no items you can audit before your next CIRO examination or institutional vendor review. Built for wealth firms, with a scoring guide and a full vendor-risk section.
No sales call required. Want your own vendor list checked against these controls? Book a consultation.
Frequently asked questions
The questions below are the ones advisory firms actually ask us, drawn from CIRO’s Compliance Report for 2026, Guidance Note GN-2300-21-003 on outsourcing, and the vendor questionnaires institutional partners send down. Each answer carries the specific figure or instrument the question turns on.
What does CIRO expect on third-party risk?
Can a small firm meet this without a compliance team?
What does CIRO say about third-party service providers?
Does CIPF protect clients if a vendor is breached?
Does OSFI Guideline B-13 apply to an advisory firm?
Must client data stay in Canada?
Is my vendor using AI on our client data a regulatory issue?
Is Fusion Computing the same as Fusion Cyber Group?
A partner mailbox is the most common third-party path to a redirected transfer. Our guide to wire fraud and business email compromise at wealth firms covers the kill-chain and the one control that breaks it.
Talk to Fusion about your firm’s security
The work is small and the deadline is not yours to set. CIRO’s Compliance Report for 2026 tells dealers to assess third parties before, during and after an engagement, and Guidance Note GN-2300-21-003 sets the outsourcing expectations behind it. In my experience a first vendor inventory takes about half a day.
Start with the inventory. Fusion Computing runs the first pass with you and maps each vendor to what it can reach. We deliver the due-diligence and access records in a form a CIRO examiner will accept.
Book a consultation or call (416) 566-2845
Written by Mike Pearlstein, CISSP, founder of Fusion Computing, a Canadian managed IT and cybersecurity provider serving regulated SMBs since 2012.
Regulated industries we secure. Law firms. Accounting firms. Financial services. Wealth management.
Related: the CIRO cybersecurity guide for wealth firms · compare IT providers for wealth-management firms.

