Third-Party and Vendor Risk for Canadian Wealth-Management Firms

Tags:

HomeIndustriesWealth Management

Third-Party and Vendor Risk for Canadian Wealth-Management Firms

Last updated: May 2026 · Reviewed by Mike Pearlstein, CISSP

Wealth-management firms run on vendors: custodians, portfolio platforms, and outsourced IT. CIRO expects firms to understand and manage the risk those vendors introduce. This is what a practical vendor-risk posture looks like for a small or mid-size Canadian firm.

Talk to Fusion

CISSP-led. Canada’s 50 Best Managed IT (2024 & 2025). Microsoft Solutions Partner. Canadian-owned, serving regulated SMBs since 2012.
Key takeaways

  • CIRO named third-party risk in its Compliance Report for 2026 and pointed dealers at Guidance Note GN-2300-21-003 on outsourcing arrangements.
  • Assess a vendor at all three stages: before, during, and after the engagement. Most firms only do the first.
  • The core artifacts are vendor due diligence, a clear answer on where client data is processed, and current access records.
  • CIPF coverage is custodial only. It will not make a client whole after a vendor breach, so do not let anyone treat it as a backstop.
  • A firm of 8 to 40 people can meet the expectation without a compliance team, provided the evidence stays current rather than being rebuilt at exam time.
From the field
When a wealth firm hands me its vendor list during onboarding, the surprise is almost always the gap between the list and reality. Across our Canadian client base the written list runs to six or eight names. The real count, once we trace who can actually reach client data, usually lands closer to twenty. The extra ones are e-signature tools, a marketing platform holding contact records, and whoever the previous IT provider left standing.

Why vendor risk is a regulator question

CIRO put third-party risk in writing. Its Compliance Report for 2026 is bulletin 26-0034, published February 17, 2026. It records “an increase in cases involving third-party service providers affecting our dealers.” It then sets the standard. Firms must “assess risks at all stages: before, during, and after the engagement.”

That last clause is the part most firms miss. Due diligence at signing is common. Due diligence during the relationship, and an exit plan for after it, is rare. CIRO points dealers at Guidance Note GN-2300-21-003: Outsourcing Arrangements, which sets out what functions may be outsourced and what the firm is expected to manage.

The reporting duty is the part I make sure owners understand. IDPC Rule 3703 requires investment dealers to report cybersecurity incidents that meet defined criteria, and a vendor incident that reaches your systems is your incident to report. CIRO also says it will run another cybersecurity table-top exercise in 2026, aimed particularly at small and mid-sized dealers.

According to the Canadian Centre for Cyber Security (2025), ransomware remains the top cybercrime threat to Canadian critical infrastructure. The Canadian Anti-Fraud Centre reports business losses in the hundreds of millions each year, led by business email compromise, and notes most fraud is never reported at all.

A wealth firm’s data and operations depend on third parties. CIRO expects registered firms to understand and oversee that dependency, because a vendor incident becomes the firm’s incident.

The point is not to eliminate vendors. It is to know what each one does, what data it holds, and what the firm would do if that vendor failed or was breached.

What is third-party risk for an advisory firm, explained

Third-party risk is the exposure a firm keeps after it hands work to someone else. The custodian, the portfolio platform, the CRM, the e-signature tool and the outsourced IT provider each hold or touch client information. Regulators treat that exposure as the firm’s own, because the client relationship, the records duty and the supervision obligation never transfer with the work.

Three misreadings cost firms the most, and I hear all of them in my first meeting with a new advisory client.

“Our custodian is regulated, so we are covered”

A regulated custodian reduces custody risk. It does nothing about the marketing platform holding your client list, and it does not answer for your own systems. Scope your inventory to everything that touches client data, not just the balance sheet.

“CIPF protects the client anyway”

CIPF is explicit that its coverage “is custodial in nature” and “does not provide protection against any other type of risk or loss.” It answers member insolvency. It does not answer a vendor breach, a wire redirected by fraud, or an outage that stops you trading.

“OSFI B-13 does not apply to us”

Strictly true for most advisory firms. Guideline B-13, effective July 31, 2022, applies to federally regulated financial institutions, including foreign bank and insurance branches. It still reaches you sideways, because the bank or insurer you partner with pushes B-13 expectations down through its own vendor questionnaire. Answering B-13-shaped questions is often the real trigger for this work.

Want this reviewed against your firm’s current setup?

Book a no-obligation review

The artifacts to keep: the criteria an examiner actually asks for

Four documents carry most of the weight. First, a vendor inventory naming every third party that touches client data. Second, due-diligence records showing what each attests to. Third, a written answer on where that data is processed. Fourth, current access records showing who can reach what. The Canadian Centre for Cyber Security Baseline Controls map cleanly onto a small firm.

1. The vendor inventory

One row per third party. What it does, what data it holds, who owns the relationship, and the renewal date. If a vendor cannot be described in one sentence, that is itself a finding.

2. Due diligence, dated

What the vendor attests to, and when you last checked. CIRO’s own examinations found dealers who assessed a counterparty at onboarding and never revisited it. The regulator flagged the same pattern in referral arrangements, where firms “failed to conduct due diligence, including assessing potential conflicts of interest prior to onboarding referral entities.”

3. Where the data is processed

Answer it honestly rather than aspirationally. Canadian residency is not a legal requirement here. The Office of the Privacy Commissioner is direct about it. PIPEDA “does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.” Schedule 1, Principle 4.1.3 sets the duty as comparable protection by contract. So record where the data goes and what contract protects it. A Canadian data centre is not the test.

4. Access records

Who at the vendor can reach your environment, who at your firm can reach theirs, and when that was last reviewed. This is the artifact firms most often cannot produce on the day it is asked for.

These are what a firm hands over during a CIRO examination or an institutional partner’s vendor review. Kept current, the request turns from a scramble into a retrieval.

Making it manageable for a small firm: what the rule requires, explained

Size does not lower the bar, and the usual scare statistic is backwards. Statistics Canada found 16% of Canadian businesses were impacted by a cyber security incident in 2023, and large businesses were the most likely to be hit, at 30%. Small firms are not targeted disproportionately. They are simply thinner on the people who would notice.

Large businesses were the most likely to be impacted, not small ones.Statistics Canada reported that 16 percent of Canadian businesses were impacted by a cyber security incident in 2023, and that large businesses remained the most likely to be impacted at 30 percent.Businesses impacted by a cyber incident, 2023.Large firms were hit most often, contrary to the usual claim.16%All businesses.30%Large businesses.Source: Statistics Canada, 2023 reference year, fusioncomputing.ca.
Large businesses were the most likely to be impacted at 30%, against 16% across all businesses. Source: Statistics Canada.

I want to be blunt about that number, because the inverted version of it gets quoted at wealth firms constantly. The honest case for doing this work is simpler. A 12-person advisory firm has nobody whose job is to check. CIRO sets the same expectations whatever your headcount.

A small firm does not need an enterprise vendor-management platform. A maintained list of vendors, their data access, and their attestations, reviewed once or twice a year, covers most of the expectation.

A vendor list you rebuild for an examination is not a control. It is a performance. The one that protects clients is the one somebody updates when a contract is signed.

Mike Pearlstein, CISSP, Fusion Computing

Fusion Computing manages much of this for clients. We audit the vendor list, produce the control summaries, and run the access reviews, so my clients have the evidence ready before anyone asks for it.

Outsourced versus in-house: how to compare the answers you get back

Compare vendors on evidence rather than assurance. Ask each one for its incident-notification window in hours, its subcontractor list, where client data is processed, its most recent independent assessment, and what happens to your data at termination. A vendor that answers four of five in writing is usually a better partner than one that answers five verbally.

AI has now joined that list. In the same 2026 report CIRO says examiners “will be enquiring about the use of AI in dealers’ operations.” They will be “reviewing the operational controls they implemented.” If a vendor quietly added AI features to a platform touching client records, that is now an examination topic.

Two follow-ups are worth putting to every incumbent this year.

  • Does any part of your service now use AI on our client data?
  • Did that change require us to notify CIRO of a material business change?

The regulator points firms to Form 33-109F5 and Guidance Notice GN-2200-21-001 for exactly that question. Want these questions put to your vendors in writing? Book a vendor-risk review.

If you are still choosing that provider, our buyer comparison of IT providers for Canadian financial-services firms sets out the 10 CCCS ITSM.50.030 areas to put to every shortlisted vendor in writing.

Free download

The Wealth-Management Cybersecurity Controls Checklist (2026)

The vendor inventory, access records, and control evidence described above, written as 42 yes/no items you can audit before your next CIRO examination or institutional vendor review. Built for wealth firms, with a scoring guide and a full vendor-risk section.



No sales call required. Want your own vendor list checked against these controls? Book a consultation.

Frequently asked questions

The questions below are the ones advisory firms actually ask us, drawn from CIRO’s Compliance Report for 2026, Guidance Note GN-2300-21-003 on outsourcing, and the vendor questionnaires institutional partners send down. Each answer carries the specific figure or instrument the question turns on.

What does CIRO expect on third-party risk?
That registered firms understand and manage the risk introduced by the vendors that touch their systems and client data, including knowing where data lives and what happens if a vendor has an incident.
Can a small firm meet this without a compliance team?
Yes. A maintained vendor list with data access and attestations, reviewed once or twice a year, covers most of the expectation. A managed IT provider can own much of the work.
What does CIRO say about third-party service providers?
Its Compliance Report for 2026 is bulletin 26-0034, published February 17, 2026. CIRO records an increase in incident cases involving third-party service providers. It tells dealers to assess risk “before, during, and after the engagement.” It directs firms to Guidance Note GN-2300-21-003 on outsourcing arrangements. IDPC Rule 3703 then governs reporting a cybersecurity incident that meets the criteria.
Does CIPF protect clients if a vendor is breached?
No. CIPF states that its coverage “is custodial in nature” and “does not provide protection against any other type of risk or loss.” It answers the insolvency of a member firm. A vendor breach, a fraudulent wire, or an outage that stops you trading all sit outside it, which is why firms carry their own controls and insurance instead.
Does OSFI Guideline B-13 apply to an advisory firm?
Usually not directly. B-13, effective July 31, 2022, applies to federally regulated financial institutions, including foreign bank and insurance branches. Most advisory firms are not FRFIs. It still reaches them through the vendor questionnaires their banking and insurance partners send down, so B-13-shaped questions are worth being able to answer in writing.
Must client data stay in Canada?
Not as a matter of law. The Office of the Privacy Commissioner states that PIPEDA “does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.” Schedule 1, Principle 4.1.3 requires comparable protection by contract. Record where the data is processed, hold the vendor to that standard, and disclose it. Residency is a contractual and transparency question, not a border one.
Is my vendor using AI on our client data a regulatory issue?
It can be. CIRO says examiners “will be enquiring about the use of AI in dealers’ operations.” They will review “the operational controls they implemented.” If a vendor adds AI features touching client records, ask whether that is a material business change. Notice goes on Form 33-109F5, per Guidance Notice GN-2200-21-001.
Is Fusion Computing the same as Fusion Cyber Group?
No. Fusion Computing Limited and Fusion Cyber Group (fusioncyber.ca) are separate businesses. Fusion Computing was founded in 2012 in Toronto and is CISSP-led, with founder Mike Pearlstein holding the CISSP.

A partner mailbox is the most common third-party path to a redirected transfer. Our guide to wire fraud and business email compromise at wealth firms covers the kill-chain and the one control that breaks it.

Talk to Fusion about your firm’s security

The work is small and the deadline is not yours to set. CIRO’s Compliance Report for 2026 tells dealers to assess third parties before, during and after an engagement, and Guidance Note GN-2300-21-003 sets the outsourcing expectations behind it. In my experience a first vendor inventory takes about half a day.

Start with the inventory. Fusion Computing runs the first pass with you and maps each vendor to what it can reach. We deliver the due-diligence and access records in a form a CIRO examiner will accept.

Book a consultation   or call (416) 566-2845

About the author
Written by Mike Pearlstein, CISSP, founder of Fusion Computing, a Canadian managed IT and cybersecurity provider serving regulated SMBs since 2012.

Regulated industries we secure. Law firms. Accounting firms. Financial services. Wealth management.

Related: the CIRO cybersecurity guide for wealth firms · compare IT providers for wealth-management firms.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611