What a Real Vendor Risk Assessment Looks Like for a CPA Firm
If you asked most CPA firm owners how they chose their tax software, you'd hear something like "our partner at the time recommended it" or "we've been using it since the firm started." If you asked how they vetted the security of that vendor, you'd hear silence.
That's not a criticism. It's just the reality of how small firms operate. Vendor selection in professional services has historically been driven by functionality, reputation, and relationships. Security was never part of the conversation. But the threat landscape has changed, and the regulations have caught up.
35.5% of all data breaches in 2024 originated from third-party compromises, up from 29% the year before. Supply chain breaches specifically jumped 68% compared to 2023. The pattern is clear: attackers have figured out that compromising one vendor gives them access to dozens or hundreds of downstream clients simultaneously.
For CPA firms, this isn't abstract. Berry, Dunn, McNeil & Parker, an established accounting firm, was breached through their third-party IT service provider. The breach exposed clients' personal data including Social Security numbers, financial account details, and tax information. The IT provider was compromised. The firm's clients paid the price. And the firm bore the regulatory and reputational consequences.
What the FTC Requires
The Safeguards Rule doesn't suggest vendor oversight. It mandates it. Section 314.4(f) requires three specific actions.
First, you must take reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for client data. This means you need a documented basis for trusting the vendors you use.
Second, you must require your service providers, by contract, to implement and maintain safeguards. Not a handshake. Not an assumption. A written agreement that spells out what they're responsible for.
Third, you must periodically assess whether your service providers' safeguards remain adequate. The word "periodically" means at least annually, and more often when circumstances change, such as after a vendor reports a security incident or when you add a new vendor to your ecosystem.
If you've never done a formal vendor assessment, you're not alone. But the gap between "never done it" and "have a process" is smaller than you think.
Step 1: List Your Vendors
Start by inventorying every vendor that touches client data. For a typical CPA firm, this list includes:
Your tax preparation software (Drake, Lacerte, UltraTax, CCH Axcess, ProConnect). Your document management system (ShareFile, SmartVault, Canopy). Your email provider (Microsoft 365, Google Workspace). Your cloud storage (OneDrive, Google Drive, Dropbox). Your client portal. Your payroll processing software. Your scanning and workflow tools. Your IT managed service provider. Your phone system, if it handles voicemail with client information.
Most small firms have between 8 and 15 vendors that handle or have access to client data. Write them all down. This list is the foundation of your vendor oversight program.
Step 2: Prioritize by Risk
Not every vendor carries the same level of risk. Your tax software vendor, which stores Social Security numbers, bank account details, and complete financial histories for every client, presents a fundamentally different risk than your office supply vendor.
Prioritize your assessment based on two factors: the sensitivity of the data the vendor accesses, and the breadth of that access. A vendor that stores and processes data for all of your clients is higher priority than one that handles data for a subset. A vendor that has administrative access to your systems is higher priority than one that provides a standalone product.
Start your assessments with the top five vendors on your risk-prioritized list. You can expand to the rest over the following quarter.
Step 3: Ask the Right Questions
You don't need a 200-question enterprise security questionnaire. For a small firm assessing its core vendors, 10 focused questions cover the essential ground. Here's a practical set you can use:
1. Do you encrypt client data at rest and in transit? This is the baseline. If the answer is no, that's a significant concern regardless of anything else.
2. Do you require multi-factor authentication for access to systems that contain our client data? If the vendor's own employees can access your data with just a username and password, their compromise becomes your compromise.
3. Do you conduct regular vulnerability assessments or penetration testing? How often? You want to know that someone is actively testing their defenses. Annual at minimum, more frequently for high-risk vendors.
4. Do you have a documented incident response plan? How quickly would you notify us if a breach affecting our data occurred? This question reveals whether the vendor has thought about what happens when things go wrong, and whether they'll tell you about it promptly.
5. What security certifications do you hold? SOC 2 Type II is the gold standard for service organizations. The AICPA Trust Services Criteria used in SOC 2 reporting explicitly require evidence of vendor risk assessment and continuous monitoring. If your vendor has a current SOC 2 report, ask for a copy.
6. How do you manage access controls for your employees who handle our data? You want to understand whether the vendor follows the principle of least privilege, meaning their employees only have access to the data they need for their specific job function.
7. What is your data retention and disposal policy? When your relationship with a vendor ends, or when data is no longer needed, how is it destroyed? Does the vendor retain copies of your client data after you stop using their service?
8. Do you carry cyber insurance? A vendor with cyber insurance has made a financial commitment to their own security posture, and that insurance may provide you with an additional layer of protection if the vendor is breached.
9. Will you sign a contract or addendum that includes data protection requirements? This is the FTC requirement. If a vendor won't agree to contractual security obligations, that's a meaningful data point in your assessment.
10. Have you experienced a data breach in the past three years? If so, what happened and what changes did you make? This isn't a disqualifying question. Vendors that have been breached and improved their security may actually be more resilient than vendors that haven't been tested. The quality of the answer matters more than the answer itself.
Step 4: Track and Score the Responses
You don't need complicated software for this. A spreadsheet works fine. Create a row for each vendor and a column for each question. Record their responses and assign a simple score: meets expectations, partially meets expectations, or does not meet expectations.
For each "does not meet" response, decide whether it's a dealbreaker or a gap you can address. If your document management vendor doesn't encrypt data at rest, that's probably a dealbreaker. If your phone system provider doesn't have a SOC 2 report but has reasonable security controls in other areas, that might be acceptable depending on what data they handle.
The AICPA has published guidance on vendor management that includes frameworks for evaluating vendors. Their approach covers governance, policy development, risk assessment, due diligence, and ongoing monitoring. For small firms, the simplified version works: ask the questions, document the answers, make reasonable decisions, and review annually.
Step 5: Update Your Contracts
If your vendor agreements don't include data protection language, they need to. The FTC requires that your contracts with service providers include provisions for implementing and maintaining safeguards and preventing unauthorized access to client information.
At minimum, your vendor contracts should include: a requirement to maintain appropriate security safeguards, an obligation to notify you promptly of any security incident affecting your data, a commitment to cooperate with your incident response efforts, and a right for you to reassess the vendor's security practices periodically.
Many vendors, especially larger software providers, already include security terms in their service agreements. Review what's there. If it's insufficient, ask for an addendum. If the vendor refuses to commit to basic data protection terms, document that refusal and factor it into your assessment.
What You Can Do This Week
-
List your vendors. Open a spreadsheet. Write down every vendor that handles client data. Include the type of data they access and the number of clients affected. This takes 20 minutes.
-
Rank them by risk. Which vendors have access to the most sensitive data? Which ones touch the most clients? Put those at the top.
-
Send the questionnaire to your top three vendors. Copy the 10 questions above into an email. Most vendors will respond within a week or two. Some, especially those with SOC 2 reports, will have pre-built responses ready.
-
Review your contracts. Pull the agreements for your top vendors and look for data protection language. If it's missing, note which contracts need updates.
-
Document everything. Save the vendor list, the questionnaire responses, the contract review, and your assessment decisions. This documentation is your compliance evidence.
The Bottom Line
Vendor risk assessment sounds like something for large enterprises with dedicated compliance teams. It's not. It's a straightforward process that any firm owner can manage with a spreadsheet and 10 good questions.
The FTC expects you to know who handles your client data and to have a reasonable basis for trusting them. That expectation is documented in the Safeguards Rule, and it's not going away. The firms that build a simple vendor assessment process now will be ready when a regulator asks. The firms that don't will be scrambling.
If you want a structured vendor assessment workflow with built-in templates, tracking, and scoring, Kompflow includes vendor oversight as a core module. But the 10 questions and a spreadsheet are enough to start. The important thing is to start.
You trust your vendors. Now document why.