Home /

Vendor Management: How to Audit Your Service Providers

You’re probably writing checks to a dozen service providers every month, lawyers, accountants, IT consultants, a property manager, maybe a cleaning service that knows where you keep the good silverware, and you likely have no idea which of them are actually earning their fee.

Most families with real wealth treat vendor relationships like subscriptions they forgot to cancel. The retainer renews, the invoice gets paid, and nobody asks the uncomfortable questions. That’s a problem, and it’s a fixable one.

Why Paying the Retainer Isn’t the Same as Managing the Vendor

A family office exists to protect and grow wealth across generations, and that means managing more than the investment portfolio. It means managing everyone who touches the family’s money, data, and private life. Lawyers see the estate plan. Accountants see every transaction. IT providers hold the keys to email and cloud storage. The cleaning service knows when the house is empty. Each of those relationships is a risk, and risk that isn’t managed is risk that’s ignored.

Start with a simple annual review. Once a year, put every vendor relationship through three questions: what did we pay, what did we get, and should we continue. That sounds basic because it is basic, and almost nobody does it. Families under $500 million in assets tend to outsource heavily. Families in the $1 billion to $3 billion range outsource selectively, often keeping investment consulting in-house while pushing IT and fund administration outside. Above $3 billion, outsourcing narrows to niche functions that need global reach or occasional specialty work. Wherever you fall on that spectrum, every outside relationship should get reevaluated at least once a year.

Build a Kill Switch Into Every Contract

Here’s what nobody thinks about until it’s too late: what happens when a vendor gets hacked. Picture your accountant’s email getting compromised, handing a bad actor wire instructions, account numbers, and personal information for the whole family. Or a property manager whose staff is careless with keys, turning your vacation home into a target. These aren’t hypotheticals. They happen, and when they do, most families discover they’re locked into contracts that make it slow or expensive to walk away.

The fix is contract language that allows immediate termination on a security breach, a data exposure, or a failure to maintain agreed security standards. No waiting period, no penalty fee. If a vendor becomes a liability, you should be able to leave the same day. That’s not paranoia, it’s planning.

What a Real Cyber-Audit Checks

Multi-factor authentication is table stakes now. Any vendor handling sensitive data should require more than a password, and if they don’t, that’s a real red flag. SOC 2 compliance goes further: it’s a certification, backed by an independent audit, of a vendor’s controls around security, availability, processing integrity, confidentiality, and privacy, and keeping it requires ongoing reassessment, not a one-time check.

For custodians and financial service providers, families often push further and ask whether the vendor uses hardware security modules to store cryptographic keys, whether those modules meet federal information processing standards, and whether the physical facility has real security, armed guards, no exposed access points. That level of scrutiny fits when you’re protecting generational wealth. For a bookkeeper or a virtual assistant, the bar is lower but the question is the same: is MFA enabled on every account that touches your data. If the answer is no and the vendor won’t fix it, replace them.

Someone Has to Own This

Auditing vendors takes time, reviewing contracts takes expertise, and tracking whether a relationship still delivers value takes discipline most family members don’t want to provide themselves, and shouldn’t have to. That’s the case for a dedicated vendor management function: someone who owns service level agreements, tracks key performance indicators, and runs the annual review whether or not anyone feels like scheduling it.

One client came in with a vendor list that ran three pages: law firms, accounting practices, concierge services, IT providers, insurance brokers, and no single person had ever reviewed all of them together. A simple checklist, applied to every vendor, surfaced the problems fast. One accountant hadn’t updated their systems in four years. A property manager was using a shared email password across staff. A long-tenured law firm was charging legacy rates the market had left behind. None of that was hidden exactly, it just had never been looked at directly. You can’t manage what you don’t measure, and you can’t protect what you don’t audit.

Educational only, not tax, legal, or investment advice. Check primary sources and speak with a qualified professional before making financial decisions.

Sources

    Jake Claver

    Written by

    Jake Claver

    Family office professional working on how substantial holdings are held, structured and passed on. Qualified Family Office Professional. Finance degree, University of North Texas. Board member, Arkansas Blockchain Council. Author of Wealth in Numbers and Infinite Banking for Crypto Investors.