Start with the three questions a regulator would ask, then rank your relationships by what they hold rather than what they cost, then verify one control rather than accepting a summary. That is the whole method, and most family offices could run a first pass in an afternoon.

The reason it does not happen is rarely a shortage of diligence skill. Offices that scrutinise managers and counsel closely are perfectly capable of scrutinising a vendor. It does not happen because nobody has been told the review is theirs, and because the relationships holding the most sensitive information are the ones least likely to be thought of as vendors at all. Your attorney is not a supplier. Your accountant is a trusted professional. Both hold more about the family than your own network does, which is why the advisor network is where exposure concentrates.

The three obligations worth borrowing

There is a well-specified public model for this, though its legal reach is narrower than its usefulness. Under the FTC Safeguards Rule, an organization must “select service providers with the skills and experience to maintain appropriate safeguards,” and must have contracts that “spell out your security expectations, build in ways to monitor your service provider’s work, and provide for periodic reassessments of their suitability for the job.”

The applicability caveat matters. That rule binds entities the FTC treats as “financial institutions,” meaning those engaged in an activity “financial in nature” or incidental to such activities under section 4(k) of the Bank Holding Company Act of 1956. Whether a given family office sits inside that definition depends on what it actually does, and it is a question for counsel. Our recommendation is to adopt the three obligations voluntarily regardless, because they are a better structure than most offices currently use, not because the rule necessarily applies.

What the method looks like underneath

NIST’s supply-chain risk management guidance fills in the mechanics. It describes using “due diligence questionnaires for the initial screening and collection of evidence from potential suppliers,” and treats the point of that work as generating a supplier risk profile rather than filing a response. It also treats the resulting plan as “a living document,” reviewed and refreshed periodically, and is unusually direct that these “are not intended to be documents developed to satisfy a compliance requirement.” NIST publishes an assessment scoping questionnaire as supplemental material, which is a reasonable starting shape even if the questions need translating.

Two scope notes, because they affect how much of this transfers. That guidance is written for federal enterprises acquiring information and operational technology, not for a family office vetting its tax accountant. What transfers is the method: screen with questions, build a risk profile, put requirements in the contract, refresh on a cadence. What does not transfer is its control catalogue and its three-level enterprise structure.

The single most transferable idea is the one NIST calls flow-down: screening requirements should be “a flow-down requirement to relevant sub-level subcontractors.” This matters more for a family office than for most organisations, in our experience, because the sensitive work is frequently done by somebody the office has never heard of. The document management platform behind the law firm. The outsourced bookkeeper behind the family accountant. The staffing agency’s background check subcontractor. Reviewing the firm you signed with, and stopping there, reviews the wrong entity.

Why this is worth the afternoon

Third-party access is not a marginal breach pathway. SecurityScorecard’s STRIKE unit analyzed 1,000 breaches and found 35.5 percent of those in 2024 were linked to third-party access, a 6.5 point rise on 2023, with 41.4 percent of ransomware attacks in the same dataset involving third-party access (2025 Global Third-Party Breach Report). Two honest qualifications: that dataset is cross-industry rather than family offices, and the vendor categories it found most frequently compromised were IT services, cloud platforms and software, which are not the professional advisors this article is mostly about.

The mechanism that makes an advisor compromise different from a data loss is worth stating plainly. FinCEN describes attackers impersonating trusted senior contacts specifically “to discourage employees receiving the fraudulent payment instructions from challenging or confirming the order.” When an advisor’s email is compromised, what the attacker acquires is not primarily documents. It is a channel your office already trusts.

The review itself

Rank by what they hold, not what they cost.
The most expensive relationship is often not the most exposed one. A staffing agency holding household staff records and background checks may carry more family-specific risk than a large platform with a substantial security budget.

Ask for the report, not the certificate.
If a provider holds an ISO 27001 certification or a SOC 2 report, ask for the report itself and read two things: what was in scope, and what exceptions the auditor recorded. A certificate tells you an assessment happened. The scope tells you what it covered, which is frequently narrower than the service you are buying.

Ask what happens when they are breached.
Specifically: are you contractually entitled to be told, within what period, and by whom. The FTC framing requires contracts to build in monitoring, and this is the monitoring question that matters most, because a provider’s own incident is the one you will hear about last.

Accept a narrative answer from professional firms, then verify one control.
Law firms and accountants routinely decline security questionnaires, and pressing a questionnaire on a relationship that predates you is often counterproductive. A written narrative response from their general counsel or IT director is usually obtainable. Then pick one specific control and verify it: how the firm transmits documents to you, or whether privileged matters sit behind separate access. One verified control is worth more than a completed form.

Do not let the reviewed party run the review.
The provider managing your systems should not be the party assessing whether your systems are well managed, which is the same independence argument that applies to choosing a security advisor.

Set a cadence and a name.
Annually, and on any material change to the relationship, with one named owner. The cadence is ours; the requirement to reassess periodically is not. Who that owner is has already been worked out in our piece on family office cybersecurity governance, which places it with the COO.

What a review will not do

It will not tell you a provider is secure. It surfaces which relationships you cannot currently describe, which is a different and more useful result. In practice the first pass tends to produce a short list of providers whose access nobody can account for, and that list is the actual output.

It also will not survive as a one-off. NIST’s point about living documents applies exactly here: a review completed once and filed is a compliance artefact, and the offices that get value from this treat it as a recurring obligation attached to a person.

Where to start

  • List every outside party that holds family information or can move money, then rank the list by what they hold.
  • Take the top three and ask them the four questions above: scope of any audit report, exceptions, breach notification entitlement, and who their own subcontractors are.
  • Put the answers next to the relationship, with a date, and set the next review.

Designing the review and its question set is work we handle through cybersecurity program development. Running it on a cadence, and being the party that reads the audit reports and pushes back on a weak answer, is what ongoing advisory is for.

Sources

U.S. Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know

NIST Special Publication 800-161r1-upd1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, November 2024 update

SecurityScorecard STRIKE, 2025 Global Third-Party Breach Report, March 2025

FinCEN Advisory FIN-2019-A005, Updated Advisory on Email Compromise Fraud Schemes Targeting Vulnerable Business Processes