Vendor Risk & Data Mapping
Your firm relies on a dozen-plus outside vendors. Every one is a place client and employee information can be collected, shared, or forgotten about.
Built for law firms, CPA practices, and wealth management firms.
Start With a Vendor & Data ReviewThe Problem
Microsoft 365. QuickBooks. DocuSign. Dropbox. A CRM. Payroll. Cloud backup. Website forms. An AI meeting assistant. That's nine systems before you even count browser extensions, old accounts, and tools employees picked on their own.
The real question: what are we giving them, where does it go, who else gets it — and do we still need to be doing it?
What We Do
01
Build the Inventory
A working list of every vendor touching your firm's information — not a compliance checkbox, an actual living record.
02
Map the Data
Client → employee → application → vendor → subprocessor. We trace where sensitive information enters and where it leaves your control.
03
Assess the Risk
Sensitivity, access, retention, AI use, and contractual controls — ranked, not treated like every vendor is equal risk.
In Practice
Real findings from a 12-person CPA firm running M365, QuickBooks, DocuSign, a CRM, and a handful of AI tools:
- Website intake form quietly routes client data through a third-party service nobody flagged
- An old cloud storage account still holds client files no one remembered
- Former employees still have active access in several platforms
- Multiple staff created personal AI accounts using company email
- A key vendor changed its AI/privacy terms after the firm signed on
None of this required ripping out the tech stack. Turn it off. Restrict access. Update the agreement. Document the decision.
Sound familiar? That's exactly what we find.
Start With a Vendor & Data ReviewWhat You Receive
Vendor Inventory
Every important vendor, what they do, what they touch, and who owns the relationship.
Data Map
A practical map of how information moves through your firm and where third parties enter.
Vendor Risk Tracker
Prioritized findings, recommended actions, ownership, and remediation status.
Remediation Roadmap
Disable this. Restrict that. Close these accounts. Ranked by importance and effort.
If nobody at your firm can confidently say what vendors have your sensitive data and why, that's the problem we solve.
Start With a Vendor & Data Review