SD-17.8 — Vendor, Outsourcing & Service-Provider Oversight
Business Domain: BD-17 Corporate Services & Resources (Cross-cutting — corporate) · Applies: BOTH
Purpose
Oversees the firm’s outsourced providers and vendors — the fund administrators, custodians, data vendors, technology providers and other third parties the firm depends on. SD-17.8 is the commercial and relationship-level oversight of those providers: the due diligence before appointment, the service-level agreement, the ongoing performance and risk review, the concentration and exit-risk assessment. The buy-side firm outsources heavily — administration, custody, data — and the regulator holds it responsible for what it outsources; SD-17.8 is that oversight. It is not the operational, asset-level oversight of a custodian — that is SD-12.5, which watches the assets — SD-17.8 manages the contract and the relationship; SD-12.5 watches what the provider holds.
Service Operations
- Run service-provider due diligence — assess a provider before appointment, and periodically re-assess it.
- Manage service-level agreements — agree, monitor and enforce the SLAs the firm’s providers operate to.
- Review provider performance and risk — periodically review each provider’s performance, financial soundness and operational risk.
- Assess outsourcing and concentration risk — assess the risk the firm carries from its outsourcing, including provider concentration and the fourth-party (sub-outsourcing) chain.
- Manage provider exit and transition — maintain exit plans and manage provider transitions.
Inputs and outputs
- Inputs: the provider population; asset-level evidence from SD-12.5; the providers’ control-assurance reports (via SD-14.7); data-feed-quality evidence from SD-13.4; the outsourcing regulation.
- Outputs: provider due-diligence assessments, SLA-performance records and the outsourcing-risk assessment — consumed by the governing bodies, SD-14.1 Enterprise & Operational Risk Management and the regulators.
Entities
- Consumes: E-01 Legal Entity (the service providers — administrator, custodian and vendor roles); PM-03 Fund Administrator; FO-08 Service-Provider Appointment (the first-class appointment record — SD-17.8 creates and terminates FO-08 rows as part of the provider-lifecycle workflow; consumer SDs read them for operational routing); the SD-12.5 asset-level evidence; the SD-13.4 data-feed-quality evidence; the SD-14.7 providers’ control-assurance reports; E-36 Oversight Exception (from SD-12.16 — the operational-evidence input that feeds the commercial relationship and the exit-risk assessment).
- Owns: FO-08 Service-Provider Appointment — the first-class record of which E-01 legal entity is appointed to which FO-01 fund in which role (custodian / depositary / fund administrator / transfer agent / trustee / auditor / prime broker / ManCo-AIFM / investment manager), with appointed and terminated dates and status. Single owner. The SLA / service-level terms associated with each appointment are an open extension.
Standards
- The outsourcing regulation — the EU outsourcing rules and the DORA (EU Digital Operational Resilience Act, Regulation (EU) 2022/2554) ICT-third-party-risk-management requirements (Chapter V), the FCA outsourcing rules, the SEC outsourcing rule. (Distinct from the DevOps-Research-and-Assessment “DORA metrics” cited under SD-17.9 — same acronym, unrelated bodies.)
- SOC 1 / ISAE 3402 and SOC 2 as the provider control-assurance evidence (reviewed via SD-14.7).
Open extensions
- An SLA / service-level entity.
- The fourth-party (sub-outsourcing) chain sub-model.
- The Service-Operation-level input/output contracts.