Vendor Due Diligence Is the Real Job for an RIA's Procurement
For a registered investment advisor, vendor due diligence is the real procurement job, and Procurify's request-first flow creates the timestamped pre-purchase approval record an examiner wants more naturally than Airbase's card-first flow. Neither platform performs the due diligence itself; that stays with your compliance officer.
Getting that trail right matters more here than in most industries, because an examiner isn't just checking whether you paid on time, they're checking whether you can prove you thought about vendor risk before you signed.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
What an Examiner Actually Asks to See
A typical SEC exam vendor-management request wants to see the firm's vendor risk assessment process, evidence that new vendors handling client data or funds were reviewed before onboarding, and a record of who approved that decision and when. A firm that can only produce vendor invoices, with no record of a pre-purchase review, is answering half the question. The other half, proof that someone evaluated the vendor's data security and access to client information before signing, has to live somewhere, and a spend platform's approval history is one of the more natural places to keep it if the approval step is built to capture it.
Why Procurify's Request-First Model Fits This Job Better
Procurify's default behavior, requiring a request and approval before a purchase clears, naturally creates the kind of pre-purchase record an examiner wants: who requested the vendor, who approved it, and when, all timestamped before money moved. Adding a required field for data access level, does this vendor touch client PII, account data, or trading systems, turns that approval record into something closer to the due diligence documentation compliance actually needs, rather than a generic purchase log.
Where Airbase Still Fits: Low-Risk, Recurring Operating Spend
Not every purchase an RIA makes touches client data or carries compliance risk, office supplies, a scheduling tool, conference registration fees. For that category, Airbase's card-first speed is a reasonable fit, because forcing every low-risk purchase through a compliance-grade review wastes the compliance team's attention on things that don't need it. The discipline is in the split: know which vendor categories actually carry data or fiduciary risk and route only those through the slower, request-first, documented path.
A Worked Example: Adding a New Market Data Vendor
Say the firm wants to add a new market data feed to support a growing set of client portfolios. If that request routes through Procurify with a required data-access field, the compliance officer sees, before the vendor is engaged, exactly what data the feed will touch and can document the review. If the same purchase happens on a card with no structured review step, the compliance record for that vendor relationship might not exist at all until someone builds it retroactively for an exam, usually under time pressure and with gaps that are hard to fill months later.
A Common Mistake: Treating Vendor Review as a One-Time Event
Some firms do a careful review when a vendor is first onboarded and then never revisit it, even as the vendor's role or data access expands. A market data provider that starts as a read-only feed but later gets connected to portfolio rebalancing logic has taken on a materially different risk profile, and that change deserves its own review, not a pass based on the original onboarding. Building a periodic vendor review, annually at minimum for anything touching client data, into the approval platform's calendar is what turns a one-time compliance check into an actual ongoing control.
Building the Data Access Question Into Every Request
The single most useful change most RIAs can make to either platform is adding one required question to the purchase request form: does this vendor touch client PII, account data, custodial credentials, or trading systems? A vendor that answers yes gets routed to the compliance officer for review before approval; a vendor that answers no can move through the standard operating-spend approval path. That one field, consistently required, does more to satisfy an examiner's due diligence question than any amount of after-the-fact documentation, because it captures the risk assessment at exactly the moment it matters, before the relationship starts.
Firms that skip this step often find, during an exam, that they can produce a general vendor list but can't easily separate which vendors actually touch client data from which don't, which turns a routine document request into a scramble to reconstruct that distinction under time pressure.
Build the data access question into every request:
- Add one required field asking whether the vendor touches client PII, account data, custodial credentials or trading systems.
- Route any yes answer to the compliance officer for review before approval, so the review is documented before the vendor is engaged.
- Let vendors that answer no move through the standard operating-spend path without compliance sign-off on each purchase.
- Trigger a fresh review when a vendor's role or data access expands, instead of relying on the original approval.
What Good Looks Like
A well-run RIA can produce, for any vendor with access to client data, a timestamped record of who reviewed and approved that relationship before it began, along with evidence that access has been reviewed periodically since.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Vendor invoices that arrive outside the platform still need an approval trail before payment, and BILL's workflow keeps that record intact for vendors that don't route through the main compliance review.
A firm engaging independent contractors, such as outside compliance consultants, needs W-9 collection and TIN verification handled at intake, and Tax1099 catches that before the first invoice.
Keeping the firm's own operating cash clearly separate from any client asset accounts is a baseline expectation for an RIA, and Mercury's account structure supports that separation on the operating side.
Frequently Asked Questions
Does either platform satisfy SEC vendor due diligence requirements on its own?
No, neither platform performs due diligence, that's still the compliance officer's job. What they can do is create and preserve the timestamped approval record that shows due diligence happened before the vendor was engaged, which is the documentation an examiner is actually looking for during a review.
How do we decide which vendors need the compliance-grade review versus the fast path?
Start with data access: any vendor that touches client PII, account balances, holdings, or trading systems needs the documented review. Vendors with no client data access, office tools, scheduling software, general operating purchases, can reasonably move through a faster approval path without compliance sign-off on every purchase.
What happens when a vendor's role expands after the initial approval?
That expansion should trigger a new review, not ride on the original approval, because the risk profile has changed even if the vendor relationship itself hasn't formally changed. A periodic review cadence for data-touching vendors, built into the approval platform rather than left to memory, is the practical way to catch this.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
Sales Tax Questions for a Registered Investment Advisor
Advisory fees are exempt everywhere, so sales tax questions for an RIA usually come from research tools or model portfolios. Here is what to check.
BILL vs Tipalti for Registered Investment Advisors
An RIA's own vendor list is short, but the recordkeeping bar is high. Here's how BILL and Tipalti fit a registered investment advisor's operating AP.
Granting Equity at an RIA Without a Form ADV Surprise
A step-by-step look at what a registered investment advisor needs to check before granting real equity, and where Pulley or Carta fits the process.
What an SEC Exam Actually Tests, Versus a SOX Audit
Why a registered investment advisor's real audit risk is an SEC exam, not SOX, and where FloQast and AuditBoard actually fit around it.
Documenting Foreign Vendor Payments for an RIA Compliance File
How registered investment advisors can choose between Payoneer and Wise for offshore research and sub-advisor payments while keeping compliance records clean.
What an RIA's Client Consent Rules Mean for a 409A
A large enough ownership change at an RIA can trigger client consent under the Advisers Act. Here's how that shapes the Carta vs Shareworks decision.