Procure-to-Pay, PO Workflows & Spend Governance3 min readUpdated September 2026

Vendor Due Diligence Is the Real Job for an RIA's Procurement

For a registered investment advisor, vendor due diligence is the real procurement job, and Procurify's request-first flow creates the timestamped pre-purchase approval record an examiner wants more naturally than Airbase's card-first flow. Neither platform performs the due diligence itself; that stays with your compliance officer.

Getting that trail right matters more here than in most industries, because an examiner isn't just checking whether you paid on time, they're checking whether you can prove you thought about vendor risk before you signed.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

What an Examiner Actually Asks to See

A typical SEC exam vendor-management request wants to see the firm's vendor risk assessment process, evidence that new vendors handling client data or funds were reviewed before onboarding, and a record of who approved that decision and when. A firm that can only produce vendor invoices, with no record of a pre-purchase review, is answering half the question. The other half, proof that someone evaluated the vendor's data security and access to client information before signing, has to live somewhere, and a spend platform's approval history is one of the more natural places to keep it if the approval step is built to capture it.

Why Procurify's Request-First Model Fits This Job Better

Procurify's default behavior, requiring a request and approval before a purchase clears, naturally creates the kind of pre-purchase record an examiner wants: who requested the vendor, who approved it, and when, all timestamped before money moved. Adding a required field for data access level, does this vendor touch client PII, account data, or trading systems, turns that approval record into something closer to the due diligence documentation compliance actually needs, rather than a generic purchase log.

Where Airbase Still Fits: Low-Risk, Recurring Operating Spend

Not every purchase an RIA makes touches client data or carries compliance risk, office supplies, a scheduling tool, conference registration fees. For that category, Airbase's card-first speed is a reasonable fit, because forcing every low-risk purchase through a compliance-grade review wastes the compliance team's attention on things that don't need it. The discipline is in the split: know which vendor categories actually carry data or fiduciary risk and route only those through the slower, request-first, documented path.

A Worked Example: Adding a New Market Data Vendor

Say the firm wants to add a new market data feed to support a growing set of client portfolios. If that request routes through Procurify with a required data-access field, the compliance officer sees, before the vendor is engaged, exactly what data the feed will touch and can document the review. If the same purchase happens on a card with no structured review step, the compliance record for that vendor relationship might not exist at all until someone builds it retroactively for an exam, usually under time pressure and with gaps that are hard to fill months later.

A Common Mistake: Treating Vendor Review as a One-Time Event

Some firms do a careful review when a vendor is first onboarded and then never revisit it, even as the vendor's role or data access expands. A market data provider that starts as a read-only feed but later gets connected to portfolio rebalancing logic has taken on a materially different risk profile, and that change deserves its own review, not a pass based on the original onboarding. Building a periodic vendor review, annually at minimum for anything touching client data, into the approval platform's calendar is what turns a one-time compliance check into an actual ongoing control.

Building the Data Access Question Into Every Request

The single most useful change most RIAs can make to either platform is adding one required question to the purchase request form: does this vendor touch client PII, account data, custodial credentials, or trading systems? A vendor that answers yes gets routed to the compliance officer for review before approval; a vendor that answers no can move through the standard operating-spend approval path. That one field, consistently required, does more to satisfy an examiner's due diligence question than any amount of after-the-fact documentation, because it captures the risk assessment at exactly the moment it matters, before the relationship starts.

Firms that skip this step often find, during an exam, that they can produce a general vendor list but can't easily separate which vendors actually touch client data from which don't, which turns a routine document request into a scramble to reconstruct that distinction under time pressure.

Build the data access question into every request:

  • Add one required field asking whether the vendor touches client PII, account data, custodial credentials or trading systems.
  • Route any yes answer to the compliance officer for review before approval, so the review is documented before the vendor is engaged.
  • Let vendors that answer no move through the standard operating-spend path without compliance sign-off on each purchase.
  • Trigger a fresh review when a vendor's role or data access expands, instead of relying on the original approval.
Executive Capability Standard

What Good Looks Like

A well-run RIA can produce, for any vendor with access to client data, a timestamped record of who reviewed and approved that relationship before it began, along with evidence that access has been reviewed periodically since.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Pull your current vendor list and check how many vendors with client data access have any documented pre-engagement review on file.
2. Do Manually:Require a written due diligence checklist, data access, security posture, business continuity, for any new vendor before the firm signs.
3. Delegate:Assign the compliance officer or a designated reviewer to own vendor approval sign-off for any category touching client data.
4. Automate:Configure Procurify or Airbase's approval workflow to require a data-access field and compliance sign-off before any flagged vendor category is approved.
5. Buy:Adopt a vendor risk management platform that schedules periodic reviews automatically and maintains the full audit trail an examiner would request.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Does either platform satisfy SEC vendor due diligence requirements on its own?

No, neither platform performs due diligence, that's still the compliance officer's job. What they can do is create and preserve the timestamped approval record that shows due diligence happened before the vendor was engaged, which is the documentation an examiner is actually looking for during a review.

How do we decide which vendors need the compliance-grade review versus the fast path?

Start with data access: any vendor that touches client PII, account balances, holdings, or trading systems needs the documented review. Vendors with no client data access, office tools, scheduling software, general operating purchases, can reasonably move through a faster approval path without compliance sign-off on every purchase.

What happens when a vendor's role expands after the initial approval?

That expansion should trigger a new review, not ride on the original approval, because the risk profile has changed even if the vendor relationship itself hasn't formally changed. A periodic review cadence for data-touching vendors, built into the approval platform rather than left to memory, is the practical way to catch this.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides