Third-party risk · 16 December 2025
NYDFS tightens expectations on third-party risk
Vendor oversight must now operate as a real cybersecurity control across the full relationship lifecycle.
An evidence-led lifecycle
Effective oversight starts before contracting and continues through monitoring, escalation and offboarding. Questionnaires alone are not enough: firms need qualified review, clear contractual controls and proof that issues are resolved.
Four areas to examine
- Risk-based due diligence and subcontractor visibility.
- Contracts covering access, encryption, breach notification and data use.
- Ongoing evidence, remediation tracking and escalation.
- Complete, documented removal of access and data at termination.