Third-party risk · 16 December 2025

NYDFS tightens expectations on third-party risk

Vendor oversight must now operate as a real cybersecurity control across the full relationship lifecycle.

An evidence-led lifecycle

Effective oversight starts before contracting and continues through monitoring, escalation and offboarding. Questionnaires alone are not enough: firms need qualified review, clear contractual controls and proof that issues are resolved.

Four areas to examine

  • Risk-based due diligence and subcontractor visibility.
  • Contracts covering access, encryption, breach notification and data use.
  • Ongoing evidence, remediation tracking and escalation.
  • Complete, documented removal of access and data at termination.

Discuss your third-party framework