Print this article

The Financial Services Industry’s Shadow Vendor Problem

Warren Finkel

14 August 2026

The following article comes from Warren Finkel , managing director of Omega Systems. The editors are pleased to share this important content and invite readers’ responses. The usual editorial disclaimers apply. To comment, email tom.burroughes@wealthbriefing.com and amanda.cheesley@clearviewpublishing.com


Registered investment advisors spent months vetting the vendors they know. The June 3, 2026 compliance deadline for the amended Regulation S-P made sure of it. Custodians, customer relationship management platforms, portfolio management systems, financial planning applications and cloud providers were all reviewed and documented.
 
What the review didn’t catch: the AI vendors' employees added on their own, with no one else in the loop. Employees can add AI assistants, browser extensions or software plug-ins to their workflows in minutes. These actions that fall well outside the review process that just took months to complete. 

This rapid adoption is no edge case. Verizon’s 2026 Data Breach Investigations Report found that regular AI tool use tripled to 45 per cent in one year. Notably, 67 per cent of users accessing unauthorized generative AI services did so via noncorporate accounts on company devices.

For RIAs, every one of those tools is a potential Regulation S-P service provider that never got a due-diligence review. A vendor no one knows about can't be assessed for security risk and can't be documented for examiners. Shadow vendors are a compliance failure and a breach waiting to happen, and Regulation S-P now holds firms accountable for both. 

AI changed how vendor relationships begin
Traditional vendor relationships follow a structured sequence: request, IT and compliance evaluation, control review, contract negotiation, and inventory logging.

User-adopted AI tools bypass that process. An employee can create an account, accept the standard terms and begin using the tool in minutes, while the firm takes on security and data handling risks it never assessed. 

The employee may simply be trying to work faster. But once client information passes through the platform, the firm may have no record of where it went and no answers to basic governance questions:

Where is the information stored? How long is it retained? Can it be used to train the provider’s models? Who can access it? What happens if the provider is breached? 

This isn't hypothetical. In May 2026, an employee at Community Bank in Pennsylvania uploaded customer names, Social Security numbers and dates of birth into an unauthorized AI app, believing that the sensitive fields had been stripped from the file. No hacker, no network breach, just legitimate access to an unapproved AI tool. Parent company CB Financial Services filed the first SEC Form 8-K ever triggered by shadow AI.

Regulation S-P defines a service provider by access. An AI tool that touches client data qualifies, whether anyone signed a contract or not.

When that relationship starts through a personal account, the firm can't show that it assessed the provider, decided which safeguards applied, set up a process for breach notification, or folded the tool into its incident-response program. It can't oversee a relationship it doesn't know exists.

Annual reviews leave firms managing a moving target
Regulation S-P requires ongoing oversight of service providers but doesn't dictate how often firms have to review them. In practice, most RIAs answer that question with an annual cycle: evaluate a provider before signing, log it in a central inventory, and reassess it on a fixed schedule. It's defensible, it's documentable, and examiners are used to seeing it.

That process assumes that technology enters through a controlled front door. Shadow vendors do not. Personal accounts, AI meeting assistants, browser extensions, file-sharing applications and software integrations can give outside providers access to firm or client information without involving compliance or IT.

A firm can therefore complete every scheduled assessment and still lack an accurate view of the tools touching customer data. That gap matters. Regulation S-P grades firms on whether their oversight caught the systems that were actually accessing customer information. 

Picture a firm that closes out its Q1 vendor review with a clean, fully-documented file. In Q3, an advisory team adopts a new AI note-taking plug-in to speed up client meeting summaries. No one flags it. There is no review scheduled until next Q1. For months, the tool has access to client conversations, but the firm's official inventory has no record that it exists.

That kind of invisible gap is exactly what shows up in the breach data below. The stakes behind that standard aren't theoretical. Verizon’s 2026 Data Breach Investigations Report found that third parties were involved in 48 per cent of breaches, a 60 per cent year-over-year increase. 

Periodic reviews provide a snapshot. RIAs also need technical visibility that helps identify new relationships as they form and bring them under appropriate oversight.

Four steps for bringing shadow vendors under oversight
Bringing shadow vendors under control starts with making them visible. From there, firms can put the right oversight in place before those tools become a compliance or security problem. 

1. Identify the tools employees are actually using
Compare the official vendor inventory with the firm’s actual technology activity. Identity records, endpoint data, browser inventories, network logs and SaaS discovery tools can help identify unknown platforms and integrations.

Pay particular attention to AI assistants, meeting transcription services, browser extensions, file sharing platforms and plug-ins connected to approved applications.

Discovery should lead to evaluation rather than automatic punishment. Some tools may offer legitimate value and adequate safeguards. Others may be inappropriate for customer information. The firm needs an accurate inventory before it can make that distinction.

2. Give employees clear guardrails and a workable approval process
Employees need practical guidance on which platforms are approved, what information they may use with them and where the firm draws the line.

A policy buried in an annual training deck has limited value when an employee needs an immediate answer. RIAs should create a straightforward request process and assign clear decision-making responsibility across compliance, IT, cybersecurity, and business leadership.

3. Make monitoring and documentation continuous
Adding a newly-discovered tool to a spreadsheet is only the beginning.

Firms should document how the technology was identified, what information it can access, who owns the relationship, what decision was reached and what safeguards followed. Approved providers should then be monitored as their services, integrations and security posture change.

Regulation S-P requires written compliance records and procedures for overseeing service providers. Those procedures must be reasonably designed to ensure that providers notify the firm as soon as possible, but no later than 72 hours after becoming aware of a breach resulting in unauthorized access to a customer information system maintained by the provider.

Meeting those obligations becomes much harder when the firm does not know that a platform is being used or what customer information has passed through it.

4. Extend internal capacity where needed 
Steps 1-3 are ongoing work, not a one-time fix, and few internal teams have spare capacity to run them continuously. Smaller RIAs often rely on lean teams responsible for compliance, vendor management, cybersecurity, business continuity and daily technology operations.

Continuous discovery, provider assessments, incident-response testing and documentation can quickly exceed that team’s capacity.

Where internal resources fall short, a managed service provider or managed security service provider can help extend that capacity, as in supporting vendor evaluations, advising on security controls, running incident response and breach notification testing, and maintaining the documentation needed to demonstrate year-round oversight.

The primary value is accountability. A coordinated partner can help prevent responsibilities from falling between IT, cybersecurity, compliance and vendor management teams.

What an RIA should be ready to show an examiner
In January 2026, the SEC ran an outreach session to help small firms prepare for the June deadline: an incident-response tabletop exercise, a sample document request list, and a mock examination. The message was direct: examiners want to see the process work, not just the policy on file.

The SEC's 2026 examination priorities back that up. The Division has named policies and procedures, internal controls, third-party vendor oversight and governance practices as areas of focus and separately flagged the training and security controls firms use to identify and mitigate AI-related risks. Vendor oversight and AI exposure are no longer separate line items on an exam checklist. They're the same review.

The financial consequences are significant. In January 2025, the SEC ordered Robinhood Securities and Robinhood Financial to pay $45 million in combined penalties across more than a dozen securities law violations, including, notably, failing to safeguard customer information under Regulation S-P.

The shadow-vendor problem predates the amended Regulation S-P, but the rule makes poor visibility harder to defend. A firm that cannot identify a tool touching customer information may struggle to contain an incident, receive timely notice, determine whether customer notification is required or document its response.

Shadow vendors don't announce themselves. They show up in a browser extension, a personal AI account, a plug-in nobody logged. Firms that can't account for them are managing two risks at once: a regulatory penalty that can run into the millions and a breach with no plan behind it.
 

About the author
As managing director of Omega Systems' Northeast Region, Warren Finkel has decades of experience in the financial services sector. Prior to Omega's acquisition of ACE IT Solutions in 2022, which he founded and served as leader for 14 years, Finkel delivered IT solutions to family offices, private equity firms, hedge funds, RIAs, and alternative asset firms.