News & Analysis as of

Third-Party Service Provider Due Diligence

Blake, Cassels & Graydon LLP

What Can Service Providers to the Public Sector Learn From the PowerSchool Privacy Incident?

On November 17, 2025, Ontario’s Information and Privacy Commissioner (ON IPC) and Alberta’s Office of the Information and Privacy Commissioner (AB OIPC) each released their findings from their investigations into a...more

Parker Poe Adams & Bernstein LLP

New Industry Letter Provides Guidance for Companies Using Third-Party Service Providers

As organizations increasingly rely on third-party service providers (TPSPs) for critical services, including cloud computing, IT management, and fintech solutions, the scale and complexity of cyber risks have grown. A recent...more

Troutman Pepper Locke

Legal AI in Practice: Firm Governance, Build vs. Buy Decisions, and Vendor Due Diligence — The Good Bot Podcast

Troutman Pepper Locke on

In this episode of The Good Bot, Brett Mason sits down with Leigh Zeiser, director of AI and automation at Troutman Pepper Locke, to unpack how the firm operationalizes AI responsibly. They discuss the firm's AI portfolio —...more

Pillsbury Winthrop Shaw Pittman LLP

Lessons from a Major Software Sunsetting: Contractual and Post-Contractual Best Practices

Proactive planning and governance from both clients and vendors are essential to manage software sunsetting effectively....more

Troutman Pepper Locke

NCUA Issues Updated AI Resource Hub

Troutman Pepper Locke on

On December 22, the National Credit Union Administration (NCUA) updated its Artificial Intelligence (AI) resource page to consolidate key technical and policy references for federally insured credit unions. The page sits...more

A&O Shearman

BCBS principles for the sound management of third-party risk

A&O Shearman on

The Basel Committee on Banking Supervision (BCBS) has published its principles for the sound management of third‑party risk, replacing the 2005 Joint Forum outsourcing paper and establishing a common baseline for banks and...more

Cadwalader, Wickersham & Taft LLP

When Privacy Rules Meet Fund Finance, December 2025 - The New Regulation S-P Amendments and What They Mean for Lenders in Fund...

The SEC's 2024 amendments to Regulation S-P introduce the most comprehensive update to federal privacy and data security standards for SEC-regulated institutions since the rule was adopted. While the amendments are directed...more

Whiteford

Client Alert: With End-Of-Year Giving in Full Swing, Actions Against Fundraising Platform Flipcause Highlight Need for Continued...

Whiteford on

In the midst of nonprofits’ discovery of GoFundMe’s creation of donation pages for approximately 1.4 million nonprofit organizations without their consent or knowledge , another online fundraising platform for nonprofits has...more

Ropes & Gray LLP

Initial Guidance on Responding to the SitusAMC Data Breach

Ropes & Gray LLP on

Over the last weekend, major media reported that a key financial services provider, SitusAMC, suffered a substantial data security incident. This Alert summarizes what we know so far, the possible legal implications, and some...more

Herbert Smith Freehills Kramer

Buying a business with software at its core: Key issues in Australia

In this article we do a deep dive on key legal issues when buying a software business in Australia. Whether the business offers ‘traditional’ (on-premise) software, software as a service (SaaS, or other as-a-service models)...more

Troutman Pepper Locke

FERC Staff Audit Report Identifies CIP Standard Compliance Risks in FY2025

Troutman Pepper Locke on

On October 20, 2025, FERC Staff issued a report outlining areas of risk to the reliability of the electric grid based on non-public Critical Infrastructure Protection (CIP) Audits of U.S. based North American Electric...more

Guidepost Solutions LLC

How Organizations Can Strengthen Third-Party Vendor Oversight and Compliance

Guidepost Solutions LLC on

Organizations that rely on third-party vendors for critical operations face unique challenges in managing vendor risks. These external relationships are essential for operational success, but can also create vulnerabilities...more

Nelson Mullins Riley & Scarborough LLP

NYDFS Issues Additional Guidance on Managing Risks Related to Third-Party Service Providers

Covered Entities should expect heightened supervisory focus on relationships where third party service providers (TPSPs) access systems or handle non-public information (NPI). On October 21, the New York State Department of...more

Ward and Smith, P.A.

Trick or Treat Contracts: Avoiding AI Vendor Horror Stories

Ward and Smith, P.A. on

Ed. Note: This is the fifth article in our series, “Conjuring Competitive Advantage: An AI Spellbook for Leaders,” focused on unlocking AI for business with practical steps and insights. Read Part 1, Part 2, Part 3, and Part...more

McDermott Will & Schulte

NYDFS clarifies expectations for third-party cybersecurity risk management

On October 21, 2025, the New York State Department of Financial Services (NYDFS) issued an industry letter highlighting risks associated with third-party service providers – such as providers of cloud computing, file transfer...more

Paul Hastings LLP

NYDFS Puts Third-Party Service Providers Under Regulatory Spotlight

Paul Hastings LLP on

The New York Department of Financial Services (NYDFS) issued an industry letter titled “Guidance on Managing Risks Related to Third-Party Service Providers” (Guidance) for Covered Entities engaging third-party service...more

Whiteford

Client Alert: With Giving Tuesday Approaching, What Nonprofits Need to Know About GoFundMe’s Creation Of Over A Million...

Whiteford on

With Giving Tuesday quickly approaching on December 2, 2025, nonprofits are alarmed to discover that GoFundMe, an online for-profit fundraising platform, had created donation pages for approximately 1.4 million nonprofit...more

Sheppard Mullin Richter & Hampton LLP

NYDFS Issues Cybersecurity Guidance on Third-Party Service Provider Risk

On October 21, the NYDFS issued new cybersecurity guidance addressing the growing risks associated with regulated entities’ reliance on third-party service providers (TPSPs). The guidance clarifies compliance obligations...more

Alston & Bird

NYDFS Issues Guidance on Managing Risks Related to Third-Party Service Providers

Alston & Bird on

On October 21, 2025, the New York Department of Financial Services (“NYDFS”) published an Industry Letter (the “Letter”) outlining guidance on managing risks related to third-party service providers (“TPSPs”). NYDFS...more

Fisher Phillips

NY Dept of Financial Services Issues Guidance to Covered Entities on Overseeing Third-Party Service Providers: 4 Areas of Focus

Fisher Phillips on

The New York Department of Financial Services (NYDFS) just sent a stark reminder to covered entities (which includes financial institutions, insurance companies, and any other businesses regulated by the NYDFS) that they are...more

Jackson Lewis P.C.

When Big Doesn’t Mean Bulletproof: The Importance of Third-Party Service Provider Due Diligence

Jackson Lewis P.C. on

Leaders charged with safeguarding data privacy and cybersecurity often assume that size equates to security—that large, well-resourced organizations must have airtight defenses against cyberattacks and data breaches. It’s a...more

Ropes & Gray LLP

Insure Or Secure: Should All Businesses Have Cyber Insurance?

Ropes & Gray LLP on

Last week it came to light that the victims of two of the UK’s most high-profile recent data breaches — the Co-operative Group and Jaguar Land Rover — did not have cyber insurance in place. As a result, the companies will...more

Warner Norcross + Judd

Data Breaches in the Supply Chain: The Risk, the Cost and What You Can Do to Protect Against Them

Warner Norcross + Judd on

Data breaches are increasing in frequency and cost for U.S. corporations, and businesses in the supply chain are often prime targets for bad actors. It’s critical for suppliers to understand the risk and costs of data...more

Morrison & Foerster LLP

A MoFo Privacy Minute: Do You Know What AI Tools Are Installed on Your Company’s Systems?

Question: The use of AI tools without formal approval from a company (referred to as “Shadow AI”) is increasing. What are the risks and how should companies respond? Answer: Employees across industries are quietly...more

Mitratech Holdings, Inc

Third-Party Risk Management: The Definitive Guide

In a world with increasingly interconnected companies, vendors, suppliers, logistics partners, and cloud services providers, Third-Party Risk Management (TPRM) has advanced from being an annual checklist exercise to a...more

74 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide