WISP service provider oversight is the part of a written information security plan that firms most often leave as a single sentence, even though the FTC Safeguards Rule spells out three separate duties for it. If your accountants, software vendors, IT consultants or cloud hosts touch customer information, your plan has to show how you choose them, bind them and check on them.
This guide explains what the rule requires, how to tier providers so the effort matches the risk, what belongs in the contract, and what evidence to keep. It builds on our written information security plan template, which covers the wider structure.
Free gap assessment
Where do you actually stand against ISO 27001?
Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.
Run the free ISO 27001 gap assessment → or View premium report sample
What the Safeguards Rule requires for WISP service provider oversight
Section 314.4(f) of the FTC Safeguards Rule sets out three requirements for overseeing service providers. First, take reasonable steps to select and retain providers that are capable of maintaining appropriate safeguards for the customer information at issue. Second, require your providers by contract to implement and maintain those safeguards. Third, periodically assess your providers based on the risk they present and the continued adequacy of their safeguards.
| Duty | What it means in practice | Evidence to keep |
|---|---|---|
| Select and retain | Check security before you sign, not after | Due diligence notes, questionnaire, reports reviewed |
| Require by contract | Put safeguard duties in the written agreement | Signed contract or security addendum |
| Periodically assess | Re-check based on risk, at least on a set cycle | Review records, dated conclusions, follow-up actions |
The wording is deliberately flexible, so the plan has to say what “reasonable” means for your business. That is the job of the WISP service provider oversight section, and a regulator will read it against what you actually did.
Who counts as a service provider in your WISP
A service provider is any outside party that receives, maintains, processes or can access customer information through its services to you. Typical examples are cloud storage and email hosts, payroll and tax software, managed IT support, document shredding and disposal companies, e-signature tools, outsourced call centres and consultants with system access. Start by listing every party that fits, then note what customer information each can reach. Any provider you cannot describe in one line, such as what data it holds and where, should go to the top of your review list.
Tier providers by risk
Because the rule ties periodic assessment to the risk each provider presents, a simple tiering system is easy to defend. Rate providers on the sensitivity of the data, the volume, the level of access and how hard the service would be to replace.
- High. Holds or processes sensitive customer data at scale, or has administrative access to your systems. Full due diligence, annual review.
- Medium. Holds limited customer data or has restricted access. Questionnaire and contract check, review every year or two.
- Low. No access to customer information. Record the rating and move on.
Our guide to vendor risk tiering shows how to score providers consistently.
Selecting providers under your WISP service provider oversight process
Before you sign, ask what safeguards the provider maintains. Useful evidence includes an independent audit report, a security certification, a completed vendor security questionnaire, and a summary of how the provider handles access control, encryption, incident response and staff screening. For a small provider with no formal report, a short call and written answers may be all that is proportionate. What matters is that you asked, recorded the answers and made a judgment. Our vendor due diligence checklist lists the usual questions.
What the contract should say
The rule requires safeguards by contract, so the agreement has to contain them. A workable clause set covers the following points.
- Safeguards. The provider must maintain administrative, technical and physical protections appropriate to the data.
- Purpose limits. Customer information may be used only to deliver the service.
- Incident notice. The provider tells you promptly of any security event affecting your data. Tie the deadline to your own reporting duties.
- Subcontractors. The provider passes the same safeguards to anyone it engages.
- Audit or evidence rights. You may request reports or answers to reasonable questions.
- Return and deletion. Data is returned or securely destroyed when the contract ends.
If a provider will not sign your terms, its standard terms may still contain enough. Read them, note any gaps and record how you decided to proceed. The notification clause matters especially, because your own duties under FTC Safeguards Rule breach notification run from the moment you discover an event.
Periodic assessment and monitoring
Set a review cycle by tier and put the dates in a calendar. At each review, check whether the provider’s report or certificate is current, whether its scope covers the service you use, whether any exceptions affect you, and whether its ownership, location or subcontractors have changed. Record a short conclusion and any action. When a provider suffers an incident, run an unscheduled review as well.
The Qualified Individual, the person your plan designates to oversee the programme, should own the process. Under the rule, that person reports at least annually to the board or senior officer, and that report covers service provider arrangements among other matters, so keep your provider list and review status ready for it. See our guide to the Qualified Individual role for what the role involves.
Onboarding and offboarding providers
Oversight starts before the contract and ends after it. At onboarding, run the risk tiering, complete due diligence in proportion to the tier, sign the contract and grant access only to what the provider needs. At offboarding, remove accounts and credentials the same day, confirm in writing that customer information has been returned or destroyed, and record the date. A departed vendor whose login still works is one of the easiest findings for an examiner to make, and one of the easiest to prevent. Our vendor offboarding checklist covers the closing steps in detail, and it belongs in the same file as the rest of your WISP service provider oversight records.
A hypothetical example
Consider a small tax and advisory practice with six providers. Its cloud document platform and tax software hold sensitive client data and are rated high. The managed IT firm has administrator access and is also high. The shredding company holds paper records and is rated medium. The office cleaner and the coffee supplier have no access and are rated low. The Qualified Individual collects a report or questionnaire from each high provider every year, checks the contracts for the six clauses above, and logs a one-paragraph conclusion for each. When the cloud platform announces it has moved hosting to a new subprocessor, she runs an extra review and files the answer. The example is illustrative only.
Writing the oversight section of the plan
Keep the plan text short and specific. State who owns the process, how providers are tiered, what due diligence each tier receives, which contract clauses are mandatory, how often each tier is reviewed and where the records are stored. Avoid promising more than you will do: a plan that says every provider is audited annually creates an obligation you may not meet. Link to the provider register instead of copying it into the plan, so the list can change without rewriting the document. Have the Qualified Individual approve the section and review it whenever the rule, your services or your provider mix changes materially.
Common gaps in WISP service provider oversight
The same weaknesses appear again and again. There is no complete provider list. Contracts predate the plan and say nothing about security. Reports are collected but never read. Reviews happen once at onboarding and never again. Small vendors with high access are treated as low risk because they are cheap. And the plan describes a process that nobody follows, which is worse than having no process at all, since the written text becomes evidence against you. Compare your plan against the description of what you actually do and fix whichever is out of date.
State laws add their own expectations. The Massachusetts regulation, covered in our 201 CMR 17.00 WISP guide, also expects reasonable steps in selecting and retaining capable providers and requiring safeguards by contract, so a single process can serve both.
Tools for WISP service provider oversight
The documents involved are repeatable: a provider register, a tiering method, a due diligence questionnaire, contract clauses, a review log and a board summary. The WISP Toolkit includes templates for these, alongside the core plan documents, so you can adapt them to your firm. For the rule text itself, read 16 CFR 314.4 and check that your provider process maps to paragraph (f).
WISP service provider oversight FAQ
What does the FTC Safeguards Rule require for service providers?
You must select providers capable of maintaining safeguards, require those safeguards by contract, and periodically assess providers based on the risk they present.
Do I need a contract with every vendor?
You need written terms with any provider that can access customer information. Vendors with no access to that data present little risk and need only a recorded rating.
How often should I review providers?
The rule says periodically and by risk. Many firms review high-risk providers annually and others less often, and the plan should state the cycle.
Who is responsible for provider oversight?
The Qualified Individual oversees the programme, though the firm remains responsible for compliance even where that role is outsourced.