How ARMP Automates Third-Party Vendor Vetting for Dealers

Terry Dortch President, Automotive Risk Management Partners

Key takeaways

  • The Gramm-Leach-Bliley Act requires dealerships to vet their third party vendors and service providers as part of data protection compliance.
  • ARMP automates the vendor vetting process by sending a third party service provider agreement and questionnaire based directly on what the rule requires.
  • To start the process, a dealership only needs to provide ARMP with the vendor company name, a contact individual, and that individual's email address.
  • ARMP sends an updated questionnaire to vendors annually to check for any changes in how they collect, preserve, or protect data.
  • Vendor questionnaires and agreements are stored in the dealership's dashboard so they can be pulled up quickly for verification or proof in the event of an incident.
  • Many parties can access dealership customer data, including service contract providers, cleaning services, and advertising agencies, which makes vendor monitoring increasingly important.

Summary

The Gramm-Leach-Bliley Act requires dealerships to vet the third party service providers who touch customer data, from service contract providers to advertising agencies that access vehicle photos and records in the DMS. That vetting has always been part of the data protection process, but it gets complicated fast because many vendors lack a process for responding to these requests or don't answer at all, leaving dealers without documented proof that their vendors protect customer data the way the rule requires.

This video covers how that vendor vetting can be handled without manual follow-up. The dealer supplies a vendor's company name, contact, and email, and a service provider agreement and questionnaire built directly from the Safeguards Rule's requirements go out automatically, with an updated questionnaire sent annually to catch any changes in how a vendor collects, stores, or protects data. Every response is stored in the dealer's dashboard, so if an incident occurs, proof that a vendor was vetted can be pulled up in seconds rather than chased down after the fact.

Transcript

Introduction to vendor vetting questions

Hello, my name is Terry Dortch, I'm with Automotive Risk Management Partners. You know, over the last couple of weeks I've been running around calling on dealers with my guys, and in our journeys we came across a lot of issues, or not, I would say their issues, a lot of questions regarding third party vendors.

Gramm-Leach-Bliley origins of vendor vetting

Now back in 2003, when Gramm-Leach-Bliley came out, part of this whole process, or part of this whole data protection journey that everybody's on right now, was that we had to vet our vendors, our third party service providers. It became kind of complicated, I guess is the best word, mainly because a lot of your vendors don't get back to you. They don't have a process for it, they haven't developed it, or whatever. I mean, more and more they're creating their processes and they're able to respond to your requests.

ARMP's automated questionnaire and agreement process

What we've done, as opposed to some of our competitors out there, is we've completely automated that process for you. And what I mean by that is we've made it very simple, in the sense that all you need to do is you provide us with the name of the company, an individual at that company, and an email address for that individual. We have created a third party service provider agreement as well as a questionnaire. Obviously it's nothing that's earth shattering, we haven't reinvented the wheel by any stretch of the imagination, we took it right off of the rule itself and as far as what they require. So our questionnaire and our agreement, the third party service provider agreement, is all based off of what the rule requires.

Annual updates and dashboard record keeping

So anyway, what we do is we send that out to your vendors, and then we have an actual file within your dashboard, and in that file it will house all your different vendors. Every year we'll go back and just send them an updated questionnaire in case there's been any changes in the way that they collect the data, the way that they preserve it, the way that they protect it, that type of thing. So that questionnaire on an annual basis goes out as well. You don't have to do any of that. Once you've given us their name, their email address, the name of the company, we take care of everything from there, and then it sits inside your dashboard so that if any time you need to access it for verification or proof, if there's an incident, it's all right there for us, we can pull it up in a matter of seconds.

Why vendor monitoring matters at dealerships

That's something really that you need to be aware of, you need to take into consideration. It's going to become more and more pertinent as time goes on, because there's more and more vendor interaction, and especially at a dealership level, if you look at all the different people that can access your data, I mean that's everybody from, my God, the service contract provider, to, you know, Aramark to a certain extent, you've got your different advertising agencies, things like that, that are going to go in and get, and look at, and get pictures of cars, and get the, you know, so I mean there's a whole host of people that actually access your database. And obviously you still monitor that and there are controls for it, but at least this way we can take and send them out that questionnaire and verify that they're doing everything that you are to protect that customer data as well.

Contact information for questions

Again, if you have any questions regarding this, please feel free to give us a call, number's on the screen here, as well as our website, you can go to our website, send us an email, whatever you want to do. But, you know, shout out to us if you need to. Thanks, talk to you guys, bye.

Questions this video answers

Why do we need to vet our third party vendors?

Since Gramm-Leach-Bliley came out in 2003, dealerships have been required to vet their third party service providers as part of the data protection process, because many of these vendors can access customer data and need to show they protect it properly.

What do we need to provide ARMP to start vetting a vendor?

You just need to give ARMP the name of the vendor company, an individual contact at that company, and an email address for that individual. ARMP then sends out the third party service provider agreement and questionnaire and handles everything from there.

How often are vendors re-checked once they are in the system?

Every year ARMP goes back and sends vendors an updated questionnaire in case there have been any changes in how they collect, preserve, or protect data, so the dealership does not have to manage that follow-up themselves.

Where can I find the vendor questionnaires and agreements if I need them?

They are stored in a file within the dealership's dashboard housing all the different vendors, so if you ever need to access it for verification or proof, such as after an incident, it can be pulled up in a matter of seconds.

Covered in this video

  • Gramm-Leach-Bliley Act
  • third-party service provider vetting
  • vendor due diligence
  • FTC Safeguards Rule