Auditen
practitioner note

The Comfort of a Signed Service Level Agreement

The Thankyou Payroll breach in New Zealand is an embarrassment, and it's a warning for anyone managing third party risk with a spreadsheet. When bank details and Inland Revenue Department data leak, companies follow a script. They point at the vendor. Then they pull out a contract that says the vendor is responsible for security.

I've sat on both sides of the table. A contract isn't evidence. It's just a legal tool to recover money after the data is gone. It doesn't stop the leak.

Most firms treat vendor management as procurement. They don't actually audit. They send a questionnaire, get a "Yes" for every security control, and save the PDF in a folder. Why do they call this maturity? If you tell me your program is mature, I assume you have a very tidy folder of lies.

The real question is: what would you show the assessor on a Tuesday?

Most people just hand over a SOC2 report from fourteen months ago when an auditor asks if their payroll provider is actually following promised controls, and that isn't proof of a current control. It's a historical snapshot of an old software version, probably checked by a different team, and it's basically a postcard from a holiday the vendor took last year.

Why would you try to audit a third party by reading a marketing brochure? You need to see the real output. For payroll, that means seeing proof of encrypted transit and access logs for who is touching IRD data; if you aren't asking for those samples, you aren't managing risk. You're just outsourcing your liability.

The objection here is always the same: "We don't have the leverage to demand a real-time audit from a global provider."

Maybe that is true. But it doesn't change things when the regulator issues the fine (they won't care if you lacked leverage). The real trouble isn't just the immediate data loss, but the regulatory pivot that follows. When a payroll firm fails, regulators don't stop at the provider. They look for the clients who handed over sensitive data without verifying anything first. You become the next target since you failed your duty of oversight.

It turns a technical failure into a governance failure.

Blame always lands on governance. Look at the SEC and their rules. They've proposed rescinding Rule 206(4)-5, and comments are due by November 9. The regulator keeps shifting how they see the bond between firms and agents. Trust isn't a control.

Stop looking for certificates if you want to satisfy an auditor. Ask for proof that a control actually worked yesterday. Get a screenshot of the latest user access review; find the last three failed login attempts on the admin portal.

Why trust a template? You only find out if a vendor is secure, or just good at paperwork, when you ask for something they can't pull from a form.

Check your vendor folder. If every document in there was signed by a lawyer instead of an engineer, you're exposed.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. SEC Proposes Sweeping Modernization of Transfer Agent Rules - JD Supra Compliance Week (Google News)
  2. FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices - The HIPAA Journal InfoSec Compliance (Google News)
  3. GDPR wasn't designed for AI and that's a security problem - Computer Weekly Compliance Week (Google News)
  4. Kiwi payroll firm caught up in 'global' data breach - RNZ Data Privacy (Google News)
  5. Thankyou Payroll breach exposes IRD, bank data - B2B News Data Privacy (Google News)
  6. SEC Proposed Rescission of Rule 206(4)-5 Published in Federal Register; Comments Due November 9, 2026 - Skadden, Arps, Slate, Meagher & Flom Compliance Week (Google News)
  7. NFRA sets up advisory committee on audit quality and technology - BusinessLine PCAOB
  8. Delaware Consumer Privacy and Data-Breach Law Updates - The National Law Review Data Privacy (Google News)

How stories are selected and assessed