The ITRE Review / Asset management
Technology Governance for REITs and Asset Managers
What boards and audit committees should ask about technology risk, payment controls and data reporting in property investment vehicles.
An investment vehicle that owns real property has an unusual technology profile. The managers are small, the money is large and much of the operational data sits with third-party property managers. Boards and audit committees increasingly want assurance that technology risk is understood. This article suggests a set of questions and controls that a REIT or asset manager can use as a practical governance framework.
Ask what the technology is protecting
A useful start is to list the information assets that matter: the rent roll, investor records, treasury and banking access, lender covenants and compliance reporting, valuation models and acquisition files. For each, name the owner, the system and the consequence of loss or leak.
This inventory focuses the discussion. Boards often find that the most valuable assets are held in shared drives and personal spreadsheets, not in the systems that receive the investment.
Payment controls across entities
Large payments across multiple entities are the most exposed process. Require dual approval, call-back verification for any change to banking details and a defined limit above which an additional senior approver is needed. Bank portal access should be tied to named individuals with multi-factor authentication.
Document the process once and test it. An annual walk-through, where a finance team member attempts to follow the procedure under a realistic fraud scenario, reveals the gaps.
Third-party property managers and vendors
The asset manager frequently relies on property managers who hold tenant data and operate buildings. Include technology expectations in management agreements: multi-factor authentication, incident notification, data return at termination and a right to review security evidence.
SOC 2-aligned practices are a reasonable benchmark for significant vendors. Request evidence, but also ask practical questions about access, backups and who can see your data.
Consolidated reporting you can trust
Board packs often depend on data from several property managers, each with its own format. A governed reporting model that consolidates rent rolls, budgets and variances, with written definitions of each metric, improves both speed and credibility.
Reconciliation to the ledger is the discipline that makes dashboards trustworthy. Build reconciling checks into the pipeline and report any variance.
Resilience, insurance and the board
Boards should know the answer to three questions: how quickly could the business operate after a major outage, has recovery been tested, and what does the cyber insurance policy require? Insurers now ask detailed questions about authentication, backups and incident response, and an independent assessment provides evidence for the application.
Request an annual technology risk report, one or two pages long, covering incidents, control status, audit findings and the roadmap. Short and regular beats long and rare.
Common mistakes we see
A frequent mistake is to ask the wrong question of the technology team. Boards ask whether the firm has been hacked, when they should ask how a fraudulent payment would be detected and what is the recovery time for critical systems. Another is to accept vendor certifications without asking what they cover.
Asset managers also depend on key individuals. The one person who understands how the rent-roll data is consolidated is a single point of failure. Document the process and cross-train. Finally, technology risk reporting is often a long, technical document that nobody reads. A page with five measures and a short narrative is more likely to prompt a useful discussion.
Checklist to take to your next meeting
- Inventory of key information assets with owners
- Dual approval and call-back verification for payments
- Technology clauses in property-management agreements
- Governed consolidated reporting with reconciliations
- Tested recovery objectives for critical systems
- Annual one-page technology risk report to the board
Where this fits in your technology plan
Guidance works best as part of a coordinated programme rather than a one-off fix. These ITRE services address the subject directly.
- 01Device Management for Agents
Device Management for Agents establishes a respectful but firm standard for the equipment that touches brokerage data: enrolment, encryption, updates and remote wipe, with a clear separation between personal and brokerage content on agent-owned phones.
- 02MLS/CRM Integrations
MLS and CRM Integrations covers the plumbing between board data, your customer relationship platform, your website and the tools that send email, texts and reports. We design the data flow first, then implement it with the platforms you already pay for.
- 03Backup & Disaster Recovery
Backup and Disaster Recovery protects the records a real estate business cannot recreate: transaction files, trust records, leases, drawings and mail. We design the backup, the recovery targets, and then test restoring from them on a schedule.
Further reading
- 01Cybersecurity for Property Managers: Protecting Tenant and Owner Data
What property management firms should secure first: tenant information, trust funds, building systems and the vendors that touch them.
- 02Developer Site Connectivity: Sales Centres, Trailers and Temporary Offices
How to plan internet, Wi-Fi and security for presentation centres and construction sites that open quickly and close cleanly.
- 03Strata Data Governance in BC: Records, Owners and Privacy
A practical guide for strata councils and managers on keeping records safe, accessible and handled in line with BC privacy law.
Take it to your next leadership meeting
Guidance is only useful when someone acts on it. If this article raised questions about your own office, development or portfolio, bring the checklist above to your next leadership meeting and assign an owner to each item. ITRE offers a free thirty-minute consultation to help you decide what to do first and what can wait.
Speak with an advisor
To discuss any of this in the context of your business, call (604) 632-4959 or write to info@SAZ.ca. You will speak with a senior advisor, and the guidance on this site is reviewed by Ali Sedighi, MBA. There is no obligation, no lock-in and no sales script.
Questions and answers
- What should an audit committee ask about cyber risk?
- Ask what is most valuable, who has access, how payments are verified, how quickly the business could recover and what independent assurance exists. Short written answers are better than long presentations.
- Is SOC 2 required of our vendors?
- It is not mandatory, but SOC 2-aligned practices are a recognised benchmark. Ask for evidence and discuss material exceptions.
- How do we oversee property managers' security?
- Include requirements in management agreements, request periodic evidence, and review access to your data annually.
- Can ITRE produce a board-level assessment?
- Yes. A security assessment starts at $1,900 and produces a plain-language report and a costed roadmap suitable for a board or audit committee.
- Do you provide investment or legal advice?
- No. We advise on technology, security and reporting systems. Investment, securities and legal matters remain with your professional advisors.