Our General Counsel team screens all law firms which includes a specialized (very short) data security questionnaire. THe process requires completion and re-attest at least every 3 years. The questionnaire is reviewed by out InfoSec team just like the SOC reviews etc. for gap identification and remediation.
TPRM has oversight (scheduling, review coordination, etc.) of the law firm data security review process, but otherwise the law firms are exempt.
We have a few similar exempt carveouts for Line 1 managed qualification processes (panel real-estate appraisers, etc.)