AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

SEC Regulation S-P for the Small RIA: 30 Days to Tell Clients, and a Program to Prove You Could

Regulation S-P amendments reached smaller advisers on 3 June 2026: incident response program, 30-day client notice and vendor oversight. What the exam asks.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

The exam asks for the file that does not exist

A three-partner registered investment adviser outside Denver manages about $400 million for 300 households. The partner who handles compliance, alongside a full client book, bought a 38-page Regulation S-P policy package in May 2026 from a compliance vendor. He put the firm's name on the cover and checked the box before 3 June.

In late August the SEC's exam request list arrives. Item 14 asks for the firm's written incident response program and evidence it has been tested. Item 15 asks for the service provider oversight file: the vendor list, the due diligence on each, and the contract terms requiring breach notice.

He opens the 38 pages. The incident response section describes a Cybersecurity Incident Response Team, a Chief Information Security Officer and a Security Operations Center. The firm has three partners, an operations manager and a part-time IT consultant named Ray. Nobody has tested anything. The service provider section says the firm "maintains a comprehensive inventory of third-party providers." No such inventory exists.

He starts one on a legal pad. The custodian, the portfolio software, the CRM, the email host, the document vault, the planning tool, payroll, Ray. Eight names in five minutes, before he has asked which of them hold Social Security numbers.

The examiner is not looking for a perfect firm, only one that could tell a client, inside 30 days, what happened to their data. He cannot yet.

What the heck does this mean

Regulation S-P is the SEC's privacy and safeguards rule for broker-dealers, investment advisers, funds and transfer agents. It has required a safeguards policy since 2000. The 2024 amendments added three things that a policy template alone cannot deliver.

An incident response program is a written procedure to assess an incident, contain it, and notify the people affected. The rule wants it to exist, to be specific to your firm, and to work.

The 30-day notice means that once you become aware that sensitive customer information was, or was reasonably likely to have been, accessed without authorization, you tell the affected individuals within 30 days, unless you can show the information is unlikely to be misused.

Service provider oversight means written due diligence on every vendor that touches customer information, ongoing monitoring, and terms requiring them to protect it and tell you about a breach.

Sensitive customer information is the subset that can hurt someone if it leaks: Social Security numbers, account numbers with access codes, identity documents, and any name paired with them.

The compliance dates were 3 December 2025 for larger firms and 3 June 2026 for smaller ones. Both have passed. Every SEC-registered adviser is now inside the rule.

The numbers that matter

Smaller entities had to comply with the amended Regulation S-P by 3 June 2026, and larger entities by 3 December 2025, under the SEC's 2024 amendments. An exam in September 2026 will expect the program to be running, not drafted.

The amended rule requires notification to affected individuals no later than 30 days after the firm becomes aware of an unauthorized access to sensitive customer information, per the SEC's 2024 Regulation S-P text. Thirty days is enough time only if the logs exist to say who was affected.

The mean time to identify and contain a breach was 247 days, according to the IBM 2026 Cost of a Data Breach Report. The 30-day clock starts at awareness, and the firm that takes 247 days to become aware has a larger problem than the notice letter.

What to do this week

  1. Rewrite the incident response program on one page with the real names: who decides an incident has occurred, who contains it, who drafts the client notice, who calls counsel and the custodian. Delete the Security Operations Center. (CIS 17 Incident Response Management)
  2. Run a thirty-minute tabletop with the three partners and Ray: "A client's statement was emailed to the wrong household on Friday." Note who did what and how long the 30-day clock would have taken. Keep the notes; that is the test evidence item 14 asks for. (CIS 17 Incident Response Management)
  3. Finish the vendor list from the legal pad. For each name: what customer information they touch, what due diligence you did, the date, and whether the contract requires breach notification. Eight rows, one afternoon. (CIS 15 Service Provider Management)
  4. Send each vendor without a breach-notice clause a short written addendum, and file the signed copies with the list. Ray gets one too. (CIS 15 Service Provider Management)
  5. Find the sensitive customer information outside the systems built to hold it: scanned statements in email, account-opening forms on a partner's laptop, the spreadsheet of Social Security numbers from the last tax season. Move it into the vault and delete the copies. (CIS 3 Data Protection)
  6. Turn on access logging in the CRM, the document vault and email, with retention of at least a year, so the question "whose data was touched" has an answer within days instead of months. (CIS 8 Audit Log Management)

Where AccuSights fits

We have sat across from examiners at institutions far larger than three partners; the questions are the same at every size. Our assessment turns Regulation S-P into a firm-specific program: the incident plan with names, the vendor file with evidence, and a map of where sensitive customer information actually lives. Our team implements the controls at a reasonable rate, from data loss prevention that catches the misdirected statement to scanning and protection of the partners' laptops. The Cyber Hygiene Test takes three minutes; the call with an engineer takes fifteen.

Questions people ask

Does Reg S-P apply to state-registered advisers? No. Regulation S-P is an SEC rule and applies to SEC-registered investment advisers, broker-dealers, funds and transfer agents. A state-registered adviser sits outside it, but not outside the obligation: the FTC Safeguards Rule treats advisers as financial institutions and asks for the same things, a written program, a named responsible person and breach notification, and most state securities regulators have their own requirements. The homework is the same; the examiner is different.

What counts as sensitive customer information? Any customer information whose compromise could cause substantial harm or inconvenience: a Social Security number, a driver's license number, an account number combined with a password or access code, or a name combined with any of those. The amendments also widened customer information to include data you receive from another financial institution, so the statements your custodian sends you count too, alongside the data you collected yourself.

Do we need written contracts with every vendor? You need written due diligence and monitoring of every service provider that receives, maintains or can access customer information, and you need the provider to be bound to protect that information and to tell you about a breach promptly; the rule expects notice to you within 72 hours of the provider becoming aware. In practice that means a contract clause or a written addendum with each one, and a file showing you checked. A vendor with no access to customer information can stay off the list, but you have to have made that determination and written it down.

A policy proves you could write. A tested program proves you could act. The examiner, and the client, only care about the second one.

Controls this post maps to

CIS 17 Incident Response ManagementCIS 15 Service Provider ManagementCIS 3 Data Protection

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.