Regulation S-P: What SEC-Registered RIAs Should Ask Their MSP to Document

An incident response policy is easier to trust when your managed service provider can show how it works. For an SEC-registered investment adviser, that means knowing who receives a security alert, what evidence survives an investigation, and how quickly the firm gets usable facts.

The amended Regulation S-P compliance dates have passed: December 3, 2025 for larger entities and June 3, 2026 for smaller entities. The SEC’s small entity compliance guide explains the requirements. The practical question now is whether your documentation matches day-to-day operations.

Start With Two Different Notification Clocks

Under the SEC’s final rule, an RIA’s service-provider oversight procedures must be reasonably designed to ensure providers notify the firm promptly, with a 72-hour maximum after discovering a security breach that caused unauthorized access to a customer information system they maintain. This is the provider-to-firm notification trigger.

The firm’s customer-notice obligation is separate. Notice to affected individuals is due promptly, with a 30-day maximum after the firm learns unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. It concerns individuals whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization.

A reasonable investigation can support a no-notice determination when the sensitive information has not been, and is not reasonably likely to be, used in a way causing substantial harm or inconvenience. A limited delay mechanism involves an Attorney General determination concerning national security or public safety. Have counsel evaluate exceptions; an unfinished investigation is not a general extension.

1. A Customer-Information and Responsibility Map

The safeguards cover customer information held or handled by the firm or on its behalf, including information about another financial institution’s customers. Ask your MSP to help map where that information travels.

  • List relevant email, document storage, client portals, endpoints, backups, and support tools.
  • Identify the administrator, business owner, and provider for each system.
  • Record who can export logs, disable accounts, preserve evidence, and authorize restoration.

Include an explicit boundary around systems the MSP cannot access or manage. A documented gap gives the chief compliance officer something concrete to resolve with another provider.

2. A Tested Provider Escalation Procedure

Request a written escalation workflow with named primary and backup contacts, after-hours routes, and a method to confirm receipt. Ask the MSP to explain how it records when it became aware of a qualifying breach and when it notified your firm.

Use a tabletop scenario: a provider discovers unauthorized access on Friday evening. Who calls whom? What happens if the first contact is unavailable? Save the exercise timeline, missed steps, and corrective actions. Treat the 72-hour limit as an outside deadline, not a reason to wait.

3. An Incident Evidence Package

Agree in advance on the information your compliance team will need:

  • A timestamped chronology of detection, escalation, containment, and recovery
  • Affected systems, accounts, data categories, and potentially affected individuals
  • Relevant logs, investigation findings, and known evidence gaps
  • Actions taken, their owners, and unresolved questions

Ask how short-lived logs will be preserved and how investigators will distinguish confirmed facts from assumptions. Technical evidence should support the firm’s notice decision. The final rule leaves ultimate notification responsibility with the firm, even when a provider sends notices under a written agreement.

4. Evidence of Oversight and Working Controls

Regulation S-P requires service-provider oversight through due diligence and monitoring; it does not universally require a particular contract amendment. Use our vendor cybersecurity risk guide for the broader review process.

For the MSP relationship, request dated evidence relevant to your agreed safeguards: privileged-access reviews, security alert handling, remediation tickets, and recovery test results. Record exceptions and who accepted or corrected them. These are practical evidence examples, not a claim that the rule mandates every listed tool or testing interval.

5. An Accessible, Maintained Evidence Register

The amendments require compliance records. Ask the MSP to maintain an index showing each deliverable’s owner, reporting period, storage location, and next review. Have compliance counsel establish applicable retention requirements.

Keep firm-controlled access to essential records and document how they will transfer if the MSP relationship ends. Review a sample incident from alert through closure to see whether the record tells a coherent story.

This article is general information, not legal advice. Your firm’s compliance team and counsel should determine its obligations and notification decisions.

Related Financial Advisor IT Resources

Vendor Cybersecurity Risk Management

Review due diligence and monitoring for technology service providers.

Read Guide →

SEC Cybersecurity Examination

Prepare cybersecurity documentation and evidence for an SEC examination.

Read Guide →

Bring the Checklist to Your Next MSP Review

For SEC-registered RIAs in Frederick, MD and surrounding areas, this checklist provides a focused starting point for a technology and compliance conversation. Schedule a consultation with 1-UP IT Consulting to discuss your documentation and cybersecurity needs.

  • ✔ Managed IT Services
  • ✔ Cybersecurity Protection
  • ✔ Backup & Disaster Recovery
  • ✔ Strategic IT Planning
Schedule a Consultation