Full-Service Support for Amended Regulation S-P

A Turnkey Compliance Solution for Investment Advisers

The SEC’s Amended Regulation S-P expanded requirements around incident response, vendor oversight, customer notification, and written safeguards. For many firms, meeting these expectations requires significant policy updates, documentation, and ongoing operational support.

We partner with registered investment advisers to implement practical, audit-ready solutions—not just provide guidance or templates.


 

What We Deliver

Vendor Management Program

In addition to strengthening third-party oversight in line with the amended safeguards requirements, we provide an in-depth report, including risk ratings and alternate vendors, if needed.

Our support includes:

  • Vendor due diligence on required service providers
  • Assistance confirming incident notification expectations (including 72-hour notification considerations)
  • Documentation of findings and identification of potential security gaps
  • Light passive external scans of vendors’ public domains
  • Review and enhancement of your existing Vendor Management Policy
  • Drafting of a Reg S-P-aligned Vendor Management Policy, if needed

Incident Response Program

Be prepared to identify, respond to, and document security incidents with confidence.

We will:

  • Review your existing Incident Response Plan, if applicable, and determine changes to align with Amended Regulation S-P
  • Draft or enhance plans addressing identification, containment, eradication, and recovery
  • Ensure documentation supports regulatory expectations and internal governance
  • Help operationalize procedures so they are usable in real-world scenarios

Expanded Safeguards, Disposal & Recordkeeping

Meet enhanced documentation and written policy requirements without overwhelming your internal team.

In coordination with your compliance team, we:

  • Draft and update written policies and procedures
  • Align safeguards and disposal practices with amended rule expectations
  • Support required recordkeeping documentation
  • Create audit-ready compliance records that stand up to regulatory review