Full Support for Amended Regulation S-P

Mitigate risk and close the gap with our turnkey solution

PDF Download

How Fairview Can Help

Vendor Management Program

  • Vendor due diligence on all required service providers
  • Assistance confirming service providers will provide notice of an incident within 72 hours, based on items provided and reviewed
  • Detailed analysis and documentation of findings, including potential security gaps
  • Light passive external scan of vendors’ public domains
  • Review of your current Vendor Management Policy, or drafting a new one aligned to Amended Reg S-P

Incident Response Program

  • Review and/or draft an Incident Response Plan addressing identification, containment, eradication, and notification of breaches

Customer Notification Requirement

  • A “Notice Determination Checklist” and “Notice Template” ready to use if customer notification is needed

Recordkeeping and Expansion of Safeguards and Disposal

  • In coordination with our compliance team, drafting of policies and procedures to meet both requirements

Why This Matters Now

The SEC has signaled Amended Reg S-P is an examination priority, naming it a focus area in its 2026 Examination Priorities and bringing enforcement action tied to the prior version of the rule. If your firm isn’t yet compliant, the exposure is immediate.

The Amendments to Reg S-P treat Registered Investment Advisers (“RIAs”) as “covered institutions” under the rule. At a high level, covered institutions must adopt the following:

  • Comprehensive Vendor Management Program
  • Incident Response Program
  • Customer Notification Requirement
  • Expansion of Safeguards and Disposal Rules (including written records)

Key Challenges with Compliance

Many firms have experienced similar challenges in meeting and maintaining compliance requirements under Amended Regulation S-P. If you are still working to close the gaps, consider these areas:

Understanding Customer and Sensitive Information: Customer information is broader than many advisers realize — it includes any record of nonpublic personal information about a consumer who is a customer of your firm, or a customer of any other institution where the information was shared with your firm. Map out where both customer and sensitive information live.

72-Hour Notification Requirement: Not every service provider will be willing or able to amend contracts to guarantee notice within 72 hours of a breach. Document all efforts made to secure this commitment — you’ll want to show SEC examiners you made every reasonable effort, even where you can’t control the outcome.

Data Mapping and Risk Identification: Formal data mapping isn’t required by the final rule, but the SEC has signaled it’s a best practice — and examiners may ask for evidence of a risk assessment. Frameworks like NIST and the CIS benchmarks can help guide this work.

Updating Policies and Procedures: Existing Incident Response Plans and Vendor Due Diligence policies tied to prior rules will no longer suffice. All written policies and procedures must be updated to meet Amended Reg S-P’s specific requirements.

Documentation and Recordkeeping: Recordkeeping requirements range from written policies to documentation of investigations and notification determinations. Train personnel and test procedures regularly to make sure records are created and maintained every time.

Private Fund Requirements: Private funds themselves are excluded from Amended Reg S-P, but RIAs that manage private funds are in scope. If your fund has natural persons as investors — such as individual limited partners — you’ll need to comply with Amended Reg S-P for the customer information you collect about them.

Coordinating with IT Providers: IT providers bring valuable technical expertise, but many treat incident response through a general data-security lens rather than the specific requirements of Amended Reg S-P. They’re a strong resource for data mapping and risk identification, but will likely need guidance on the rule’s additional requirements.


Ready to Get Started?

If you have questions or need support, we have a dedicated Cyber Solutions team dedicated to helping RIAs meet cybersecurity-related SEC requirements and best practices. To set up a call or to learn more, submit a form  or email us at info@fairviewinvest.com.