Mitigate risk and close the gap with our turnkey solution
PDF DownloadHow Fairview Can Help
Vendor Management Program
Incident Response Program
Customer Notification Requirement
Recordkeeping and Expansion of Safeguards and Disposal
Why This Matters Now
The SEC has signaled Amended Reg S-P is an examination priority, naming it a focus area in its 2026 Examination Priorities and bringing enforcement action tied to the prior version of the rule. If your firm isn’t yet compliant, the exposure is immediate.
The Amendments to Reg S-P treat Registered Investment Advisers (“RIAs”) as “covered institutions” under the rule. At a high level, covered institutions must adopt the following:
Key Challenges with Compliance
Many firms have experienced similar challenges in meeting and maintaining compliance requirements under Amended Regulation S-P. If you are still working to close the gaps, consider these areas:
Understanding Customer and Sensitive Information: Customer information is broader than many advisers realize — it includes any record of nonpublic personal information about a consumer who is a customer of your firm, or a customer of any other institution where the information was shared with your firm. Map out where both customer and sensitive information live.
72-Hour Notification Requirement: Not every service provider will be willing or able to amend contracts to guarantee notice within 72 hours of a breach. Document all efforts made to secure this commitment — you’ll want to show SEC examiners you made every reasonable effort, even where you can’t control the outcome.
Data Mapping and Risk Identification: Formal data mapping isn’t required by the final rule, but the SEC has signaled it’s a best practice — and examiners may ask for evidence of a risk assessment. Frameworks like NIST and the CIS benchmarks can help guide this work.
Updating Policies and Procedures: Existing Incident Response Plans and Vendor Due Diligence policies tied to prior rules will no longer suffice. All written policies and procedures must be updated to meet Amended Reg S-P’s specific requirements.
Documentation and Recordkeeping: Recordkeeping requirements range from written policies to documentation of investigations and notification determinations. Train personnel and test procedures regularly to make sure records are created and maintained every time.
Private Fund Requirements: Private funds themselves are excluded from Amended Reg S-P, but RIAs that manage private funds are in scope. If your fund has natural persons as investors — such as individual limited partners — you’ll need to comply with Amended Reg S-P for the customer information you collect about them.
Coordinating with IT Providers: IT providers bring valuable technical expertise, but many treat incident response through a general data-security lens rather than the specific requirements of Amended Reg S-P. They’re a strong resource for data mapping and risk identification, but will likely need guidance on the rule’s additional requirements.
Ready to Get Started?
If you have questions or need support, we have a dedicated Cyber Solutions team dedicated to helping RIAs meet cybersecurity-related SEC requirements and best practices. To set up a call or to learn more, submit a form or email us at info@fairviewinvest.com.