In the dynamic landscape of financial management, portfolio accounting has witnessed transformative...
Reg S-P Deadline Has Come and Gone… What Now?
Regulation S-P had two go-live dates: December 3, 2025, for firms over $1.5 billion and June 3, 2026, for firms under that. Whether you updated your policies and procedures (P&Ps) in December or June doesn’t change the fact that your P&Ps should be solidly in place. Let’s take a moment to review:
Why Reg S-P Amendment?
Recognizing the expanded use of technology and the increased risks to non-public personal information (NPI), the SEC amended Regulation S-P. Per the SEC’s press release on May 16, 2024, its reason for an adopted amendment was to “modernize and enhance the rules that govern the treatment of consumers’ nonpublic personal information by certain financial institutions… to address the expanded use of technology and corresponding risks that have emerged since 2000”.
Simply put, consumer NPI can be found in a myriad of places – many of which are unsecured, purchased by nefarious entities, or stolen and placed on the dark web – and the SEC wants to ensure that firms handling consumer information, including RIAs, have appropriate safeguards in place to protect client information and documented policies and procedures to respond, should that information be compromised.
Among other requirements, the amended Reg S-P required covered firms to develop, implement, and maintain written policies and procedures for an incident response plan; provide notice to affected individuals as soon as practicable, but no later than 30 days after becoming aware of certain unauthorized access to, or use of, sensitive customer information; and maintain records documenting compliance with the amendments, including oversight of providers (this is your vendor due diligence).
What Should Be in Place Today
Whether in December 2025 or June 2026, your P&Ps should have been updated to reflect an incident response plan to notify clients of qualifying incidents within the required timeframe.
Additionally, oversight of your third-party providers (vendor due diligence) should now include vendor confirmation that they will alert you, the steward of your client’s NPI, as soon as possible, but no later than 72 hours after becoming aware of an incident. This piece is critical: receiving confirmation from your vendor that they will adhere to this requirement is paramount. Additionally, having that confirmation in writing and maintained as part of your books and records and incorporated into your incident response plan, is imperative.
Of course, let’s not forget documentation. Updating your policies and procedures is only part of compliance. Firms should also be prepared to demonstrate implementation through employee training, testing of incident response procedures, vendor oversight records, cybersecurity risk assessments, and evidence that notifications can be delivered within required timeframes. During an SEC examination, firms should expect to provide documentation supporting their Reg S-P compliance program.
