For registered advisers

Both Reg S-P dates have passed. Can you produce the record for each service provider?

The SEC adopted the Regulation S-P amendments on May 16, 2024. Compliance was required by December 3, 2025 for larger entities and June 3, 2026 for smaller ones — for an investment adviser, a smaller entity is one with less than $1.5 billion in assets under management. Both dates are behind us. Ten trade associations including the IAA asked for a six-month extension on November 19, 2025; it was not granted, and no no-action relief has surfaced. Most firms in the sub-$1.5 billion half adopted the policy and never papered the vendor layer underneath it, because the vendor layer is not a drafting exercise. It is a register, maintained, with a diligence record and a notification arrangement per row — and the population includes tools nobody procured.

(On the $1.5 billion threshold: it is well supported in law firm commentary — Holland & Knight, May 7, 2026, and Carlton Fields, 2026 — but the number sits in Table 3 of the adopting release rather than in the rule text most people read. If your AUM is near the line, confirm it against the release itself rather than against an article. Including this one.)

What the rule requires, in four parts

One: a written incident response program, reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information.

Two: customer notification as soon as practicable and no later than 30 days after becoming aware of a breach of sensitive customer information, subject to a rebuttable determination that no substantial harm is reasonably likely.

Three: service provider oversight under written policies and procedures covering due diligence and monitoring, including that the provider notify the adviser within 72 hours of unauthorized access to customer information.

Four: five years of records covering safeguards and disposal policies, incidents and responses, notification determinations, and service provider oversight and agreements.

A vocabulary note, because it matters here. Everywhere else we say clients, because that is what they are. Reg S-P says customer information — imported banking language, and the rule text controls. In this one context the word is customer. Let the seam show.

There is no written-contract requirement, and knowing that is diagnostic

The Commission proposed one and declined to adopt it. What the final rule requires is written policies and procedures reasonably designed to establish oversight, including the 72-hour notification arrangement (per Davis Polk's client update on the adopting release).

In practice most firms will implement that arrangement contractually, because a contract is the realistic way to get a vendor to commit to anything, and the records provision does refer to service provider agreements. But the obligation is the policy and the oversight, not a clause in a specific document.

Hold onto the distinction for two reasons. It changes what you have to go and do — you are not obliged to reopen thirty vendor contracts. And it is diagnostic: if a vendor tells you the SEC requires a written contract with every service provider, they are describing the proposal rather than the rule, and you now know how carefully the rest of their material was assembled.

The population is longer than the list finance pays

Not the vendors you write checks to. The vendors with access to customer information.

An AI notetaker sitting in a client meeting is a service provider with access to customer information. So, frequently, is the transcription or model layer underneath it, which may be a different company with different terms. Sixty-three percent of RIAs now use AI tools in some capacity, more than double 2023, and the dominant use is notetaking (Schwab 2026 RIA & AI Research Study, n=533 RIAs custodying at Schwab, fielded October 7–26, 2025, published January 22, 2026). At $60 to $80 per adviser per month, that is a card purchase, not a procurement event — which is exactly why it is missing from your register.

The determination record is the part firms skip entirely

Per provider, the diligence record is: what data it touches, what you reviewed, when, and what you kept. The SOC 2 report. The completed questionnaire. The data processing terms saved as a PDF with the date you retrieved them, because terms change and "we checked at onboarding" is not a record. The monitoring cadence and the date of last review.

Then the harder one. The rule contemplates a rebuttable determination that misuse of sensitive customer information has not occurred and is not reasonably likely. A determination is a decision. If it was made in a hallway and nobody wrote it down, eighteen months later it is indistinguishable from a decision nobody made. Keep the incidents where you concluded notification was not required, with the date you became aware, what you knew then, how you established scope, who decided, and on what basis. Two paragraphs is usually enough. Zero is the problem.

Vendor due diligence was among the areas where firms most expanded testing in 2026, cited by 48% (IAA / ACA Group / Yuter Compliance Consulting, 2026 Investment Management Compliance Testing Survey, 411 firms, July 29, 2026). Which also means more of your peers can answer this than could last year.

What to do Monday

  1. Build the population list first — every vendor with access to customer information, not the accounts payable list. Add the notetaker and whatever sits underneath it.
  2. For each row, capture four fields: what data it touches, what you reviewed and when, where the artifact is saved, and the 72-hour notification arrangement.
  3. Save every vendor's current data processing terms as a PDF, today, with today's date on it.
  4. Go back through the last five years of incidents and write the determination for each one — especially the ones where you decided notification was not required.
  5. Put a review date on every row and a named owner on the register.

Where we stop

We do not give regulatory advice. Whether a specific incident triggered a notification obligation, whether a specific vendor is in scope, whether your policies are adequate — those are regulatory judgments about your firm and they belong to your compliance consultant or your counsel. We will hand the question over rather than guess. We also build nothing that produces an investment recommendation or a suitability determination. What we do is build and run the register, pull the diligence artifacts, configure the tenant so the detection side actually produces records, and keep the file current after the project ends.

Signet, a division of Circle Square Consulting. Radnor, Pennsylvania.signetattest.com/evidence-file

The Evidence File — free, 30 minutes Published August 29, 2026