← All articles

After June 3: Turning Your Reg S-P Incident Response Plan From Paper Into Practice

Table Of Contents

View All Articles

The Regulation S-P compliance deadline for smaller RIAs passed on June 3, 2026 — which means every SEC-registered adviser is now required to have an incident response program and to notify affected individuals within 30 days of becoming aware that their sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. The document most firms wrote to meet that deadline is not the same thing as a program that works. The exam will test the second one.

Reg S-P RIA incident response — guide for RIAs

The deadline wasn't the finish line. It was the moment your plan became testable.

Here's the reframe most compliance calendars missed: before June 3, the risk was not having a plan. After June 3, the risk is having a plan that exists only as a PDF. The SEC amended Regulation S-P in May 2024 precisely because paper safeguards weren't protecting customers — the amendments, adopted in Release No. 34-100155, require covered institutions to develop, implement, and maintain written policies for an incident response program. "Implement and maintain" is the part examiners can test, and the part a template can't fake.

A Reg S-P incident response program is the documented set of procedures an adviser follows when customer information is compromised: assessing the nature and scope of the incident, containing it, determining which individuals' sensitive customer information was affected, and notifying them — generally within 30 days of awareness — along with oversight of service providers who hold that data.

Larger entities — including RIAs with $1.5 billion or more in assets under management — have been under the amended rule since December 3, 2025; all other covered advisers since June 3, 2026. From here forward, the question in every exam and every actual incident is the same: can your firm execute this under pressure, with evidence?

Why do paper incident response plans fail in practice?

Because incidents don't follow the org chart in the appendix. Three failure modes show up repeatedly:

Nobody can find the data. The 30-day clock runs from awareness, and the hardest step isn't drafting the notice — it's determining _whose_ sensitive information was affected. If client data is scattered across 15 disconnected tools, each with its own export format and access log (or none), scoping an incident becomes archaeology. Firms burn two of their four weeks just figuring out what the compromised system contained.

Service providers are a blind spot. The amended rule requires oversight of service providers, including provisions ensuring they notify you of breaches involving your customers' information in time for you to meet your own obligations. Most firms signed vendor agreements years before this rule existed. If your custodial data aggregator gets breached, does your contract require them to tell you in time for you to meet your own 30-day obligation? Most CCOs haven't checked.

The plan produces no records. Reg S-P amendments came with recordkeeping requirements — documentation of the incident response program's operation. A plan executed over frantic phone calls leaves nothing to produce. In an exam, an undocumented response is indistinguishable from no response.

AI widened the perimeter while nobody was updating the map. Every AI service that touches client data — a transcription bot, a document summarizer, an extraction pipeline, an AI feature inside approved software — is part of your Reg S-P surface: another place where sensitive customer information lives, and another vendor whose breach becomes your 30-day problem. The SEC's FY2026 exam priorities connect these threads deliberately, pairing Reg S-P review with scrutiny of the training and security controls firms use to identify and mitigate AI-related risks. If your incident response plan predates your firm's AI adoption, its data map is already out of date.

What will examiners ask about your incident response program now?

With compliance dates behind us, this moves from "show me your plan" to "show me it works." The FY2026 exam priorities name adherence to the amended Regulation S-P as a specific focus, and compliance consultants reported targeted exam letters reaching larger firms within days of the December 3, 2025 compliance date — with the same treatment expected for smaller advisers now that June 3 has passed. Expect requests like:

  • The written incident response program and the date of its last review
  • An inventory or data map showing where customer information resides — including third parties
  • Service provider agreements and the diligence showing breach-notification obligations flow back to you
  • Records of any incidents assessed since the compliance date, including those deemed non-notifiable and why
  • Evidence of testing: tabletop exercises, simulations, or post-incident reviews

That fourth item deserves attention. Deciding an incident did not require notification is itself a determination the rule expects you to be able to support. "We didn't think it was serious" is not documentation. A reasoned, recorded assessment is.

How do you turn the plan into practice?

Four moves separate firms that will pass this exam from firms that met the deadline:

  1. Map the data before the incident. Build and maintain a live inventory of where sensitive customer information lives — systems, vendors, exports. This single artifact cuts incident-scoping time more than anything else, and it's the first thing examiners ask for.
  2. Re-paper the vendors. Review service provider agreements for breach-notification clauses that actually support your 30-day obligation. Prioritize any vendor that touches statements, custodial feeds, or client documents.
  3. Run the tabletop. One two-hour simulated incident per year — "our portfolio tool was breached Tuesday, go" — surfaces more gaps than any policy review. Document it; the record of the exercise is itself compliance evidence.
  4. Make the response generate its own records. Every assessment, decision, and notification should land in a system of record as it happens, not be reconstructed afterward.

The quiet advantage here belongs to firms that consolidated. When client data lives in one platform instead of fifteen, the data map is short, the vendor list is shorter, and incident scoping is a query rather than a forensic project. That's a structural argument for the consolidation we make in our 2026 guide to financial document automation for RIAs — and it's how StratiFi approaches compliance generally: ComplianceIQ logs supervisory and incident-handling activity with an automatic audit trail, so the documentation the rule requires is a byproduct of the response, not a memory exercise after it. Where the SEC's broader cyber focus fits in the current cycle, our SEC 2026 exam priorities analysis has the full picture.

Frequently Asked Questions

What did the 2024 Regulation S-P amendments require?

The amendments require covered institutions — including SEC-registered investment advisers — to adopt written incident response programs, notify affected individuals within 30 days of becoming aware of unauthorized access to or use of sensitive customer information, oversee service providers handling that information, and keep records of the program's operation, per the adopting release (No. 34-100155).

When did RIAs have to comply with the amended Reg S-P?

Larger entities — RIAs with $1.5 billion or more in AUM — had to comply by December 3, 2025, and smaller entities by June 3, 2026. As of mid-2026, the amended rule applies to all covered advisers.

Does every data incident require client notification under Reg S-P?

No. Notification is required when sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, subject to the rule's provisions. But non-notification is a determination the firm should document with its reasoning — an unrecorded decision offers no protection in an exam.

What records should a firm keep about its incident response program?

Keep the written program itself, evidence of implementation (data maps, vendor diligence, training, tabletop exercises), and documentation of every incident assessment — including scope analysis, notification decisions, and copies of notices sent.

If scoping an incident across your current stack would take longer than the notification window allows, that's the real finding — before any examiner writes it. Book a demo and we'll show you how firms running on StratiFi answer "where does this client's data live?" in minutes instead of weeks.

Subscribe and stay up-to date.