Regulation S-P amendments: requirements for investment advisers

What the 2024 Regulation S-P amendments require of SEC-registered advisers: an incident response program, customer notice and service provider oversight.

The Regulation S-P amendments the SEC adopted in May 2024 make seven changes for SEC-registered investment advisers, and three of them are the headline requirements. An adviser needs a written program to detect, respond to and recover from unauthorized access to customer information. It must notify affected individuals as soon as practicable, and no later than 30 days, unless an investigation shows the information is not reasonably likely to be used to cause substantial harm or inconvenience. And it must oversee the service providers that hold its customer information, including a 72-hour deadline for them to tell the adviser about a breach.

Both compliance dates have passed: December 3, 2025 for advisers with $1.5 billion or more in assets under management, and June 3, 2026 for smaller advisers.

This answer runs in six parts:

  • What the amendments changed, rule by rule.
  • What an incident response program needs: the three steps, who gets notice, how fast, and what it says, and the 72-hour duty on service providers.
  • Redan’s position on running it.
  • How it’s actually done in the first hours of an incident.
  • The record it should leave, and how long to keep it.
  • Frequently asked questions, then the sources.

What the amendments changed

Regulation S-P’s safeguards rule already required written policies and procedures to protect customer information. That requirement stands at Rule 248.30(a)(1): administrative, technical and physical safeguards, reasonably designed to meet the three objectives in 248.30(a)(2). The amendments built on top of it.

  • An incident response program. Rule 248.30(a)(3) requires the written policies and procedures to include “a program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, including customer notification procedures.”
  • Notice to affected individuals. Rule 248.30(a)(4) sets who must be told, how fast, and what the notice says.
  • Service provider oversight. Rule 248.30(a)(5) requires policies and procedures for overseeing service providers, “including through due diligence and monitoring.”
  • Written disposal procedures. Rule 248.30(b)(2) requires written policies and procedures for disposing of consumer information and customer information.
  • A wider definition of customer information. Under Rule 248.30(d)(5)(i), customer information now includes records about the customers of other financial institutions when that information has been provided to the adviser.
  • New records for advisers. Rule 204-2(a)(25) adds six categories of Regulation S-P records to an adviser’s books and records.
  • The annual privacy notice exception. Rule 248.5(e) now sets out when an adviser need not deliver an annual privacy notice, and when it must start again.

The compliance dates. The adopting release (Release No. IA-6604) gave larger entities an 18-month compliance period after publication in the Federal Register and smaller entities 24 months. For a registered investment adviser, a larger entity is one with $1.5 billion or more in assets under management. The release was published on June 3, 2024, so the dates fell on December 3, 2025 and June 3, 2026.

The release also says that any earlier staff statement inconsistent with the amended rules is superseded, and lists the 2003 staff responses on Regulation S-P and the April 2019 risk alert on privacy notices and safeguard policies among the statements that may be affected. Guidance written before 2024 should be read against the amended text.

What an incident response program needs

Rule 248.30(a)(3) names three things the program must include procedures for.

  1. Assess. Assess the nature and scope of any incident involving unauthorized access to or use of customer information, and identify the customer information systems and types of customer information that may have been accessed or used without authorization (248.30(a)(3)(i)).
  2. Contain. Take appropriate steps to contain and control the incident to prevent further unauthorized access or use (248.30(a)(3)(ii)).
  3. Notify. Notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, unless a reasonable investigation determines that the information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience (248.30(a)(3)(iii)).

The notice

Who gets it. Each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, where the incident happened at the adviser or at “one of its service providers that is not itself a covered institution” (248.30(a)(4)(i)). A service provider that is itself a covered institution, a broker-dealer for example, falls outside that paragraph, and is subject to Regulation S-P in its own right. If the adviser cannot tell which individuals were affected, it notifies everyone whose sensitive customer information resides in the affected system, except anyone it reasonably determines was not affected (248.30(a)(4)(ii)).

In what form. The notice must be “clear and conspicuous,” and “transmitted by a means designed to ensure that each affected individual can reasonably be expected to receive actual notice in writing” (248.30(a)(4)(i)). A phone call does not meet that on its own.

What counts as sensitive. Rule 248.30(d)(9) defines sensitive customer information as any component of customer information whose compromise could create a reasonably likely risk of substantial harm or inconvenience to the individual. Its examples include a Social Security number, a driver’s license or passport number, a biometric record, and an account number, name or online user name combined with an access code, a security question and answer, or a date of birth.

How fast. As soon as practicable, and not later than 30 days after the adviser becomes aware that unauthorized access or use has occurred or is reasonably likely to have occurred (248.30(a)(4)(iii)). The only delay the rule provides for runs through the United States Attorney General. Where the Attorney General determines that notice poses a substantial risk to national security or public safety and notifies the Commission in writing, notice may be delayed for up to 30 days, then a further 30, and in extraordinary circumstances a final 60 on national security grounds alone. Any delay beyond that needs a Commission exemptive order or other action. A request to hold off from anyone else does not stop the clock.

What it says. Rule 248.30(a)(4)(iv) lists the contents: a general description of the incident and the type of information involved; the date or date range, if it can reasonably be determined; contact details including a telephone number (toll-free if available), an email address or equivalent, a postal address and the name of a specific office; for an individual with an account at the adviser, a recommendation to review account statements and report suspicious activity; an explanation of fraud alerts; a recommendation to obtain credit reports periodically and have fraudulent entries deleted; how to get a free credit report; and information about the identity theft guidance available from the Federal Trade Commission and usa.gov, with the Federal Trade Commission’s reporting site.

The decision not to notify is a record too. Rule 204-2(a)(25)(iii) requires the adviser to keep written documentation of any investigation and determination about whether notification is required, “including the basis for any determination made.”

Service providers

Rule 248.30(a)(5)(i) requires the response program to include written policies and procedures “reasonably designed to require oversight, including through due diligence and monitoring, of service providers.” Those policies must be reasonably designed to ensure that each service provider takes appropriate measures to:

  • protect against unauthorized access to or use of customer information (248.30(a)(5)(i)(A)); and
  • notify the adviser “as soon as possible, but no later than 72 hours” after becoming aware of a breach resulting in unauthorized access to a customer information system the provider maintains. When that notice arrives, the adviser “must initiate its incident response program” (248.30(a)(5)(i)(B)).

An adviser may agree in writing for a service provider to send the individual notices on its behalf (248.30(a)(5)(ii)). The obligation to make sure they are sent “rests with the covered institution” regardless (248.30(a)(5)(iii)).

A service provider, under Rule 248.30(d)(10), is anyone who receives, maintains, processes or is otherwise permitted access to customer information through providing services directly to the adviser. That usually reaches well past the obvious technology vendors.

Redan’s position

  • The clock starts with the firm’s own paper. When something happens, read the firm’s written information security policy and incident protocol first, then Regulation S-P, then the state laws that apply across the firm’s footprint. That is the order for reading. Where the firm’s own protocol is looser than the rule or a state statute, the rule and the statute govern.
  • Settle the vendor’s notification clock in diligence, before signature. Where a signed vendor contract carries no notification clock, ask the vendor for its own policy and paper it with an amendment or side letter, because a vendor’s published policy is not a contractual right.
  • A vendor that reports an incident is no longer low risk. The incident starts the firm’s own response program the day the notice lands, which is the rule. Separately, the incident moves the vendor’s risk tier, and the tier sets how deep each year’s review goes.
  • Count the 30 days from the first time anyone at the firm knew. The rule runs the clock from when the covered institution becomes aware, and it does not say whose awareness counts. Redan’s position is to count from the first time anyone at the firm knew, not the day compliance heard: a breach an employee spots on August 18 and reports to compliance on August 20 is due 30 days from August 18. When it isn’t clear who knew first, count from the earliest date anyone could have known.

How it’s actually done

  • Start from the firm’s own plan. A firm with a written information security program has an incident response plan inside it. Follow it, and open the incident file on the plan’s own template or memo, on the day, without waiting until the scale is known.
  • Bring in the right people: outside counsel, the people inside the firm who need to know, and the outside partners the incident touches.
  • Whoever runs IT runs containment. In-house IT or a managed service provider works its own response plan: resetting credentials and revoking active sessions, preserving the affected machine, checking the mailbox for forwarding rules or delegated access that was added, and pulling the sign-in log for anything that wasn’t the employee. Where it’s a managed service provider, the firm maps what the provider did back to its own plan and reconciles the two, so the incident file shows one account of what happened.
  • Count the 30 days from the right date. The clock runs from when the firm became aware, not from when the investigation closes. The incident file carries three dates: when the breach happened, when someone at the firm first knew, and when compliance learned of it. Redan’s position, above, is to count from the second.
  • Write the determination as it’s made, including the reasoning when no notice is required (204-2(a)(25)(iii)).
  • Know which vendors hold customer information before anything happens, with a contact for each.

The plan and the provider’s response are the baseline, and the full incident report builds on them.

The record it should leave

Rule 204-2(a)(25) lists what an adviser keeps:

  1. the written safeguards policies and procedures under 248.30(a)(1);
  2. written documentation of any detected unauthorized access to or use of customer information, and of the response and recovery;
  3. written documentation of each investigation and notification determination, including its basis, any Attorney General correspondence on delay, and a copy of any notice sent;
  4. the written service provider oversight policies and procedures under 248.30(a)(5)(i);
  5. written documentation of any contract or agreement entered into under 248.30(a)(5); and
  6. the written disposal policies and procedures under 248.30(b)(2).

Rule 204-2(e)(1) sets the retention period for records under paragraph (a): five years from the end of the fiscal year in which the last entry was made, the first two in an appropriate office of the adviser. Paragraph (a)(25) is not among its exceptions.

Most of that list is written at the moment of the incident, by people under time pressure. The records that hold up are written as the work happens, and they set down the time the firm became aware, what was assessed, what was contained, who decided about notice and why, and what was sent. A file reconstructed afterwards cannot show when each step happened.

The service provider half of the list is written long before any incident. That half is the vendor record. It shows which providers hold customer information, what each was asked, what each answered, and what the firm decided.

Frequently asked questions

What are the Regulation S-P amendments? Amendments to Regulation S-P the Commission adopted in May 2024 (Release No. IA-6604). For advisers they require a written incident response program (248.30(a)(3)), notice to affected individuals within 30 days (248.30(a)(4)), service provider oversight with a 72-hour breach notice to the adviser (248.30(a)(5)), written disposal procedures (248.30(b)(2)), and new records under Rule 204-2(a)(25).

When did advisers have to comply with the Regulation S-P amendments? Eighteen months after the June 3, 2024 publication for advisers with $1.5 billion or more in assets under management, and 24 months for smaller advisers. Those periods ended on December 3, 2025 and June 3, 2026.

How long does an adviser have to notify clients of a data breach under Regulation S-P? As soon as practicable, and not later than 30 days after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred (248.30(a)(4)(iii)). The rule does not say whose awareness counts. Redan’s position is to count from the first time anyone at the firm knew.

Does an adviser have to notify clients after every incident? No. Notice is not required if, after a reasonable investigation, the adviser determines that the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience (248.30(a)(3)(iii), (a)(4)(i)). The investigation and its basis must be documented (204-2(a)(25)(iii)).

Can a vendor send the breach notices for us? Yes, under a written agreement (248.30(a)(5)(ii)). The obligation to make sure the notices go out stays with the adviser (248.30(a)(5)(iii)).

Are Regulation S-P incident response programs an examination focus? Yes. The Division of Examinations’ fiscal year 2026 priorities say that after the applicable compliance dates it will examine whether firms have developed, implemented and maintained policies and procedures under the rule’s new provisions, and that Regulation S-P examinations will focus on firms’ policies and procedures, internal controls, “oversight of third-party vendors,” and governance practices.

Sources

SourceWhat it supports here
17 CFR 248.30(a) to (d), as amended at 89 FR 47786The safeguards, incident response, notice, service provider, disposal and definitions provisions
17 CFR 248.5(e)The annual privacy notice exception
17 CFR 275.204-2(a)(25) and (e)(1)The six Regulation S-P records and the retention period
Release No. IA-6604 (Exchange Act Release No. 34-100155), May 16, 2024The compliance periods, the larger-entity threshold for advisers, and the superseded staff statements
SEC Division of Examinations, Fiscal Year 2026 Examination PrioritiesThe examination focus on incident response programs and vendor oversight
State breach-notification lawsMentioned in Redan’s position as a separate layer
Redan’s positionsThe passages marked “Redan’s position”. Redan’s recommendations, labeled as such in the text