Active Incident? 24/7 Response →

For SEC-Registered Advisers

What an SEC Examination Asks a Small Adviser For

The Division of Examinations publishes a mock examination of a seven-person advisory firm, and with it the six documents it asks for first. This page walks that request, and the record each obligation leaves behind.

The examination, item by item

Most writing about Regulation S-P explains the rule. An examination does not ask you to explain the rule. It asks you to hand over documents, and then it asks the people who wrote them what they actually do.

The SEC’s Division of Examinations ran a Compliance Outreach event for small firms in January 2026 and published the deck. It contains a mock examination: a fictional advisory firm, the initial document request the staff would send it, the roles they would interview, and the three observations they most often report back. It is the closest thing to an answer key that exists for this rule, and it is free.

The firm the SEC staff used as its example

The profile is deliberately small, and it is worth reading closely if your firm looks anything like it.

The fourth line is the one that matters most here. The staff built their example around a firm that does not run its own information technology, which is the ordinary shape of a seven-person adviser, and they carried that through to the interviews. The roles named are the CCO, the CIO, the CTO, and outsourced information technology staff. If your provider is the answer to three of those four boxes, they are in the examination whether or not anyone has told them so.

The six things they ask for first

The initial document request runs across two slides in the deck, which is why it is sometimes described as five items. There are six. The sixth is a block of related requests rather than a single line.

  1. Registrant compliance manual.
  2. Written policies and procedures addressing administrative, technical and physical safeguards for the protection of customer information.
  3. Information technology managed service provider contract.
  4. Organization charts.
  5. Risk assessments related to technology and cybersecurity risk, controls, threats and vulnerabilities.
  6. Incident response specific requests, which break down into:
    • the incident response plan;
    • the policies documenting the program to detect, respond to and recover from unauthorized access, including customer notification procedures;
    • a listing of the staff, vendors and contractors responsible for incident response;
    • a listing of all detection and monitoring tools;
    • monitoring evidence;
    • and, if an incident occurred during the review period, documentation that the program’s steps were followed.

Read the sixth item again. Four of its six sub-requests are not documents a firm writes once. A listing of monitoring tools, monitoring evidence, and proof that the plan’s steps were followed are all records that only exist if something was producing them month by month. That is the difference between a firm that has a program and a firm that has a binder.

The three findings they report back

The staff list three common observations. They are quoted here as printed, capitalisation and all.

The middle one is the expensive one, and it is the one a small firm walks into most easily. A firm with no policies knows it has a problem. A firm whose policies are good and whose evidence stops in March has a problem it does not know about, and it will find out in the room. The monthly record is what answers that finding, which is the whole argument for running this as a service rather than a project. The hub sets out the service calendar and the control map behind that record.

What the enforcement record actually shows

The realistic exposure at the end of an examination is a deficiency letter, and the remediation and disruption that follows one. That is the cost worth planning around. The fine is not the expensive part, and we would rather say so than sell fear.

It is still worth being accurate about the record, because a firm that checks will find it in a single search. The Commission has brought very few safeguards cases against advisers, and as of 2026 it has announced none at all under the amended rule. The cases it has brought punished one thing consistently: a gap between the written policy and the deployed control. In 2015 an adviser with no written policies, no risk assessments and no incident response plan left client information exposed for nearly four years and was censured with a $75,000 penalty. A decade later a much larger firm was charged after email account takeovers, having had a written policy across seventeen named control categories and not having enforced it.

Those two bracket the argument. One firm had nothing written. One firm had everything written and nothing enforced. Both were charged, and the second is the one that reads like an examination finding rather than an accident.

The six obligations, and the record each one leaves

Six obligations sit in Regulation S-P, and the six obligations under Regulation S-P are set out in full on the hub. What follows is the part the hub does not carry: which of them leaves a record, what that record is, and which numbered item in the staff’s own request is the one that tests it.

Each Regulation S-P obligation, the record it leaves, and the initial document request item that asks for it.
ObligationWhat it requiresThe record it leavesWhat the examiner asks for
248.30(a)(1)Written administrative, technical and physical safeguards for customer records and information.The safeguards policies themselves, and the risk assessments behind them.Items 2 and 5.
248.30(a)(3)An incident response program reasonably designed to detect, respond to and recover from unauthorized access to customer information.Documentation of the detected access, and of the response and recovery that followed it.Item 6, and the plan itself.
248.30(a)(4)Notice to affected individuals as soon as practicable and no later than 30 days after becoming aware, with eight required contents.The investigation, the determination, and the basis for a decision not to notify.Item 6, the customer notification procedures.
248.30(a)(5)Oversight of service providers through due diligence and monitoring, including an expectation of notification within 72 hours.The oversight policies, the vendor inventory, and the provider agreement.Item 3, the managed service provider contract.
248.30(b)Written disposal policies, now reaching consumer information as well as customer information.The disposal policies, and evidence they were followed.Nothing in the request names disposal. It arrives through Items 1 and 2, or in interview.
204-2(a)(25)That the six categories above are kept, and can be produced on request.The record schedule itself.All six items. The request is the production.

Retention is one rule, not six. 17 CFR 248.30 sets no retention period at all. It comes from the adviser books and records rule: 17 CFR 275.204-2(e)(1) keeps these records in an easily accessible place for five years from the end of the fiscal year in which the last entry was made, with the first two years in an appropriate office of the adviser.

Three details in that sentence get misquoted often enough to be worth stating plainly. Easy accessibility runs the whole five years, not the first two. The two-year qualifier is about where the records live, not how quickly you can reach them. And the clock starts at the end of the fiscal year in which the last entry was made, not on the date of the event. The six-year figure that circulates alongside this one is real, and it belongs to a broker-dealer under 17 CFR 240.17a-4(a) rather than to an adviser.

Where this leaves a firm of seven people

A firm of seven carries the same obligations as a firm of seven hundred, with none of the staff to meet them. Nothing in the rule scales down. What scales is who does the work.

The plan built for this is Monitor and Comply, at $1,950 per month. up to 10 named users and 12 protected devices, on a 12 month term, billed monthly. It pairs the monitoring with the written compliance program and the dated monthly record that answers the middle observation above. Three other plans sit either side of it, from monitoring alone through to a fully managed programme, and the full comparison and the rate card are on the hub.

If your firm also prepares tax returns

Plenty of advisory firms file returns for their clients, and a firm that does sits under a second regulator with its own security rule. This section is short on purpose. If it does not describe you, skip it.

The rule names tax preparation by name. 16 CFR 314.2(h)(2)(viii) lists preparing individual tax returns among the activities that make a business a financial institution for the purposes of the FTC Safeguards Rule. This is not an analogy, and it is not a best practice. The activity is enumerated.

The small-firm exception is narrower than it sounds. 16 CFR 314.6 is a single sentence, and for a firm maintaining customer information concerning fewer than five thousand consumers it removes exactly four elements: 314.4(b)(1), (d)(2), (h) and (i). Everything else survives at any size, including the written information security program at 314.3(a), encryption at 314.4(c)(3) and multi-factor authentication at 314.4(c)(5). Note which one dropped out: 314.4(h) is the written incident response plan. Below that threshold the FTC does not require one, so a firm cannot point at its Regulation S-P incident response plan and treat the FTC obligation as answered by the same document. It is answered because the SEC requires it, not because the FTC does.

Two cautions on that five thousand figure. It counts consumers whose information you maintain, not clients you filed for this year, so prior-year files carry a small firm past the line on far fewer annual returns than people expect. And if the tax work sits in a separate accounting affiliate, the two entities are assessed separately, so decide which entity you are talking about before you count anything.

The IRS clock is the tightest one here. Publication 1345 sets six security standards, and of the six only the sixth reaches an ordinary firm that e-files. The first five are scoped to online providers, four of them narrower still. Standard 6 requires reporting a security incident as soon as possible and no later than the next business day after confirmation, and it routes a firm without an online presence to its local IRS stakeholder liaison rather than to a form. It is scoped to individual income tax returns, so a firm e-filing only business returns sits outside it.

And a Safeguards failure is an e-file failure. Revenue Procedure 2007-40, section 5.03, makes a violation of the Safeguards Rule a violation of the revenue procedure itself, which routes to sections 6 and 7. Section 7 provides for a written reprimand, suspension or expulsion from participation in IRS e-file. That is the consequence worth knowing, and it is a long way from a fine. Losing the ability to e-file in February is not a penalty a small firm absorbs.

One correction to a claim that circulates widely: revocation is the vocabulary of section 9, which is conditioned on a court injunction or comparable legal action, and it is not the route a Safeguards failure travels. Line 11 of Form W-12 is an awareness attestation, in which a preparer confirms awareness that paid preparers are required by law to create and maintain a written security plan. It is not a sworn statement that one exists.

The four plans

What each plan includes, feature by feature.
What you get
Monitor
$995 per month
Up to 10 named users and 12 protected devices
You have IT covered and your compliance paperwork is current.
Managed IT
$1,595 per month
Up to 10 named users and 12 protected devices
You want us to be your IT department, and your paperwork is current.
Monitor + Comply
$1,950 per month
Up to 10 named users and 12 protected devices
Recommended
You have IT covered but need the compliance program built and kept.
Complete
$2,495 per month
Up to 10 named users and 12 protected devices
You want one firm accountable for all of it.
Protection
Backup of every server, laptop and mailboxIncludedIncludedIncludedIncluded
Managed detection and response on every deviceIncludedIncludedIncludedIncluded
Multi-factor authentication across all five access pointsIncludedIncludedIncludedIncluded
Email filtering and security awareness trainingNot includedIncludedNot includedIncluded
Patch management to a stated targetNot includedIncludedNot includedIncluded
Proof
Dated monthly evidence pack for your recordsIncludedIncludedIncludedIncluded
Quarterly restore test, documentedIncludedIncludedIncludedIncluded
Quarterly privileged access and patch compliance reportIncludedIncludedIncludedIncluded
Cyber insurance application support, from recordsIncludedIncludedIncludedIncluded
Day-to-day IT
Helpdesk for your staffNot includedIncludedNot includedIncluded
New starters, leavers and device setupNot includedIncludedNot includedIncluded
Remediation and hardening hours included each monthNot included2 hrsNot included2 hrs
Written compliance program
Written incident response program, reviewed annuallyNot includedNot includedIncludedIncluded
Customer notification decision file, including the reasons not to notifyNot includedNot includedIncludedIncluded
Vendor inventory, due diligence and 72-hour notice termsNot includedNot includedIncludedIncluded
Annual tabletop exercise with written after-action reportNot includedNot includedIncludedIncluded
Records schedule and examiner-ready document packNot includedNot includedIncludedIncluded

Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.

Monitor + Comply is the plan built for the obligations above, because the rows in the written compliance program group are the ones that produce the Regulation S-P documents rather than only the evidence that controls are running.

What we prepare, and what stays with your CCO

We prepare

  • The written safeguards policies, the incident response plan and the disposal policies, drafted against 248.30 section by section
  • The annual risk assessment, and the evidence that it was actually performed
  • The service provider inventory, with the 72-hour notification expectation put to each provider in writing
  • Monthly monitoring, and a dated monthly record of what was running, what drifted and what we escalated
  • The document request rehearsal: we assemble the six items before anyone asks for them

Your CCO keeps

  • Adoption. The policies are yours once adopted, and adoption is a firm decision, not ours
  • The Rule 206(4)-7 annual review, and the compliance calendar it sits in
  • The notification decision, taken with counsel, and the record of the reasoning behind it
  • Every communication with the Division of Examinations
  • Legal advice, which comes from your counsel and not from us

We are a digital forensics practice, not a law firm. The distinction matters most at the notification decision, which is a legal judgment made by your CCO with counsel, on a record we help you keep.

How an engagement begins

A short call to establish what exists today, then a review of what you already have, because most firms have more written down than they think and less evidence than they need. From there the gap is a list, the list is dated, and the work starts at the top of it. Firms in remediation are the ordinary case rather than the exception, and a dated remediation plan being worked is itself the answer to a question an examiner will ask.

Plain terms

What we are, and what we are not

What we are

A private investigation agency in the making, with full digital forensics included. SleuthX is not yet a licensed private investigation agency; licensure is in progress. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. Where a matter needs field work today, whether backgrounds, locates or physical surveillance, we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization. We decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about an SEC examination

Our program is not finished. Where should we start?
Start with the document request, because it is published and it tells you what will be asked. Of the six items, the two a small firm most often cannot produce are the risk assessment and the evidence that the incident response plan was exercised rather than written. Both compliance dates have now passed, so the honest position is that the work is remediation rather than preparation. Firms in that position are common, and an examiner who sees a dated remediation plan being worked is looking at something different from a firm that has nothing.
Our custodian is SOC 2 certified. Does that cover us?
Not by itself. A SOC 2 report describes controls at the custodian, over the custodian's systems, during the period the report covers. Regulation S-P places the obligation on your firm, for your firm's records, including the copies of client information that sit in your CRM, your email and your own workstations. The custodian's report is useful evidence for the service-provider oversight file at 248.30(a)(5), and it is worth reading rather than filing. What a custodian's own contract obliges you to do is a private agreement between you and them, and it varies, so read yours rather than assuming an industry standard exists.
Our CRM vendor had an incident. Who tells our clients?
You do. Regulation S-P puts the notification obligation on the covered institution, and it does not move to the service provider because the failure happened there. A firm may agree with a provider that the provider will give notice on its behalf, but the obligation and the exposure stay with the firm. In practice this is why the 72-hour service-provider notification expectation matters so much to a small firm: it is what gives you enough of the 30 days to actually investigate.
When does the 30-day clock start?
On becoming aware that unauthorized access to sensitive customer information has occurred or is reasonably likely to have occurred. The investigation sits inside the 30 days, not in addition to them, which is the single most expensive misreading of this rule. A firm that spends three weeks deciding whether it has an incident has spent three weeks of a 30-day clock. That is also why the detection date is worth recording contemporaneously rather than reconstructing later.
We decided not to notify. Does that need to be written down?
Yes, and this is the one most likely to be missed. The rule presumes notification. A firm may determine that sensitive customer information was not accessed and that notice is therefore not required, but only after a reasonable investigation, and it has to keep the reasoning. A no-notice determination with no record behind it is a recordkeeping failure on top of whatever the underlying incident was, and it is a much harder thing to explain at an examination than the incident itself.
There are seven of us and our CCO is also the founder. Who runs the incident response plan?
Name a person, and name a backup outside the firm. A plan whose decision-maker is the person most likely to be travelling, or most likely to be the one whose account was taken over, is a plan with a single point of failure written into it. Small firms do this well by naming the CCO as the decision-maker, naming an external party who can act when the CCO cannot be reached, and writing down which of the two calls counsel. The SEC staff interview four roles at a firm this size: the CCO, the CIO, the CTO, and outsourced information technology staff. If your outside provider would be interviewed, they should know the plan before the day they are asked about it.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management