The examination, item by item
Most writing about Regulation S-P explains the rule. An examination does not ask you to explain the rule. It asks you to hand over documents, and then it asks the people who wrote them what they actually do.
The SEC’s Division of Examinations ran a Compliance Outreach event for small firms in January 2026 and published the deck. It contains a mock examination: a fictional advisory firm, the initial document request the staff would send it, the roles they would interview, and the three observations they most often report back. It is the closest thing to an answer key that exists for this rule, and it is free.
The firm the SEC staff used as its example
The profile is deliberately small, and it is worth reading closely if your firm looks anything like it.
- Assets under management of $250 million.
- One office.
- Seven employees.
- Leverages a managed service provider for information technology services.
- A client custodian.
The fourth line is the one that matters most here. The staff built their example around a firm that does not run its own information technology, which is the ordinary shape of a seven-person adviser, and they carried that through to the interviews. The roles named are the CCO, the CIO, the CTO, and outsourced information technology staff. If your provider is the answer to three of those four boxes, they are in the examination whether or not anyone has told them so.
The six things they ask for first
The initial document request runs across two slides in the deck, which is why it is sometimes described as five items. There are six. The sixth is a block of related requests rather than a single line.
- Registrant compliance manual.
- Written policies and procedures addressing administrative, technical and physical safeguards for the protection of customer information.
- Information technology managed service provider contract.
- Organization charts.
- Risk assessments related to technology and cybersecurity risk, controls, threats and vulnerabilities.
- Incident response specific requests, which break down into:
- the incident response plan;
- the policies documenting the program to detect, respond to and recover from unauthorized access, including customer notification procedures;
- a listing of the staff, vendors and contractors responsible for incident response;
- a listing of all detection and monitoring tools;
- monitoring evidence;
- and, if an incident occurred during the review period, documentation that the program’s steps were followed.
Read the sixth item again. Four of its six sub-requests are not documents a firm writes once. A listing of monitoring tools, monitoring evidence, and proof that the plan’s steps were followed are all records that only exist if something was producing them month by month. That is the difference between a firm that has a program and a firm that has a binder.
The three findings they report back
The staff list three common observations. They are quoted here as printed, capitalisation and all.
- “Policies and Procedures do not appear to be reasonably designed”
- “Policies and Procedures do not appear to be enforced”
- “Policies and Procedures do not appear to exist”
The middle one is the expensive one, and it is the one a small firm walks into most easily. A firm with no policies knows it has a problem. A firm whose policies are good and whose evidence stops in March has a problem it does not know about, and it will find out in the room. The monthly record is what answers that finding, which is the whole argument for running this as a service rather than a project. The hub sets out the service calendar and the control map behind that record.
What the enforcement record actually shows
The realistic exposure at the end of an examination is a deficiency letter, and the remediation and disruption that follows one. That is the cost worth planning around. The fine is not the expensive part, and we would rather say so than sell fear.
It is still worth being accurate about the record, because a firm that checks will find it in a single search. The Commission has brought very few safeguards cases against advisers, and as of 2026 it has announced none at all under the amended rule. The cases it has brought punished one thing consistently: a gap between the written policy and the deployed control. In 2015 an adviser with no written policies, no risk assessments and no incident response plan left client information exposed for nearly four years and was censured with a $75,000 penalty. A decade later a much larger firm was charged after email account takeovers, having had a written policy across seventeen named control categories and not having enforced it.
Those two bracket the argument. One firm had nothing written. One firm had everything written and nothing enforced. Both were charged, and the second is the one that reads like an examination finding rather than an accident.
The six obligations, and the record each one leaves
Six obligations sit in Regulation S-P, and the six obligations under Regulation S-P are set out in full on the hub. What follows is the part the hub does not carry: which of them leaves a record, what that record is, and which numbered item in the staff’s own request is the one that tests it.
| Obligation | What it requires | The record it leaves | What the examiner asks for |
|---|---|---|---|
| 248.30(a)(1) | Written administrative, technical and physical safeguards for customer records and information. | The safeguards policies themselves, and the risk assessments behind them. | Items 2 and 5. |
| 248.30(a)(3) | An incident response program reasonably designed to detect, respond to and recover from unauthorized access to customer information. | Documentation of the detected access, and of the response and recovery that followed it. | Item 6, and the plan itself. |
| 248.30(a)(4) | Notice to affected individuals as soon as practicable and no later than 30 days after becoming aware, with eight required contents. | The investigation, the determination, and the basis for a decision not to notify. | Item 6, the customer notification procedures. |
| 248.30(a)(5) | Oversight of service providers through due diligence and monitoring, including an expectation of notification within 72 hours. | The oversight policies, the vendor inventory, and the provider agreement. | Item 3, the managed service provider contract. |
| 248.30(b) | Written disposal policies, now reaching consumer information as well as customer information. | The disposal policies, and evidence they were followed. | Nothing in the request names disposal. It arrives through Items 1 and 2, or in interview. |
| 204-2(a)(25) | That the six categories above are kept, and can be produced on request. | The record schedule itself. | All six items. The request is the production. |
Retention is one rule, not six. 17 CFR 248.30 sets no retention period at all. It comes from the adviser books and records rule: 17 CFR 275.204-2(e)(1) keeps these records in an easily accessible place for five years from the end of the fiscal year in which the last entry was made, with the first two years in an appropriate office of the adviser.
Three details in that sentence get misquoted often enough to be worth stating plainly. Easy accessibility runs the whole five years, not the first two. The two-year qualifier is about where the records live, not how quickly you can reach them. And the clock starts at the end of the fiscal year in which the last entry was made, not on the date of the event. The six-year figure that circulates alongside this one is real, and it belongs to a broker-dealer under 17 CFR 240.17a-4(a) rather than to an adviser.
Where this leaves a firm of seven people
A firm of seven carries the same obligations as a firm of seven hundred, with none of the staff to meet them. Nothing in the rule scales down. What scales is who does the work.
The plan built for this is Monitor and Comply, at $1,950 per month. up to 10 named users and 12 protected devices, on a 12 month term, billed monthly. It pairs the monitoring with the written compliance program and the dated monthly record that answers the middle observation above. Three other plans sit either side of it, from monitoring alone through to a fully managed programme, and the full comparison and the rate card are on the hub.
If your firm also prepares tax returns
Plenty of advisory firms file returns for their clients, and a firm that does sits under a second regulator with its own security rule. This section is short on purpose. If it does not describe you, skip it.
The rule names tax preparation by name. 16 CFR 314.2(h)(2)(viii) lists preparing individual tax returns among the activities that make a business a financial institution for the purposes of the FTC Safeguards Rule. This is not an analogy, and it is not a best practice. The activity is enumerated.
The small-firm exception is narrower than it sounds. 16 CFR 314.6 is a single sentence, and for a firm maintaining customer information concerning fewer than five thousand consumers it removes exactly four elements: 314.4(b)(1), (d)(2), (h) and (i). Everything else survives at any size, including the written information security program at 314.3(a), encryption at 314.4(c)(3) and multi-factor authentication at 314.4(c)(5). Note which one dropped out: 314.4(h) is the written incident response plan. Below that threshold the FTC does not require one, so a firm cannot point at its Regulation S-P incident response plan and treat the FTC obligation as answered by the same document. It is answered because the SEC requires it, not because the FTC does.
Two cautions on that five thousand figure. It counts consumers whose information you maintain, not clients you filed for this year, so prior-year files carry a small firm past the line on far fewer annual returns than people expect. And if the tax work sits in a separate accounting affiliate, the two entities are assessed separately, so decide which entity you are talking about before you count anything.
The IRS clock is the tightest one here. Publication 1345 sets six security standards, and of the six only the sixth reaches an ordinary firm that e-files. The first five are scoped to online providers, four of them narrower still. Standard 6 requires reporting a security incident as soon as possible and no later than the next business day after confirmation, and it routes a firm without an online presence to its local IRS stakeholder liaison rather than to a form. It is scoped to individual income tax returns, so a firm e-filing only business returns sits outside it.
And a Safeguards failure is an e-file failure. Revenue Procedure 2007-40, section 5.03, makes a violation of the Safeguards Rule a violation of the revenue procedure itself, which routes to sections 6 and 7. Section 7 provides for a written reprimand, suspension or expulsion from participation in IRS e-file. That is the consequence worth knowing, and it is a long way from a fine. Losing the ability to e-file in February is not a penalty a small firm absorbs.
One correction to a claim that circulates widely: revocation is the vocabulary of section 9, which is conditioned on a court injunction or comparable legal action, and it is not the route a Safeguards failure travels. Line 11 of Form W-12 is an awareness attestation, in which a preparer confirms awareness that paid preparers are required by law to create and maintain a written security plan. It is not a sworn statement that one exists.
The four plans
| What you get | Monitor $995 per month Up to 10 named users and 12 protected devices You have IT covered and your compliance paperwork is current. | Managed IT $1,595 per month Up to 10 named users and 12 protected devices You want us to be your IT department, and your paperwork is current. | Monitor + Comply $1,950 per month Up to 10 named users and 12 protected devices Recommended You have IT covered but need the compliance program built and kept. | Complete $2,495 per month Up to 10 named users and 12 protected devices You want one firm accountable for all of it. |
|---|---|---|---|---|
| Protection | ||||
| Backup of every server, laptop and mailbox | Included | Included | Included | Included |
| Managed detection and response on every device | Included | Included | Included | Included |
| Multi-factor authentication across all five access points | Included | Included | Included | Included |
| Email filtering and security awareness training | Not included | Included | Not included | Included |
| Patch management to a stated target | Not included | Included | Not included | Included |
| Proof | ||||
| Dated monthly evidence pack for your records | Included | Included | Included | Included |
| Quarterly restore test, documented | Included | Included | Included | Included |
| Quarterly privileged access and patch compliance report | Included | Included | Included | Included |
| Cyber insurance application support, from records | Included | Included | Included | Included |
| Day-to-day IT | ||||
| Helpdesk for your staff | Not included | Included | Not included | Included |
| New starters, leavers and device setup | Not included | Included | Not included | Included |
| Remediation and hardening hours included each month | Not included | 2 hrs | Not included | 2 hrs |
| Written compliance program | ||||
| Written incident response program, reviewed annually | Not included | Not included | Included | Included |
| Customer notification decision file, including the reasons not to notify | Not included | Not included | Included | Included |
| Vendor inventory, due diligence and 72-hour notice terms | Not included | Not included | Included | Included |
| Annual tabletop exercise with written after-action report | Not included | Not included | Included | Included |
| Records schedule and examiner-ready document pack | Not included | Not included | Included | Included |
Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.
Monitor + Comply is the plan built for the obligations above, because the rows in the written compliance program group are the ones that produce the Regulation S-P documents rather than only the evidence that controls are running.
What we prepare, and what stays with your CCO
We prepare
- The written safeguards policies, the incident response plan and the disposal policies, drafted against 248.30 section by section
- The annual risk assessment, and the evidence that it was actually performed
- The service provider inventory, with the 72-hour notification expectation put to each provider in writing
- Monthly monitoring, and a dated monthly record of what was running, what drifted and what we escalated
- The document request rehearsal: we assemble the six items before anyone asks for them
Your CCO keeps
- Adoption. The policies are yours once adopted, and adoption is a firm decision, not ours
- The Rule 206(4)-7 annual review, and the compliance calendar it sits in
- The notification decision, taken with counsel, and the record of the reasoning behind it
- Every communication with the Division of Examinations
- Legal advice, which comes from your counsel and not from us
We are a digital forensics practice, not a law firm. The distinction matters most at the notification decision, which is a legal judgment made by your CCO with counsel, on a record we help you keep.
How an engagement begins
A short call to establish what exists today, then a review of what you already have, because most firms have more written down than they think and less evidence than they need. From there the gap is a list, the list is dated, and the work starts at the top of it. Firms in remediation are the ordinary case rather than the exception, and a dated remediation plan being worked is itself the answer to a question an examiner will ask.
















