72 Hours
Reg S-P Service Provider Notice
Policies must be reasonably designed to obtain breach notification from providers this quickly
30 Days
Customer Notification Clock
From determining that sensitive customer information was, or likely was, accessed without authorization
June 3, 2026
Smaller Entity Compliance Date
Amended Reg S-P now applies to advisers and broker-dealers of every size
4 Phases
FINRA's Vendor Framework
Decide, diligence, onboard, supervise — Regulatory Notice 21-29
There is a moment that repeats itself across regulated firms every quarter, and it is worth naming precisely because nobody plans for it.
A firm spends three weeks assembling answers to a due diligence questionnaire sent by a client's investors. Two months later, the same firm sends a nearly identical questionnaire to one of its own service providers. The people doing both jobs sit in the same office. Neither exercise made the other easier.
This is the structural condition of third-party risk in 2026: every regulated firm is simultaneously the assessor and the assessed. And for most firms, neither side of that produces anything durable, because none of the work was ever captured as a record.
What changed: you are in somebody's vendor register now
Two developments made this everyone's problem rather than a large-firm problem.
The first is amended Regulation S-P. The SEC adopted the amendments in May 2024, with compliance dates of December 3, 2025 for larger entities and June 3, 2026 for smaller entities — a date that has now passed. There is no longer a size threshold below which a registered adviser or broker-dealer can treat service provider oversight as an aspiration.
The second is that investors and institutional allocators have industrialised their own diligence. A firm managing outside capital is now routinely assessed by an allocator's chosen cybersecurity assessor, on that assessor's schedule, against that assessor's framework — and the findings go to the allocator, not only to the firm.
The practical consequence is that your control posture is being read by people who are not your regulator and who will not wait for your next annual review.
What amended Reg S-P actually requires — and one thing it does not
This is worth getting right, because it is widely misreported.
Amended Reg S-P requires covered institutions to adopt an incident response program within their written policies and procedures, reasonably designed to detect, respond to and recover from unauthorized access to customer information. Two elements draw the most attention:
⚖️ Rule
The word doing the work in both requirements is reasonably designed. That is an evidentiary standard, not a documentary one. A policy that describes an oversight program, with no record of the program having operated, is not a reasonably designed program. It is a description of one.
FINRA Notice 21-29: outsourcing does not transfer the obligation
For broker-dealers and dually registered firms, FINRA Regulatory Notice 21-29 remains the clearest statement of the expectation. Its central principle is a single sentence: outsourcing an activity or function does not relieve a member firm of its regulatory compliance and supervision obligations over that function.
The Notice frames vendor management as four sequential phases, and it is a better planning structure than most commercial frameworks because it is what examiners have in mind.
Phase 1 — The Decision to Outsource
Whether a function should be performed by a third party at all, documented as a decision rather than as a purchase. Examiners ask who approved it, on what analysis, and whether the function is one that can be supervised once it leaves the building.
Phase 2 — Due Diligence on Prospective Vendors
Assessment before selection, proportionate to the criticality of the function and the sensitivity of the data involved. This is where SOC 2 reports, penetration test summaries and financial condition are reviewed — and where the review needs to be recorded, not merely performed.
Phase 3 — Onboarding
Contract terms, data handling commitments, access provisioning, breach notification expectations, and the definition of what the firm will monitor. The Reg S-P 72-hour expectation belongs here.
Phase 4 — Ongoing Supervision
The phase most firms treat as optional. Re-assessment on a defined cadence, tracking of the vendor's own sub-processors, re-collection of expiring SOC 2 reports, and evidence that the monitoring described in the WSP actually happened.
FINRA has grouped the obligations it expects firms to consider under four headings — supervision, registration, cybersecurity and business continuity — and its more recent annual oversight reporting has kept third-party and vendor risk in view rather than retiring it.
What assessors actually test, as distinct from what the questionnaire asks
A due diligence questionnaire asks whether you have multi-factor authentication. The assessment tests whether MFA is enforced for every account including service accounts and break-glass administrators, whether any conditional access policy grants an exclusion, and when that exclusion was last reviewed.
The gap between the two is where findings come from. In our experience the recurring items are consistent:
None of these is exotic. All of them are ordinary operational drift, and drift is invisible without something watching for it.
Why firms answer the same questions twice
Here is the part that costs the most and gets discussed the least.
When a firm completes a questionnaire, it produces a document. The document is sent, filed, and — in nearly every case we have seen — never reused. Six months later a different requester asks materially the same questions, and the work starts over: the same screenshots recaptured, the same configuration re-checked, the same people interrupted.
The reason is not laziness. It is that the first exercise produced a deliverable rather than a record. A screenshot of a settings page proves what was true on the afternoon someone took it. It cannot tell you whether the setting held last Tuesday, and it cannot be queried.
An evidence record is a different object. It is produced continuously as controls are tested, it carries a timestamp and the observed configuration, and it answers the next questionnaire by retrieval instead of by reconstruction. The difference compounds: the second assessment costs a fraction of the first, and the fifth costs almost nothing.
"It's been remediated" is not evidence
The most consequential sentence in this entire process is the one firms send in response to findings.
A finding arrives. The firm fixes it, or believes it has, and replies that the item has been remediated. That reply is an assertion. It may well be true. But the assessor has no way to distinguish it from an assertion that is not true, and neither, in most cases, does the firm — because nobody re-tested.
✅ action
The same logic applies to risk you decide not to fix. A deliberate acceptance, with a named owner, a written rationale and a review date, reads as governance. An open item with no decision record reads as neglect. The underlying facts are identical; the conclusion an assessor draws is not.
What a reusable evidence record looks like
Note what is not on this list: a new policy document. Most firms in this position do not have a policy gap. They have an evidence gap, and writing another document does not close it.
The question worth answering before somebody else asks it
If a due diligence questionnaire arrived tomorrow from a client's investors, how much of it could you answer from records you already hold — and how much would you rebuild from scratch?
For most regulated firms the honest answer is that nearly all of it gets rebuilt. That is not a reflection of a weak compliance function. It is what happens when assessment is treated as an event rather than as a by-product of operating. The firms that change this in 2026 will not be the ones with the longest policy manuals. They will be the ones who can answer the second questionnaire in an afternoon.
The Centience Governance Score is a free, five-minute self-assessment that scores your firm 0–100 across cybersecurity, data and records, supervision, infrastructure, and AI governance — and shows you where your evidence record stands before an assessor does.
Get Your Free Governance Score
🔗 Related Service: Cybersecurity Governance
Control testing against your live environment, findings with a named owner and a citation, vendor and sub-processor tracking, and an evidence record that accumulates as it is produced.
For the records foundation underneath this, see our guide to data governance and FINRA 17a-4 retention, what Reg S-P now requires of smaller RIAs, or how Centience supports financial services firms specifically.

Frequently Asked Questions




