Reg S-P overview › Regulation S-ID
Almost everything written for small advisers in 2025 and 2026 has been about the 2024 Regulation S-P amendments and their smaller-entity compliance date of June 3, 2026, which has passed. That attention is deserved — it was a real change with a real deadline. But it has had a side effect worth naming: a second, older, separately-enforced program requirement sits directly beside Reg S-P in the Code of Federal Regulations, and it has been quietly in force the whole time.
Open 17 CFR Part 248 and read its title. The part is called "Regulations S-P, S-AM, and S-ID." Reg S-P is Subpart A. Regulation S-ID — Identity Theft Red Flags — is Subpart C, at §§ 248.201 and 248.202. Same part, same page of the CFR, entirely different obligation.
And the SEC's examiners treat them as a pair. In the Division of Examinations' fiscal-year 2026 priorities, they share one subsection — section VII.A.2, on page 12 — under the heading "Regulation S-ID and Regulation S-P." S-ID is named first.
Read the disclaimers, because the SEC wrote them. The FY2026 priorities document states that it "is not a rule, regulation, or statement of the U.S. Securities and Exchange Commission… it does not alter or amend applicable law, and it creates no new or additional obligations for any person." The 2022 Risk Alert quoted further down carries the same language and adds that it "is not legal advice." Neither document adds an obligation. They are useful because they tell you where staff attention goes — not because they change what the rule requires.
Reg S-P changed in 2024, so everyone re-read it. Reg S-ID did not change, so nobody did.
The eCFR keeps a change timeline for every section. For § 248.201, as displayed on September 15, 2026, that timeline reads: "No changes found for this content after 1/03/2017." The eCFR page was current through 9/10/2026, with Title 17 last amended 9/08/2026.
So the 2024 Reg S-P rulemaking — the safeguards rule, the disposal rule, the incident-response-program requirement, the 30-day customer notice — did not amend § 248.201. Your Reg S-P work does not update your S-ID Program, and vice versa. They are two written documents with two different jobs.
| Regulation S-P (as amended 2024) | Regulation S-ID | |
|---|---|---|
| Where | 17 CFR Part 248, Subpart A | 17 CFR Part 248, Subpart C (§§ 248.201–248.202) |
| In force since | Amendments: June 3, 2026 for smaller entities | November 20, 2013 |
| Threat it addresses | Unauthorized access to or use of customer information | Identity theft — "a fraud committed or attempted using the identifying information of another person without authority" (§ 248.201(b)(9)) |
| Who it applies to | Covered institutions, including SEC-registered advisers | Only advisers that are a financial institution or creditor under FCRA and offer or maintain covered accounts |
| The document | Written incident response program + safeguards policies | Written Identity Theft Prevention Program |
Subpart C's source note is 78 FR 23663, Apr. 17, 2013; the joint SEC/CFTC adopting release is Release No. 34-69359 (Apr. 10, 2013). Rulemaking and enforcement authority moved to the SEC and CFTC from the FTC under section 1088 of the Dodd-Frank Act.
Two programs, two review cycles, one place to log them. AdviserLedger keeps the dates, the reviews and the evidence in one record — so "when did we last reassess covered accounts?" has an answer with a date on it.
See how it works →This is where most small advisers stop reading, and it is the wrong place to stop. The answer is genuinely maybe — the SEC's own small-entity compliance guide says the rules apply to "most registered brokers, dealers, and investment companies, and some registered investment advisers." The sequencing matters, because each question gates the next.
Section 248.201(a)(3) puts every investment adviser "registered or required to be registered under the Investment Advisers Act of 1940" within the rule's scope — but only if the adviser is a financial institution or creditor as those terms are defined in the Fair Credit Reporting Act. The SEC's small-entity guide gives the working test:
"An SEC-regulated entity will generally qualify as a financial institution if it holds a transaction account belonging to an individual. An account may be a transaction account… if the individual account owner can personally make payments or transfers of money from his or her account to third parties, or can direct the SEC-regulated entity to make such payments or transfers to third parties."
That second clause is the one that catches advisers. You do not need to custody assets. The 2022 Risk Alert names the pattern directly: advisers "who can direct transfers or payments from individual accounts to third parties based on the individual's instructions or who act as agents on behalf of individuals."
On creditor: the guide says an entity generally qualifies if it "advances or loans money to consumers," but not where it "advances money for expenses incidental to a service provided by the entity."
Section 248.201(b)(3) defines it in two prongs, and the second prong is the one that gets under-read:
Prong (ii) has no "personal, family, or household" limit and no multiple-transactions limit. It is a risk test, not an account-type test. Note also that § 248.201(b)(1) defines account to include "an investment advisory account" expressly.
And if the answer is no, you are still not finished, which is the part worth underlining.
The determination itself is the obligation. Section 248.201(c) requires each financial institution or creditor to "periodically determine whether it offers or maintains covered accounts," and — as part of that — to "conduct a risk assessment" considering three things: the methods it provides to open accounts, the methods it provides to access accounts, and its previous experiences with identity theft. A firm that concludes it has no covered accounts has still done something the rule asks for. A firm that never asked has not.
Section 248.201(d)(1) requires a written Identity Theft Prevention Program, "appropriate to the size and complexity of the financial institution or creditor and the nature and scope of its activities." Note what that phrase does and does not do: it scales the Program to your firm. It does not scale the requirement. The SEC's small-entity guide is blunt about this — "The SEC's rules operate the same for all covered entities, regardless of their size." There is no solo-adviser carve-out.
Section 248.201(d)(2) sets four elements. The Program must include reasonable policies and procedures to:
A Red Flag is defined at § 248.201(b)(10) as "a pattern, practice, or specific activity that indicates the possible existence of identity theft." Section 248.201(f) adds that you "must consider the guidelines in Appendix A to this subpart and include in [your] Program those guidelines that are appropriate" — consider, and include what fits. The small-entity guide confirms the rules "do not single out specific red flags as mandatory… or provide a specific method of detecting red flags."
Section 248.201(e) requires the firm to:
If you are a two-person RIA with no board, the rule anticipated you. Section 248.201(b)(2)(ii) defines "board of directors," for a firm that does not have one, to include "a designated employee at the level of senior management." You designate someone, that person approves the initial Program, and you record that they did — with a date.
One narrow item you can probably set aside: the small-entity guide notes the accompanying "card issuer" rules for new or replacement cards after a change-of-address notification, and says plainly that "the SEC expects few, if any, SEC-regulated entities to be subject to these 'card issuer' rules."
In December 2022, the Division of Examinations published a Risk Alert on Reg S-ID compliance at advisers and broker-dealers. It is the most specific public account of how these Programs fail. It is also now close to four years old, and the Division's own caveat is that "some issues discussed in this Risk Alert may not be relevant to a particular firm's business." Read it as a list of failure modes, not a checklist.
| Stage | What EXAMS staff observed |
|---|---|
| Identifying covered accounts | Firms that never assessed whether any account was covered, and so never built a Program at all. Firms that identified one category once and then never reassessed — omitting online accounts, retirement accounts, and other special-purpose accounts. Firms that merged with another entity and never revisited the question. |
| Establishing the Program | Generic Programs not tailored to the business — including, in some cases, a fill-in-the-blanks template that had not been filled in. Programs that "simply restated the requirements of the regulation." Firms pointing to procedures outside the Program that had never been incorporated into it by reference. |
| Identifying red flags | Firms that listed Appendix A examples "regardless of the flags' relevance." Online-only firms listing red flags about a customer's physical appearance. Firms citing consumer-report red flags without obtaining consumer reports. Firms that wrote generic identify/detect/respond language and then included no actual red flags at all — which the Division called "merely policy statements without any actionable procedures." |
| Detecting and responding | Firms leaning on pre-existing AML procedures that were not designed to detect identity theft — for example, no process to detect forged or false credentials. Firms whose named detection procedures "did not exist." |
| Updating | Firms that moved customers from branch offices to online portals and never revisited their red flags. Firms that acquired new business lines and never brought them into the Program. |
| Administering | Insufficient (or no) periodic reports to the board or designated senior manager. Training "limited to a single sentence telling employees to be aware of identity theft." Firms relying on service providers for covered-account activity without ever evaluating the provider's identity-theft controls. |
One item in the Risk Alert is explicitly not a requirement, and it is the most useful sentence in the document for a small firm. Staff observed firms that kept no documentation of their covered-account analysis, and added: "While not required by Regulation S-ID, such documentation can assist the firm in identifying the basis for their determination to auditors and regulators." Writing down why you concluded what you concluded is optional under the rule and load-bearing in an exam.
The FY2026 priorities say the Division "will assess compliance with Regulations S-ID and S-P, as applicable," focusing on "firms' policies and procedures, internal controls, oversight of third-party vendors, and governance practices." Then, for S-ID specifically, it narrows to the written Program and two named tests — whether the policies and procedures:
"• Are reasonably designed to identify and detect red flags, particularly during customer account takeovers and fraudulent transfers; and
• Include firm training on identity theft prevention."
Our reading, offered as a reading and not as an SEC statement: those two named focus points line up with two of the 2022 Risk Alert's specific findings — firms that "experienced ongoing account takeovers over several years and did not consider any red flags related to account takeovers," and training that was one sentence long. If you are deciding where to spend a limited number of hours on a Program that already exists, those two are where four-year-old examination findings and this year's stated priorities overlap.
Worth noting for context, from the same document: the Division again lists never-examined and recently registered advisers as a standalone priority (section I.C). A firm that has never been examined and has never written an S-ID Program is sitting at the intersection of two priorities in one document.