Get Reg S-P ready →

Writing the Reg S-P incident response program: what the written IRP actually has to contain

Last reviewed July 11, 2026 · sourced to SEC and law-firm guidance (linked below)

The amended Regulation S-P requires every SEC-registered investment adviser — enforceable for smaller firms since June 3, 2026 — to maintain a written incident response program as part of its safeguards policies. (If you need the full picture of all five obligations and who counts as a "smaller entity," start with our plain-English Reg S-P overview.) This page goes deep on the one document most solo and small firms still don't have: the IRP itself. Below is a section-by-section outline of what the rule requires it to cover, in the order an incident would actually unfold.

The standard, in one sentence. Your program must be reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information — and it must include written procedures to assess the incident, contain and control it, and notify affected individuals. A one-page "we take security seriously" policy does not meet that standard.

Section-by-section: the six pieces of a compliant IRP

IRP sectionWhat it must do
1. Scope & definitionsState what counts as customer information for your firm (the amended definition is broad: any record with nonpublic personal information, in any form, held by you or a service provider on your behalf — including data about customers of other financial institutions in your possession) and what counts as an incident (unauthorized access or use, not just confirmed theft).
2. Detection & escalationHow incidents surface (system alerts, vendor 72-hour notices, a client call about a phishing email) and who they go to. In a solo firm the "who" is you — name yourself anyway, plus your outside IT contact if you use one. The exam looks for named responsibility, not headcount.
3. AssessmentWritten steps to establish the nature and scope of the incident and identify which customer-information systems and which data were touched. This is the fact-gathering that every later decision (containment, harm determination, notice contents) depends on — log it as you go.
4. Containment & controlSteps reasonably designed to stop further unauthorized access or use: credential resets, isolating the affected system or account, revoking vendor access, preserving evidence. Recovery steps (restoring from backup, re-enabling access) belong here too.
5. The harm determination & customer noticeThe default is: notice is required when sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization — unless you affirmatively determine it is not reasonably likely to be used in a way causing substantial harm or inconvenience. Your IRP should say who makes that call and require it to be documented in writing. Notices go out as soon as practicable, no later than 30 days, and must describe the incident, the data involved, and steps the individual can take to protect themselves.
6. Service-provider legYour oversight procedures: due diligence and monitoring reasonably designed so each provider protects customer information and notifies you within 72 hours of becoming aware of a breach of a system it maintains on your behalf. Remember the clocks chain — a vendor's notice to you can start your own 30-day customer clock.

An IRP that exists only as a PDF is the weakest form of compliance. AdviserLedger builds the written program, then keeps it alive: drill logs, vendor 72-hour attestations, and the notification clocks — timestamped evidence for the exam.

See how it works →

The mistake small firms make: writing the plan, skipping the evidence

The rule also requires written records documenting compliance — the program itself, records of any incident and your response to it, the written harm determination if you decided against notice, service-provider oversight documentation, and copies of any notices sent. In an examination, "show me your IRP" is the easy question; the follow-ups are "show me it has been exercised" and "show me the vendor arrangements that implement the 72-hour clause." A short, dated tabletop-drill log and a folder of vendor attestations answer both. Treat five years as the working retention floor within the adviser books-and-records regime.

A realistic tabletop drill for a solo firm (30 minutes)

  1. Pick a plausible scenario — e.g., your CRM vendor emails that an unauthorized party accessed a database including your client records.
  2. Walk your own IRP sections in order — who was notified, what would you assess first, what would containment mean when the breach is on the vendor's systems, not yours?
  3. Draft the harm determination — would this trigger the 30-day notice? Write down the reasoning either way; the written "no substantial harm" determination is itself a required record if you decide against notice.
  4. Time-check the clocks — vendor's 72-hour notice → your assessment → notice out well inside 30 days. If any step has no owner or no template, that's the gap to fix.
  5. Log it — date, scenario, participants, gaps found, fixes made. That one page converts your IRP from a dead document into demonstrable compliance.

Sources

Related on this site: Reg S-P amendments for small RIAs — the full five-obligation overview · the customer breach notice — required content and a template outline · Reg S-P vs. state breach notification laws — the five places they diverge — including why a local law-enforcement request does not pause the federal clock · what the SEC's FY2026 exam priorities say about Reg S-P. · the disposal rule — improperly disposed media are a route to unauthorized access your IRP has to contemplate