The amended Regulation S-P requires every SEC-registered investment adviser — enforceable for smaller firms since June 3, 2026 — to maintain a written incident response program as part of its safeguards policies. (If you need the full picture of all five obligations and who counts as a "smaller entity," start with our plain-English Reg S-P overview.) This page goes deep on the one document most solo and small firms still don't have: the IRP itself. Below is a section-by-section outline of what the rule requires it to cover, in the order an incident would actually unfold.
| IRP section | What it must do |
|---|---|
| 1. Scope & definitions | State what counts as customer information for your firm (the amended definition is broad: any record with nonpublic personal information, in any form, held by you or a service provider on your behalf — including data about customers of other financial institutions in your possession) and what counts as an incident (unauthorized access or use, not just confirmed theft). |
| 2. Detection & escalation | How incidents surface (system alerts, vendor 72-hour notices, a client call about a phishing email) and who they go to. In a solo firm the "who" is you — name yourself anyway, plus your outside IT contact if you use one. The exam looks for named responsibility, not headcount. |
| 3. Assessment | Written steps to establish the nature and scope of the incident and identify which customer-information systems and which data were touched. This is the fact-gathering that every later decision (containment, harm determination, notice contents) depends on — log it as you go. |
| 4. Containment & control | Steps reasonably designed to stop further unauthorized access or use: credential resets, isolating the affected system or account, revoking vendor access, preserving evidence. Recovery steps (restoring from backup, re-enabling access) belong here too. |
| 5. The harm determination & customer notice | The default is: notice is required when sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization — unless you affirmatively determine it is not reasonably likely to be used in a way causing substantial harm or inconvenience. Your IRP should say who makes that call and require it to be documented in writing. Notices go out as soon as practicable, no later than 30 days, and must describe the incident, the data involved, and steps the individual can take to protect themselves. |
| 6. Service-provider leg | Your oversight procedures: due diligence and monitoring reasonably designed so each provider protects customer information and notifies you within 72 hours of becoming aware of a breach of a system it maintains on your behalf. Remember the clocks chain — a vendor's notice to you can start your own 30-day customer clock. |
An IRP that exists only as a PDF is the weakest form of compliance. AdviserLedger builds the written program, then keeps it alive: drill logs, vendor 72-hour attestations, and the notification clocks — timestamped evidence for the exam.
See how it works →The rule also requires written records documenting compliance — the program itself, records of any incident and your response to it, the written harm determination if you decided against notice, service-provider oversight documentation, and copies of any notices sent. In an examination, "show me your IRP" is the easy question; the follow-ups are "show me it has been exercised" and "show me the vendor arrangements that implement the 72-hour clause." A short, dated tabletop-drill log and a folder of vendor attestations answer both. Treat five years as the working retention floor within the adviser books-and-records regime.
Related on this site: Reg S-P amendments for small RIAs — the full five-obligation overview · the customer breach notice — required content and a template outline · Reg S-P vs. state breach notification laws — the five places they diverge — including why a local law-enforcement request does not pause the federal clock · what the SEC's FY2026 exam priorities say about Reg S-P. · the disposal rule — improperly disposed media are a route to unauthorized access your IRP has to contemplate