Reg S-P overview › Recordkeeping
Most of the attention on the amended Regulation S-P went to the headline obligations — the written incident response program and the customer-notification clock. But the amendments also added something quieter and, for a small firm, easier to fail: an explicit recordkeeping requirement. You don't just have to do the safeguards work; you have to be able to produce records showing you did it. This page lays out exactly which records a covered investment adviser has to keep, and for how long.
The one-line version: the amended Reg S-P requires a covered institution to maintain written records documenting compliance — its incident-response and safeguards/disposal policies plus evidence they're maintained, documentation of any unauthorized-access incident and the response, the investigation and customer-notification determination, and its service-provider oversight and contracts. For an investment adviser, keep them five years, the first two in an easily accessible place.
The SEC adopted the Regulation S-P amendments on May 16, 2024 (final rule Release 34-100155), published in the Federal Register on June 3, 2024. Alongside the new incident-response and notification obligations, the amendments added a recordkeeping provision requiring covered institutions — including SEC-registered investment advisers — to keep written documentation evidencing compliance. The obligation is live as of your firm's compliance date, which for smaller RIAs (under $1.5B in regulatory AUM) was June 3, 2026 and for larger entities was December 3, 2025 — both now passed. See the compliance-deadline explainer for where that leaves a firm that's behind.
The rule doesn't ask for a single binder — it asks for written documentation across the same areas the substantive requirements cover. In the order an examiner tends to ask for them:
| # | Record | What it is in practice |
|---|---|---|
| 1 | Policies & procedures, plus evidence of compliance | Your written incident response program and your safeguards and disposal policies and procedures — and records showing they're actually maintained, not just drafted once and filed. |
| 2 | Incident documentation | Written documentation of any detected unauthorized access to or use of customer information, and of the response you took. If nothing happened, that's a different record posture than having nothing at all — you still keep the framework that would capture it. |
| 3 | Investigation & notification determination | Written documentation of any investigation you ran and the determination you reached about whether customer notification was required. The determination — including a documented decision not to notify — is itself the record. |
| 4 | Service-provider oversight & contracts | Your written service-provider policies and procedures, your oversight/monitoring documentation, and written documentation of any contract or agreement entered into for the required service-provider protections. |
Each of these maps to a substantive obligation covered elsewhere on this site: the IRP in the incident-response outline, the notification decision in what the breach notice must contain, and vendor management in service-provider oversight. The recordkeeping rule is the layer that makes each of those provable.
The retention period depends on what kind of covered institution you are. For an investment adviser, the period lines up with the Advisers Act recordkeeping rule:
| Covered institution | Retention period |
|---|---|
| Investment adviser | 5 years, the first 2 years in an easily accessible place |
| Transfer agent | 3 years |
| Broker-dealer / funding portal / registered investment company | Per the recordkeeping rule applicable to that entity type |
The trap is assuming one number applies to everyone. If you're a dual registrant or you wear more than one hat, more than one retention period can be in play — confirm against the rule text for each capacity. "Easily accessible" for the first two years generally means you can produce it promptly, not that it's buried in cold storage.
Why this bites small firms specifically: a solo or small RIA often does the right things — patches the laptop, uses a reputable custodian, would notify clients if something went wrong — but never writes any of it down. Under the amended rule, undocumented good behavior reads, on exam, like no behavior at all. The fix is cheap: dated files, kept where you can find them.
A "not in writing" on any of these is the gap the recordkeeping rule is designed to catch.
Solo or small RIA? AdviserLedger keeps the Reg S-P paper trail as a short, dated set of records — IRP, incident log, notification-decision template, and a vendor register — so "show me your records" is a five-minute answer, not a fire drill. The beta waitlist is open; planned pricing is $249/year.
Try AdviserLedger free →Related on this site: what the SEC's FY2026 exam priorities say about Reg S-P — "developed, implemented, and maintained" is what these records evidence · Reg S-P vs. state breach notification laws — the five places they diverge. · the disposal rule — your written disposal policy is itself a record, and disposal and retention are separate questions