Get Reg S-P ready →

Reg S-P overview › Recordkeeping

Reg S-P recordkeeping: the part small RIAs forget until an examiner asks "show me"

Last reviewed July 26, 2026 · official SEC sources linked below

Most of the attention on the amended Regulation S-P went to the headline obligations — the written incident response program and the customer-notification clock. But the amendments also added something quieter and, for a small firm, easier to fail: an explicit recordkeeping requirement. You don't just have to do the safeguards work; you have to be able to produce records showing you did it. This page lays out exactly which records a covered investment adviser has to keep, and for how long.

The one-line version: the amended Reg S-P requires a covered institution to maintain written records documenting compliance — its incident-response and safeguards/disposal policies plus evidence they're maintained, documentation of any unauthorized-access incident and the response, the investigation and customer-notification determination, and its service-provider oversight and contracts. For an investment adviser, keep them five years, the first two in an easily accessible place.

Where this came from

The SEC adopted the Regulation S-P amendments on May 16, 2024 (final rule Release 34-100155), published in the Federal Register on June 3, 2024. Alongside the new incident-response and notification obligations, the amendments added a recordkeeping provision requiring covered institutions — including SEC-registered investment advisers — to keep written documentation evidencing compliance. The obligation is live as of your firm's compliance date, which for smaller RIAs (under $1.5B in regulatory AUM) was June 3, 2026 and for larger entities was December 3, 2025 — both now passed. See the compliance-deadline explainer for where that leaves a firm that's behind.

The four records you have to keep

The rule doesn't ask for a single binder — it asks for written documentation across the same areas the substantive requirements cover. In the order an examiner tends to ask for them:

#RecordWhat it is in practice
1Policies & procedures, plus evidence of complianceYour written incident response program and your safeguards and disposal policies and procedures — and records showing they're actually maintained, not just drafted once and filed.
2Incident documentationWritten documentation of any detected unauthorized access to or use of customer information, and of the response you took. If nothing happened, that's a different record posture than having nothing at all — you still keep the framework that would capture it.
3Investigation & notification determinationWritten documentation of any investigation you ran and the determination you reached about whether customer notification was required. The determination — including a documented decision not to notify — is itself the record.
4Service-provider oversight & contractsYour written service-provider policies and procedures, your oversight/monitoring documentation, and written documentation of any contract or agreement entered into for the required service-provider protections.

Each of these maps to a substantive obligation covered elsewhere on this site: the IRP in the incident-response outline, the notification decision in what the breach notice must contain, and vendor management in service-provider oversight. The recordkeeping rule is the layer that makes each of those provable.

How long you keep them — and the entity-type trap

The retention period depends on what kind of covered institution you are. For an investment adviser, the period lines up with the Advisers Act recordkeeping rule:

Covered institutionRetention period
Investment adviser5 years, the first 2 years in an easily accessible place
Transfer agent3 years
Broker-dealer / funding portal / registered investment companyPer the recordkeeping rule applicable to that entity type

The trap is assuming one number applies to everyone. If you're a dual registrant or you wear more than one hat, more than one retention period can be in play — confirm against the rule text for each capacity. "Easily accessible" for the first two years generally means you can produce it promptly, not that it's buried in cold storage.

Why this bites small firms specifically: a solo or small RIA often does the right things — patches the laptop, uses a reputable custodian, would notify clients if something went wrong — but never writes any of it down. Under the amended rule, undocumented good behavior reads, on exam, like no behavior at all. The fix is cheap: dated files, kept where you can find them.

A short recordkeeping self-check

  1. Is your incident response program a dated document with a named owner — and can you show it's been reviewed, not just created?
  2. If you had an incident tomorrow, is there a place it would be written down — what happened, what you did, and the notify/don't-notify decision with its reasoning?
  3. For each vendor touching client data, do you have the oversight documentation and the contract terms on file?
  4. Are these kept somewhere you could hand to an examiner promptly for the first two years, and retained for five?

A "not in writing" on any of these is the gap the recordkeeping rule is designed to catch.

Solo or small RIA? AdviserLedger keeps the Reg S-P paper trail as a short, dated set of records — IRP, incident log, notification-decision template, and a vendor register — so "show me your records" is a five-minute answer, not a fire drill. The beta waitlist is open; planned pricing is $249/year.

Try AdviserLedger free →

Related on this site: what the SEC's FY2026 exam priorities say about Reg S-P — "developed, implemented, and maintained" is what these records evidence · Reg S-P vs. state breach notification laws — the five places they diverge. · the disposal rule — your written disposal policy is itself a record, and disposal and retention are separate questions

Official sources