Get Reg S-P ready →

Reg S-P guide › Service-provider oversight

Reg S-P service-provider oversight: the vendor obligation small RIAs keep overlooking

Last reviewed July 23, 2026 · official SEC sources linked below

Most of the Reg S-P attention has gone to the incident-response program and the 30-day customer breach notice. But the amended rule also added a service-provider oversight obligation — and for a solo or small RIA that runs on a stack of third-party tools (custodian, CRM, portfolio software, email, e-signature, cloud storage), this is often the piece that actually requires new work. It's been in effect for smaller entities since June 3, 2026, so this is a live obligation, not an upcoming one.

The core idea in one sentence: you can hand your data to vendors, but you cannot hand off your responsibility for it — the SEC requires written policies and procedures to oversee those vendors, and your firm remains on the hook for notifying customers no matter which party's system was breached.

What the rule actually requires

Under the amendments, a covered institution — which includes SEC-registered investment advisers — must establish, maintain, and enforce written policies and procedures reasonably designed to require oversight, including through due diligence and monitoring, of service providers. The stated purpose is twofold:

  1. to ensure service providers take appropriate measures to protect against unauthorized access to or use of customer information; and
  2. to ensure the service provider notifies the covered institution as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system the provider maintains.

That 72-hour vendor clock isn't a stand-alone deadline — it exists to feed your clock. Your firm's obligation is to notify affected customers as soon as practicable, and no later than 30 days after becoming aware that sensitive customer information was, or is reasonably likely to have been, accessed without authorization. If a vendor sits on a breach for weeks, your 30-day notice is already in jeopardy — which is exactly why the rule pushes the notification duty into the vendor relationship in writing.

The duty you can't outsource

The SEC is explicit on this point: covered institutions may outsource their operations, but they may not outsource their ultimate obligation to comply with Regulation S-P. The firm remains responsible for ensuring the required customer notices are sent — regardless of which entity actually sends them. A vendor can send the notice on your behalf; the accountability for it being sent, correctly and on time, stays with you.

How the pieces fit together

TriggerClockWho acts
Vendor becomes aware of a breach of a system it maintains≤ 72 hours to notify your firmService provider (required by your written oversight policy / contract)
Your firm becomes aware sensitive customer info was (or likely was) accessed≤ 30 days to notify affected customersYour firm (non-delegable responsibility; a vendor may send on your behalf)

What a small RIA can put in place

The rule is principles-based, so there's no SEC-mandated checklist — but "reasonably designed" written oversight, at a small firm, generally means being able to show these exist and are followed. This is a practical starting frame, not legal advice:

Where this bites hardest: the vendors you forgot are vendors. Email providers, e-signature tools, scheduling apps, and cloud backups all routinely hold client PII, yet they rarely make it onto a firm's "compliance" radar the way the custodian and CRM do. The inventory step is what surfaces them.

Who this applies to and when

The amendments apply to "covered institutions" — broker-dealers (including funding portals), investment companies, registered investment advisers, and transfer agents. Compliance dates were tiered: larger entities by December 3, 2025, and smaller entities by June 3, 2026. For advisers, "smaller entity" turns on size (broadly, SEC-registered advisers under $1.5 billion in assets — confirm your own status). Both dates have now passed, so for essentially every small RIA the service-provider oversight requirement is currently in force.

Vendor oversight is a list you have to keep, not a memo you write once. AdviserLedger helps small RIAs hold a living service-provider inventory, track diligence and the 72-hour notice clause per vendor, and keep the records Reg S-P expects — in one place instead of a scattered spreadsheet.

See how it works →

Related guides

Also: what the SEC's FY2026 exam priorities say about Reg S-P — "oversight of third-party vendors" is named in the FY2026 priorities by that phrase.

Related on this site: the disposal rule after 2024 — customer information includes records handled “on your behalf,” so ending a vendor relationship is a disposal question about the same vendor list · initial and annual privacy notices — § 248.13 lets you share with service providers without an opt-out only if the initial notice went out and the contract term is in place.

Official sources