Reg S-P guide › Service-provider oversight
Most of the Reg S-P attention has gone to the incident-response program and the 30-day customer breach notice. But the amended rule also added a service-provider oversight obligation — and for a solo or small RIA that runs on a stack of third-party tools (custodian, CRM, portfolio software, email, e-signature, cloud storage), this is often the piece that actually requires new work. It's been in effect for smaller entities since June 3, 2026, so this is a live obligation, not an upcoming one.
Under the amendments, a covered institution — which includes SEC-registered investment advisers — must establish, maintain, and enforce written policies and procedures reasonably designed to require oversight, including through due diligence and monitoring, of service providers. The stated purpose is twofold:
That 72-hour vendor clock isn't a stand-alone deadline — it exists to feed your clock. Your firm's obligation is to notify affected customers as soon as practicable, and no later than 30 days after becoming aware that sensitive customer information was, or is reasonably likely to have been, accessed without authorization. If a vendor sits on a breach for weeks, your 30-day notice is already in jeopardy — which is exactly why the rule pushes the notification duty into the vendor relationship in writing.
The SEC is explicit on this point: covered institutions may outsource their operations, but they may not outsource their ultimate obligation to comply with Regulation S-P. The firm remains responsible for ensuring the required customer notices are sent — regardless of which entity actually sends them. A vendor can send the notice on your behalf; the accountability for it being sent, correctly and on time, stays with you.
| Trigger | Clock | Who acts |
|---|---|---|
| Vendor becomes aware of a breach of a system it maintains | ≤ 72 hours to notify your firm | Service provider (required by your written oversight policy / contract) |
| Your firm becomes aware sensitive customer info was (or likely was) accessed | ≤ 30 days to notify affected customers | Your firm (non-delegable responsibility; a vendor may send on your behalf) |
The rule is principles-based, so there's no SEC-mandated checklist — but "reasonably designed" written oversight, at a small firm, generally means being able to show these exist and are followed. This is a practical starting frame, not legal advice:
The amendments apply to "covered institutions" — broker-dealers (including funding portals), investment companies, registered investment advisers, and transfer agents. Compliance dates were tiered: larger entities by December 3, 2025, and smaller entities by June 3, 2026. For advisers, "smaller entity" turns on size (broadly, SEC-registered advisers under $1.5 billion in assets — confirm your own status). Both dates have now passed, so for essentially every small RIA the service-provider oversight requirement is currently in force.
Vendor oversight is a list you have to keep, not a memo you write once. AdviserLedger helps small RIAs hold a living service-provider inventory, track diligence and the 72-hour notice clause per vendor, and keep the records Reg S-P expects — in one place instead of a scattered spreadsheet.
See how it works →Also: what the SEC's FY2026 exam priorities say about Reg S-P — "oversight of third-party vendors" is named in the FY2026 priorities by that phrase.
Related on this site: the disposal rule after 2024 — customer information includes records handled “on your behalf,” so ending a vendor relationship is a disposal question about the same vendor list · initial and annual privacy notices — § 248.13 lets you share with service providers without an opt-out only if the initial notice went out and the contract term is in place.