Regulation S-P Compliance Deadlines Have Passed. Are You Ready for an SEC Examination?

Image of a modern clock on a wall

SEC³
June 19, 2026

The countdown is over.

The compliance dates for the SEC’s amended Regulation S-P have arrived, and investment advisers can no longer view the new requirements as a future project. Whether your firm has fully implemented the required changes or is still working through policy updates, incident response procedures, and vendor oversight, the reality is that SEC examiners may begin assessing compliance at any time.

If you missed our earlier article discussing the amendments and implementation requirements, you can read it here:

Are you ready for a REG SP exam? It’s coming.

The Compliance Deadline Has Passed. Now What?

Many advisers spent the past year updating privacy notices, revising cybersecurity policies, and reviewing vendor relationships. Unfortunately, our work with advisers across the country suggests that many firms remain only partially prepared for an examination focused on Regulation S-P.

The SEC’s amendments require more than a generic cybersecurity policy. Examiners are increasingly focused on whether firms can demonstrate that they have implemented a comprehensive program to safeguard customer information and respond appropriately to security incidents.

The question is no longer whether your firm understands the rule.

The question is whether your firm can prove compliance.

What Examiners May Request

If your firm receives an examination request, SEC staff may ask for:

  • Regulation S-P policies and procedures
  • Information security policies
  • Incident response plans
  • Documentation of cybersecurity incidents
  • Vendor inventories and due diligence records
  • Employee training records
  • Risk assessments
  • Evidence of annual reviews and testing
  • Customer notification procedures
  • Records demonstrating how the firm would determine whether a notification obligation exists

Many advisers have policies. Fewer have documentation demonstrating implementation.

That distinction matters.

Areas Where Advisers Are Still Vulnerable

In reviewing adviser compliance programs, we continue to encounter several recurring weaknesses:

Incident Response Planning

Many firms have cybersecurity policies but lack documented procedures for investigating, escalating, documenting, and responding to a potential breach involving customer information.

Vendor Oversight

Third-party providers often have access to sensitive customer information. Advisers should be prepared to demonstrate how they evaluate, monitor, and oversee those vendors.

Testing and Validation

Examiners may expect firms to show evidence that policies have been tested, reviewed, and validated. A policy that sits on a shelf may provide little protection during an examination.

Documentation

A common SEC examination theme remains:

“If it isn’t documented, it didn’t happen.”

Even firms with strong controls can create unnecessary examination risk when compliance activities are not properly documented.

Why This Matters

Historically, major SEC rule changes are often followed by targeted examination initiatives designed to assess industry compliance.

While no firm can predict when a sweep examination may occur, advisers should assume that Regulation S-P compliance is now firmly on the SEC’s examination radar.

Firms that have not fully implemented the required safeguards may find themselves scrambling to answer examination requests under tight deadlines.

The cost of preparing before an examination is almost always less than the cost of responding after deficiencies have been identified.

Questions Every Adviser Should Be Able to Answer Today

Ask yourself:

  • Do we have a written incident response plan?
  • Have we updated our policies for the amended Regulation S-P requirements?
  • Can we identify every vendor that has access to customer information?
  • Have we documented our due diligence on those vendors?
  • Do employees receive training on safeguarding customer information?
  • Have we tested our response procedures?
  • Could we produce the required documentation if the SEC requested it tomorrow?

If any of these questions create uncertainty, now is the time to address them.

How SEC3 Can Help

SEC3 Compliance Consultants assists investment advisers with:

  • Regulation S-P gap assessments
  • Policy and procedure reviews
  • Incident response planning
  • Vendor oversight programs
  • Mock examinations
  • Compliance testing and documentation reviews
  • Remediation of identified deficiencies

Our team works with advisers of all sizes to evaluate readiness and identify potential examination risks before regulators do.

The Regulation S-P implementation deadline has passed.

The next question is whether your firm is prepared when the SEC comes knocking.

If you would like assistance evaluating your firm’s Regulation S-P readiness, contact SEC3 to schedule a gap analysis.

This alert is provided for informational purposes only and does not constitute legal or investment advice.

Need assistance with your compliance program? SEC’s team of experienced compliance professionals can help. For more information, please email us at info@sec3compliance.com, call (212) 706-4029 x 214, or visit our website at www.sec3compliance.com.

SEC3 provides links to other publicly available legal and compliance websites for your convenience. These links have been selected because we believe they provide valuable information and guidance. The information in this e-newsletter is for general guidance only. It does not constitute the provision of legal advice, tax advice, accounting services, or professional consulting of any kind.

Photo by CHUTTERSNAP on Unsplash