Regulation S-P Sweep Examination: What We Are Seeing First-Hand

Key Bridge Compliance has first-hand experience with the SEC’s Regulation S-P examination process. We have reviewed two separate initial examination request letters issued to different advisers. One examination came through the SEC’s Boston Regional Office. The other is being conducted through the SEC’s Technology Controls Program and is being led by an examiner located in the Chicago Regional Office, even though the adviser is located in New England. The two initial request lists effectively matched.
That consistency suggests a coordinated examination framework rather than an approach being developed independently by individual offices. The staffing is also noteworthy.
In one examination, SEC personnel described the Technology Controls Program as part of the Division of Examinations and explained that its examinations focus specifically on technology, information security, and the protection of customer information. The lead examiner also has a technology-focused background. Taken together, the examination suggests that the SEC is bringing more specialized technology personnel into the traditional adviser examination process and coordinating those personnel with other examination staff.
A Consistent Initial Request List
The initial Regulation S-P request lists contain 26 substantive requests organized around four broad areas:
- Governance and Risk Management
- Service Providers
- Compliance Program
- Vendor Management
The requests extend well beyond simply asking for a copy of the firm’s Regulation S-P policy. Among other things, the SEC asks about:
- Organizational structure and cybersecurity reporting lines
- IT governance
- Compliance policies and annual reviews
- Compliance testing
- Privacy and information-security matters
- Cybersecurity incidents
- Formal cybersecurity risk assessments
- Vendor inventories
- Vendor contracts
- Vendor due diligence
- Ongoing vendor oversight
The request list gives advisers a useful examination-readiness roadmap. But it only tells part of the story. The more useful question is: What happens after the documents are produced?
Could Your Team Answer These Questions?
During the examination interview, SEC staff repeatedly moved from written policies to operational implementation. The questions below are not the exact questions asked by the SEC. We have restated and generalized the themes from the examination so other advisers can use them as an examination-readiness exercise.
The practical question is:
Could your CCO, management team, and technical personnel answer these questions if the SEC asked them tomorrow?
Who Owns Cybersecurity?
Could your team clearly explain:
- Who is responsible for cybersecurity and information security?
- What responsibilities belong to the CCO, management, and the IT provider?
- Who has authority to make cybersecurity decisions?
- How do compliance and IT communicate?
- Who supervises outsourced compliance and technology providers?
- When compliance identifies a technology-related issue, who owns remediation?
SEC staff spent considerable time understanding reporting lines, division of responsibilities, outsourced relationships, and coordination among the adviser, compliance personnel, and technology providers.
How Do You Know Your Controls Are Working?
Installing a cybersecurity control is different from demonstrating that it works. Could your team explain:
- What cybersecurity controls are currently in place?
- Who monitors them?
- What reports and alerts are generated?
- Who receives those alerts?
- Who investigates them?
- What happens when an exception is identified?
- How does management gain comfort that its technology provider’s controls are operating effectively?
One recurring pattern in the examination was the progression from “What control do you have?” to “How do you know the control actually works?”
Could Your Technical Team Explain Your Environment?
The SEC directed detailed questions to the adviser’s managed technology provider. Could your technical team explain:
- Where firm and client information resides?
- Which systems are cloud-based and which are on-premise?
- How identity and access management works?
- Where multifactor authentication is required?
- How conditional access is configured?
- How remote access is secured?
- Whether employees have administrative privileges?
- How endpoints are protected and monitored?
- How access is revoked when an employee leaves?
- Whether access to non-Microsoft systems is periodically reviewed?
The discussion covered VPNs, MFA, conditional access, endpoint protection, administrative privileges, access termination, single sign-on, and overall system architecture.
What Can Employees Do From Personal Devices?
Personal-device access received particular attention. Could your team explain:
- Whether employees can access firm systems from personal laptops or phones?
- What information they can access?
- What happens when a new mobile device attempts to connect?
- Whether PINs, encryption, remote wipe, or other mobile controls are required?
- Whether employees can move firm information outside approved applications?
- Whether the firm can detect or block emails containing sensitive information?
- Who receives data-loss-prevention alerts?
The SEC followed the issue from basic device access into mobile controls, remote wipe, data-loss prevention, and alert escalation.
Could You Walk an Examiner Through a Cybersecurity Incident?
A written incident response plan is only the starting point. Could your team explain:
- Who gets contacted first when a potential incident is identified?
- Who determines whether customer information may have been affected?
- When are legal counsel and cyber insurance involved?
- Who coordinates the response?
- How would an affected device be isolated?
- What happens if the IT provider is remote and physical intervention is necessary?
- Has the incident response plan been tested?
- When was the last tabletop exercise?
- What documentation would demonstrate what happened and how the firm responded?
SEC staff asked about the written plan, when it became operational, whether it had been tested, and how the adviser would respond to an actual cybersecurity event.
Have You Performed a Formal Cybersecurity Risk Assessment?
The examination distinguished between routine IT monitoring and a formal cybersecurity risk assessment. Could your team answer:
- Have you formally identified cybersecurity threats and vulnerabilities?
- Does the assessment cover every system containing client nonpublic personal information?
- Does it include custodians, CRM systems, portfolio systems, Microsoft, and other third parties?
- How do identified risks determine which controls you test?
- How often is the assessment updated?
- Can you connect individual risks to specific controls, testing, and remediation?
The SEC specifically focused on whether all systems containing client information would fall within the scope of the assessment and how identified risks would drive future compliance testing.
Do You Know Where Client Information Lives?
A vendor list is not necessarily a data map. Could your firm identify:
- Every system that stores or processes client nonpublic personal information?
- What categories of information each system contains?
- Who can access each system?
- Whether access is periodically reviewed?
- How the inventory connects to the firm’s cybersecurity risk assessment?
The SEC specifically asked whether the adviser maintained a written inventory or data map identifying where client NPI resides, which systems hold it, what information is held, and who has access.
Can You Defend Your Vendor Oversight Program?
Vendor oversight was one of the most heavily explored areas. Could your team explain:
- Who owns vendor due diligence?
- What happens before a new vendor is approved?
- Which vendors receive enhanced scrutiny?
- Do you send your own questionnaire or rely only on vendor-produced materials?
- Who reviews SOC 2 or SSAE 18 reports?
- How do you determine whether a vendor is high risk?
- How frequently are vendors re-reviewed?
- What triggers an interim review?
- How do you address Regulation S-P’s 72-hour service-provider notification requirement?
- What happens when a large vendor will not amend its agreement?
- How is ongoing monitoring documented?
The SEC explored the distinction between collecting vendor information and actually performing and documenting an independent review.
What Happens When a Vendor Is Terminated?
Vendor offboarding can be easy to overlook. Could your team explain:
- How vendor access is terminated?
- How customer information is returned, transferred, or destroyed?
- How destruction is verified?
- What happens when one technology provider replaces another?
- Who documents completion of the process?
SEC staff specifically asked how customer information would be handled when a vendor relationship ends.
Could You Reconstruct an Incident Months Later?
Logging and record retention also became part of the examination. Could your technical team explain:
- What security logs are retained?
- How long they are retained?
- Whether the firm deliberately selected those retention periods or accepted vendor defaults?
- Whether the logs would allow the firm to reconstruct an incident?
- Whether the firm could determine which accounts, devices, or customer information were affected?
SEC staff focused on whether retained logs would allow the adviser to reconstruct the scope of an incident and determine what customer information had actually been affected.
What Happened Next: Supplemental Requests
Approximately a month after the initial production was due, and following the examination interview, the SEC issued another set of targeted document requests.
These supplemental requests are particularly instructive because they show how information obtained during the initial production and interview can lead directly to requests for additional evidence.
Among other things, the SEC requested:
- Completed service-provider review checklists supporting the Annual Compliance Review, including reviewer findings and sign-off.
- The firm’s current Business Continuity Plan.
- A detailed explanation of who detects, receives, investigates, and contains firewall, endpoint, and Microsoft 365 alerts, and when internal personnel are notified.
- Confirmation that MFA is enforced on required systems, including identification of any bypasses, exemptions, or opt-outs.
- A list of systems using SSO, identification of systems containing customer information, and an explanation of MFA controls where SSO is not used.
- The current Incident Response Plan.
- A written data map showing where client NPI resides, what categories of NPI are stored in each system, who has access, and whether access is periodically reviewed.
- Confirmation of vendor breach-notification requirements and how those obligations are tracked.
- Documentation regarding vendor questionnaires, pre-engagement information-security reviews, contractual safeguards, ongoing cybersecurity reviews, and review of SOC 2 or SSAE 18 reports.
- The process for securely returning or destroying customer information when a vendor relationship is terminated.
The Examination Pattern Is Becoming Clear
The process we are seeing can be summarized as:
Initial request list → document production → examiner interview → targeted supplemental requests
At each stage, the inquiry becomes more specific. The progression is essentially:
- Describe the control.
- Identify who owns it.
- Explain how it operates.
- Explain how compliance oversees it.
- Demonstrate how you know it is effective.
- Produce the supporting documentation.
- Explain what happens when the control fails.
- Show how exceptions are remediated and tracked to completion.
A statement that employees use MFA leads to questions about which systems, which authentication factors, and whether any exceptions exist.
If an outside security operations center monitors cybersecurity alerts, that leads to questions about exactly who receives the alerts, who investigates them, who contains the threat, and when management is notified.
A statement that vendor due diligence is performed leads to questions about questionnaires, SOC reports, contractual safeguards, periodic reviews, breach notification, and vendor offboarding.
KBC Client Resources
Key Bridge Compliance will continue sharing developments from the examination first with our clients as the process progresses. We have already provided KBC clients with:
- A of the initial Regulation S-P examination request list.
- An anonymized version of the SEC’s supplemental request list.
If you are not a current client you can download these resources by completing this form. We encourage advisers to use both as a practical tabletop examination exercise. Bring together compliance, operations, management, and the individuals responsible for the firm’s technology environment and ask:
Could we answer this today? Could we produce the documentation? And would our CCO, management team, and technical personnel give the SEC a consistent answer? That may be one of the most effective ways to determine whether your Regulation S-P program is truly examination-ready.
Takeaways
- Two separate initial examination request lists involving different SEC offices effectively matched, indicating a coordinated approach.
- The SEC is incorporating personnel with deeper technology experience into adviser examinations. Examiners are testing implementation, not merely reviewing written policies.
- Expect detailed questions about IT governance, MFA, mobile devices, incident response, cybersecurity risk assessments, data mapping, logging, and vendor oversight.
- Oral answers can lead directly to supplemental requests for supporting evidence.
- Compliance, management, and technology personnel should prepare together.
- KBC clients will receive redacted copies of both the initial and supplemental requests as examination-readiness tools.