THE EXECUTIVE VIEW
Three takeaways
Establish where customer information is held and who can obtain reliable incident facts.
Test supplier notification arrangements against the decisions the firm must make.
Demonstrate that response procedures work through a realistic exercise and retained evidence.
Confirm the perimeter before assessing readiness
Smaller covered institutions were required to comply with the amended Regulation S-P by 3 June 2026; the deadline for larger entities was 3 December 2025. Covered institutions include broker-dealers, funding portals, investment companies, SEC-registered investment advisers and relevant registered transfer agents. The amendments require written incident-response arrangements and strengthen the protection of customer information. They do not automatically apply to every business serving US financial services clients. SEC small entity compliance guide (opens in a new tab)
Leadership should confirm the position for each relevant entity and service. A group may contain businesses with different regulatory obligations and shared suppliers. Understanding those relationships is essential to deciding who must act when customer information is affected.
Supplier involvement adds another layer. The firm may be responsible for decisions even when the information needed to make them sits elsewhere. The practical assessment should therefore trace the path from a supplier detecting a problem to the firm understanding the effect on its customers.
Map information to the service it supports
Start with the customer journey and identify the information required at each stage. Include the systems used to collect documents, administer accounts and communicate with customers. Establish which providers handle that information and where the firm depends on them to investigate an incident.
The map should support a response team under pressure. A list of vendor names will be insufficient if no one can establish which customers or records are involved. The team needs access to people who understand the service, the data categories and the relevant systems.
Consider a hypothetical investment firm whose outsourced administrator reports unauthorised access to a document portal. The firm's first task is to establish what information the portal holds, which customers may be affected and what the provider can substantiate. An annual assurance report may provide useful background, but it will not supply the facts of that incident.
This is a reason to keep information ownership current as services change. When a new product or provider is introduced, update the response arrangements alongside the operating process. Otherwise, the incident team may have to reconstruct relationships that delivery teams understood months earlier.
Make notification arrangements usable
The amendments require service-provider oversight arrangements designed to ensure that providers notify the covered institution as soon as possible, and no later than 72 hours after becoming aware of a qualifying security breach involving unauthorised access to a customer information system. Customer notice is a separate requirement, generally due as soon as practicable and within 30 days of becoming aware that unauthorised access to or use of customer information has occurred or is reasonably likely to have occurred, subject to specified exceptions. Ultimate responsibility for customer notice remains with the covered institution even where a provider sends it on the firm's behalf. SEC final rule on Regulation S-P (opens in a new tab)
Those timeframes should be translated into working arrangements with the people involved. Confirm the notification route, the information expected in an initial alert and how subsequent updates will reach the response team. The process should allow an incomplete but useful notification to be assessed while investigation continues.
An escalation route should identify who can make decisions when the supplier's update is uncertain or delayed. The firm should also know how it will document its assessment of the customer-notification requirement and any relevant exception. A reasonable investigation needs a record of the facts and reasoning on which the decision rests.
Avoid treating a contractual clause as the end of the exercise. Ask whether the provider has the contact details, authority and operational capacity to fulfil the arrangement. Then test whether the firm's own receiving team knows what to do with the information.
Test the response through to the customer
A useful exercise would begin with a short supplier alert that leaves several facts unresolved. Ask the participants to identify affected services, appoint the decision owner and request the evidence needed for the next judgement. Introduce a later update that changes the initial understanding of the data involved.
Follow the exercise through customer communications and operational recovery. Who checks that contact information is usable? Who answers customer questions? How are decisions revised if the investigation identifies additional people? These practical dependencies should be addressed while there is time to improve them.
Retain the decisions made, the evidence considered and the actions arising. Prioritise weaknesses that could prevent the firm from understanding exposure or communicating effectively. Give each action an owner able to change the process, and use a further exercise to establish whether the fix works.
The executive view should connect this evidence to service quality. Management needs to know where customer information remains poorly understood, which providers are difficult to reach and which decisions depend on scarce expertise. Those are useful inputs to supplier renewal, investment and growth decisions.
Three questions should guide the next review: can we identify the affected information quickly; can we obtain usable facts from the relevant provider; and can we explain the decisions made on behalf of our customers? A reliable answer depends on preparation across the whole service chain.
June 2026 perspective. Sources reflect information available at the issue date.
