Skip to main content

Author: Renaissance Regulatory Services

Summertime is Here! Compliance Can Keep You Cool!

As the summer heat kicks in, while there is little indication that the regulatory “warming trend” will subside any time soon, the typical slowdown in business over the summer months provides opportunities to review your firm’s compliance program. Focusing on selected aspects of your compliance program may also reveal ways to cut costs associated with compliance in the long run. The secret to an efficient review is to focus on the regulatory target areas and not try to do too much.

The Regulatory Focus

The regulatory focus on the retail investor will continue. The SEC and FINRA have enhanced their practices to target the areas of the highest risk to the public. Novel new products such as digital assets, structured securities, and prediction markets are in focus. The updates to Regulation S-P brought renewed focus on firm’s due diligence practices for vendors that host systems and access or store customer data. Piling on all that is the increasing risk of cybercrime – both internal and external – and the increasing use of artificial intelligence tools. If that’s all buttoned up, then you don’t want to get caught off guard with “old school” compliance gaps such as inadequate policies and procedures, recordkeeping, or supervision. There are certainly a wide range of focus areas that can be addressed. Like many firms, the regulators are using AI to assist in their analysis, which provides the ability to cover a wider range of topics in exams.

Identifying the Areas to Review

With the above in mind, the review of your firm’s operations should focus on those areas most relevant to your business. First, assess your products and services from a financial perspective, identifying products and services that generate the most revenue. The compliance review should focus on those areas of your firm’s operations that generate the most business, i.e. revenue. Also, consider looking at the policies and procedures for supervising branch offices and remote locations. Additionally, if there is a product or service that you have not reviewed in some time, or that is new to your firm, the policies and procedures related to those areas should be included in your review. For example, if you’re selling more ETF’s or insurance securities, look at the supervisory and operational procedures for those products. If you recently added digital assets or prediction market access, look at the procedures governing those practices and the training programs in place for the public facing and supervisory personnel.

Second, consider any areas where you rely on third parties to provide a significant support function. The most common for broker-dealers is the clearing function, while RIAs may rely heavily on the custodian or a portfolio valuation service. Create a list of vendors that includes the services they provide, the contact people for the vendor, and the contract date. Larger firms should also add the person(s) internally who own the relationship, such as the financial officer for accounting software, the operations officer for clearing relationships, etc. Consider all services provided by third parties or affiliates (services provided by affiliates are typically considered outsourced) including surveillance and compliance management vendors. In addition to the clearing and custody relationships noted above, many firms use third party vendors to support internet access and email, storage of books and records, payroll processing, and accounting functions. Some other common areas that are often overlooked are the phone systems, technology support, law firms, and consultants.

Conducting the Review

For the areas you’ve selected to review, determine how the business is processed from start to finish. It may be helpful to create a flow diagram of the process that identifies “touch points” where a supervisory procedure or control would/should exist. A good example would be where the representative forwards completed paperwork for a variable annuity transaction to a principal for review. These points could include the representative assembling the paperwork, delivering it to a sales assistant, and the sales assistant forwarding it to the principal or a centralized operations department for review and approval. Your procedures should address a control or supervisory process for each time the paperwork changes hands. Perhaps the sales assistant does a check to ensure all the proper completed paperwork is included, and in the predetermined order, before forwarding to the principal. This simple control will reduce delays in processing paperwork and the time that the principal has to spend reviewing, and supervising, the transaction, thereby saving time and money. When reviewing processes, policies and procedures for new lines of business, be careful not to try to fit a square peg into a round hole. That is, don’t assume that the procedure for supervising an equity security transaction will fit the exchange traded note. You must consider the unique aspects of the product, related disclosures, and the customer’s objectives. This is a simple example and more complex operations require a more in-depth assessment even when processes are automated, we often find data breaks where two or more data feeds are required to complete a process. These need to be carefully mapped out.

If your firm relies on third party vendors and does not have a due diligence process for assessing them, develop one – you are late to the game. Start with the vendor contract to determine if the regulatory requirements are met. For example, Regulation S-P now formally requires notification of a breach within 72 hours. Also, if the vendor is deemed a “Service Bureau” for the purposes of the SEC’s Books and Records Rules, the vendor must agree to make the records available to the Regulators. Similarly consider any AML, business continuity, and privacy issues that may arise from the relationship. For FINRA members, these arrangements may also have to be disclosed before implementation. Depending on the nature of the vendor relationship, your due diligence process should include reviews of the vendor’s internal control reports, business continuity plans, information and technology security, and insurance coverage such as E&O, theft, and professional liability. Ongoing vendor monitoring is critical. While most services can be monitored on an ongoing basis – that is, if the service fails you know it and correct it with a backup plan – it’s a good practice to schedule a formal meeting at least annually with the vendors’ representatives to review the services and reassess the areas covered in the due diligence process.

Correction and Documentation

As you complete each review, create a short, written summary of the review and gap analysis performed, including the corrective steps to be taken, if any. For material deficiencies, consider reviewing with counsel to determine the potential regulatory impact. In addition to amending written policies and procedures, corrective actions should include training employees to ensure that proper procedures are implemented, and the new procedures are adequately communicated.

Conclusion

A compliance review provides a great opportunity to reassess your business operations, not only for compliance purposes, but to identify areas of efficiency and cost savings. This type of review can be incorporated into your annual review requirements and supervisory controls testing. Your review should be reasonable, and you should not try to do too much. Once you start digging, you may find that one issue will take longer than you anticipated completing. It’s better to do a portion at a time and complete a full review on an area than to take on too much and leave items undone.

So, what are your plans this summer? Awaiting the regulatory heat? Or sitting back and enjoying the compliance reliance?

By: Louis Dempsey, CRCP, CSCP


Business professionals looking at charts.

Regulation S-P: Next Steps for Investment Advisers

As the SEC’s amended Regulation S-P requirements become effective for all investment advisers, firms should now be focused on implementation of the requirements, including cybersecurity governance, vendor oversight, use of artificial intelligence (AI), and testing their ability to respond effectively to cyber incidents.

We outline key areas firms should prioritize over the balance of the year.

Implementation Readiness

The Regulation S-P requirements now place greater emphasis on incident response, customer notification, and protection of customer information.

Firms should ensure they have:

  • Written incident response procedures
  • Escalation and breach assessment protocols
  • Customer notification procedures
  • Vendor oversight programs
  • Information security controls
  • Documented employee training
  • Evidence of testing and governance

Recommended Action Items:

  • Conduct at least one tabletop cybersecurity exercise
  • Confirm client notification templates are prepared
  • Test escalation and communication workflows
  • Review vendor incident notification obligations

Key Risk: It is expected that the SEC will focus on firms that cannot demonstrate implementation and testing of their cybersecurity controls.

Artificial Intelligence (AI) Governance

AI usage has expanded rapidly, creating new regulatory and operational risks.

The SEC expects firms to maintain controls over customer information regardless of the technology platform being utilized.

Primary AI Risks:

  • Employees entering confidential client data into public AI systems
  • Unapproved “shadow AI” usage
  • AI-generated inaccuracies
  • Improper use of AI-generated marketing content
  • Vendor AI data retention concerns

Recommended Controls:

  • Establish an AI Governance Policy
  • Maintain an approved AI tools inventory
  • Prohibit entry of customer information into public AI platforms
  • Require human review of AI-generated content
  • Conduct employee AI usage training
  • Include AI vendors in vendor due diligence reviews

Best Practice: Treat AI access and governance similarly to email, cloud storage, and cybersecurity controls.

Cybersecurity & Threat Management

Cyber threats targeting financial services firms continue increasing in sophistication.

Key Threats Firms Should Monitor:

  • AI-powered phishing attacks
  • Business email compromise (BEC)
  • Remote Access Tool (RAT) attacks
  • Ransomware
  • Vendor and supply chain breaches
  • Credential theft and MFA bypass attacks

Recommended Controls:

  • Multi-factor authentication (MFA)
  • Endpoint Detection & Response (EDR)
  • Device encryption
  • Patch management
  • Privileged access restrictions
  • Secure backup testing
  • Employee phishing simulations
  • Wire transfer verification procedures

Best Practice: Cybersecurity should be treated as an enterprise risk management issue, not solely an IT function.

Vendor Oversight & Third-Party Risk Management

The SEC continues to increase focus on vendor oversight. Firms should identify all vendors with access to:

  • Customer information
  • Network infrastructure
  • Email systems
  • Portfolio or trading systems
  • AI or cloud environments

Recommended Vendor Reviews:

  • SOC 2 reports
  • Cybersecurity questionnaires
  • Incident notification obligations
  • Data encryption standards
  • Subcontractor usage
  • Business continuity capabilities
  • Cyber insurance coverage

Best Practice: Require contractual notification obligations for suspected breaches within 72 hours.

SEC Examination Preparedness

Regulators are increasingly requesting evidence of implementation rather than simply reviewing policies.

Firms should be prepared to provide:

  • Evidence of employee training
  • Incident response testing results
  • Vendor due diligence documentation
  • Access review records
  • Cybersecurity governance documentation
  • Risk assessments
  • AI governance documentation
  • Annual review and testing results

Likely SEC Examination Questions:

  • How does the firm identify and classify cyber incidents?
  • How are vendors monitored?
  • How does the firm govern AI usage?
  • What testing has been performed?
  • How would the firm notify clients after a breach?
  • What evidence exists that management reviewed cybersecurity risks?

Employee Training

Many cybersecurity incidents continue to originate from employee actions.

Training should include:

  • Phishing awareness
  • Password and MFA security
  • AI usage restrictions
  • Remote work security
  • Escalation procedures
  • Social engineering risks
  • Data handling procedures

Best Practice: Conduct periodic phishing simulations and maintain evidence of employee participation.

Governance & Documentation

One of the most important themes for 2026 is documentation.

If an action is not documented, regulators may assume it did not occur.

Firms should maintain documentation related to:

  • Testing activities
  • Vendor reviews
  • Employee training
  • Risk assessments
  • Incident response exercises
  • AI governance reviews
  • Cybersecurity committee or management discussions

Best Practice: Maintain centralized cybersecurity and compliance evidence repositories.

Final Takeaways

For the remainder of 2026, investment advisers should focus on five core themes:

  1. Implementation and Awareness
  2. Cybersecurity Governance
  3. AI Oversight and Controls
  4. Vendor Risk Management
  5. Testing and Documentation

The firms best positioned for SEC examinations will be those able to demonstrate that cybersecurity, AI governance, and operational controls are active, tested, and supported by management oversight.

Regulation S-P should now be viewed as a broader operational and cybersecurity framework rather than solely a privacy rule.

Broker Dealer Compliance Program and FINRA Compliance Review

Strengthening Your Broker-Dealer Compliance Program with Support from RRS

Broker-dealers operate in one of the most highly regulated areas of the financial services industry. Regulatory oversight from the SEC, FINRA, and other self-regulatory organizations requires firms to maintain strong compliance controls and supervisory systems. As a result, firms must implement a comprehensive broker dealer compliance program that addresses supervisory responsibilities, internal controls, regulatory reporting, and periodic compliance testing.

Continue reading

Investment adviser compliance program review and regulatory testing

How RRS Helps Firms Build an Investment Adviser Compliance Program

Investment advisers operate in a complex regulatory environment where maintaining a strong investment adviser compliance program is essential. The Securities and Exchange Commission (SEC) requires advisers to establish and maintain formal compliance systems designed to prevent regulatory violations and protect investors.

Continue reading