Skip to main content

SEC Proposed Custody Rule Amendments: Modernizing Custody for an Evolving Financial Landscape

Business professionals point at chart on board.

Safeguarding client assets is a fundamental investor protection within the regulatory framework governing investment advisers. At the same time, regulations must provide both meaningful investor protection and operational practicality. As technology, asset classes, and the infrastructure supporting financial markets continue to evolve, the regulatory framework must evolve with them.

That theme is at the center of the Securities and Exchange Commission’s October 1, 2026 proposal to amend the custody rules applicable to registered investment advisers and regulated funds.

In his statement regarding the proposal, SEC Commissioner Mark T. Uyeda highlighted the need to revisit the custody framework as new asset classes emerge and technology continues to develop. While the core principles of custody—including asset separation and appropriate controls—remain important, the way those principles are applied may look different as technology changes.

Safeguarding a paper certificate held in a bank vault and safeguarding an asset recorded on a distributed ledger may require very different processes and controls, even though the underlying objective is the same: protecting client assets.

Modernizing Compliance Alongside Technology

The proposal provides an important reminder that modernization is not simply about adopting new technology. It is also about ensuring that compliance frameworks remain relevant as financial services change.

Investment advisers are increasingly evaluating artificial intelligence tools, automated workflows, cloud-based platforms, and other third-party technology solutions to make day-to-day operations more efficient. These technologies create opportunities, but they also bring additional compliance considerations.

As more information moves through technology platforms and third-party providers, firms must consider how confidential and sensitive information is collected, accessed, transmitted, stored, and protected. Privacy, cybersecurity, data governance, vendor oversight, and access controls therefore remain important components of a modern compliance program.

While the proposed custody amendments do not specifically address artificial intelligence, the broader modernization principles reflected in the proposal are relevant as firms evaluate how emerging technologies fit within their existing compliance and risk-management frameworks.

Crypto Assets and Self-Custody

The proposal also addresses one of the areas where traditional custody concepts have faced some of their biggest challenges: crypto assets.

The SEC proposes a framework for the custody of certain crypto assets, including permitting certain state-chartered trust companies to serve as custodians, subject to specified conditions.

The proposal also recognizes that, for certain “novel crypto assets”, a qualified custodian may not be available or willing to hold the assets. In those circumstances, the proposal would permit self-custody in certain situations, subject to safeguards involving areas such as safeguarding expertise, cybersecurity, annual reviews, internal reporting, account statements, and client disclosures.

Self-custody creates an additional compliance consideration because an adviser holding client crypto assets may face a different conflict-of-interest analysis than it would when assets are held by an independent custodian. Importantly, an adviser’s fiduciary obligations continue to apply when it holds client crypto assets.

For firms considering digital assets, this could require careful consideration of policies and procedures, cybersecurity controls, supervision, disclosures, documentation, and conflicts of interest.

Other Areas of Modernization

Beyond crypto custody, the proposal also raises questions about how other aspects of the custody framework may evolve, including the role of broker-dealers as custodians, certain authorized discretionary trading arrangements, and independent verification requirements.

While these provisions are more technical, they reflect the same broader issue: the way advisers operate today is not necessarily the way they operated when the existing custody framework was developed.

The goal should not be to move away from strong controls or investor protections. Rather, those protections need to remain effective as technology, business practices, and the financial markets change.

For compliance professionals, this raises an important question: how do we preserve the protections that have always mattered while ensuring that the regulatory framework remains practical and relevant to the way the industry operates today?

What This Could Mean for Compliance Programs

As firms adopt AI tools, work with additional third-party providers, and consider digital assets and other emerging technologies, compliance programs may need to evolve alongside those developments.

That may mean revisiting areas such as:

  • Third-party due diligence and oversight;
  • Data privacy and information security;
  • Cybersecurity and incident response;
  • Policies governing AI and other emerging technologies;
  • Custody and asset-safeguarding procedures;
  • Conflict-of-interest assessments;
  • Supervisory procedures; and
  • Client disclosures and recordkeeping.

The objective is not simply to accommodate new technology or asset classes. It is to ensure that the appropriate controls and protections continue to work as the underlying technology and business processes change.

Looking Ahead

The SEC’s proposal is not yet a final rule, and the public comment period will remain open for 60 days following publication of the proposing release in the Federal Register.

As the rulemaking process moves forward, advisers, funds, custodians, and compliance professionals will have an opportunity to evaluate how the proposed changes could affect their existing custody arrangements and compliance programs.

Commissioner Uyeda summarized the proposal’s objective by stating:

“Today’s proposal presents a workable path to compliance without compromising the protections the custody rules are designed to provide.”

That balance between investor protection and operational practicality is one of the most important themes of the proposal.

As the financial services industry continues to incorporate digital assets, artificial intelligence, distributed ledger technology, and an expanding network of technology and service providers, the compliance framework supporting those activities will need to evolve as well.

As technology changes, effective compliance must change with it.

Source

SEC.gov | Statement on Proposed Amendments to the Custody Rules (October 1, 2026).

Note: The proposed Custody Rule Amendment reflects SEC staff views, has no legal force or effect, and does not create new obligations.

Top Five AML Testing Failures – The Penny Stock Edition

Business professionals engaging in meeting.

Findings related to penny stocks—more commonly referred to as low‑priced securities—are not new. Regulators have consistently highlighted the elevated risk these securities present, particularly in the context of market manipulation and money laundering. However, recent enforcement activity suggests that these issues are not only persisting, but may be increasing in frequency and severity, particularly where firms’ AML programs are not adequately aligned with the underlying risk.

For purposes of regulatory analysis, a “penny stock” generally refers to equity securities trading at low prices, typically over‑the‑counter and often lacking robust public disclosure. These securities are also commonly referred to as low‑priced securities, microcap securities, OTC securities, or thinly traded securities. Regardless of terminology, they share common characteristics—limited liquidity, price volatility, and reduced transparency—that make them particularly susceptible to manipulative or illicit activity. Against that backdrop, recent AML testing and enforcement observations reveal several recurring failure points.

1. Surveillance That Doesn’t Capture the Risk

A consistent issue is the presence of surveillance systems that technically exist, but are not designed to capture the firm’s actual risk exposure.

In many cases, firms relied on reports or exception monitoring that:

  • Excluded key account types (e.g., omnibus, DVP/RVP, or certain institutional accounts)
  • Filtered out lower‑value or segmented transactions
  • Failed to aggregate activity across accounts or time periods

The result is a control environment where the highest‑risk activity is effectively outside the scope of monitoring. From a testing perspective, this is not a gap in execution—it is a design failure. Surveillance that cannot identify relevant activity cannot be considered “reasonably designed” under Rule 3310.

2. Lack of Risk Alignment with the Firm’s Business Model

Another recurring theme is the failure to tailor AML programs to the firm’s specific business activities involving low‑priced securities.

This commonly arises where firms:

  • Facilitate trading through correspondent, omnibus, or foreign financial institution accounts
  • Operate in execution‑only environments with limited insight into underlying customers
  • Engage in high‑velocity or high‑volume trading in thinly traded securities

Despite these risk factors, AML programs often remain generic and do not reflect the firm’s actual operational exposure.

From a testing perspective, the key question is not whether a firm has an AML program—it is whether the program reflects the actual risks presented by the firm’s activities. Where low‑priced securities are a meaningful part of the business, regulators expect enhanced, targeted controls.

3. Red Flags Identified—But Not Operationalized

Many firms appropriately identify red flags associated with low‑priced securities in their written procedures. However, a common failure is the absence of operational guidance around those red flags.

Specifically:

  • Red flags are listed, but not linked to specific surveillance scenarios
  • There is no defined process for how alerts are generated or identified
  • Escalation thresholds and investigative expectations are unclear or undefined

In practice, this creates a disconnect between policy and execution. Staff may recognize that certain activity is risky in theory, but lack the tools or direction to detect and act on that risk.

Effective AML programs require that red flags are not only documented—but translated into actionable surveillance, investigation, and escalation procedures.

4. Failure to Investigate and Escalate Suspicious Activity

Even where potentially suspicious activity is identified, firms frequently fail to conduct reasonable investigations or escalate concerns appropriately.

Testing observations often include:

  • Acceptance of customer explanations without independent verification
  • Lack of documented investigative steps or conclusions
  • Failure to consider whether activity warrants SAR filing

This issue is particularly pronounced in low‑priced securities activity involving:

  • Significant liquidations relative to market volume
  • One‑sided trading patterns (e.g., repeated sell orders with no corresponding buys)
  • Rapid movement of proceeds following transactions

From a regulatory perspective, detecting activity is only the first step. Firms must demonstrate a structured, documented, and defensible investigative process, including clear rationale for escalation or non‑escalation decisions.

4. Failure to Investigate and Escalate Suspicious Activity

Even where potentially suspicious activity is identified, firms frequently fail to conduct reasonable investigations or escalate concerns appropriately.

Testing observations often include:

  • Acceptance of customer explanations without independent verification
  • Lack of documented investigative steps or conclusions
  • Failure to consider whether activity warrants SAR filing

This issue is particularly pronounced in low‑priced securities activity involving:

  • Significant liquidations relative to market volume
  • One‑sided trading patterns (e.g., repeated sell orders with no corresponding buys)
  • Rapid movement of proceeds following transactions

From a regulatory perspective, detecting activity is only the first step. Firms must demonstrate a structured, documented, and defensible investigative process, including clear rationale for escalation or non‑escalation decisions.

The common thread across these findings is not the absence of AML programs—but the absence of operational, risk‑aligned controls that reflect the realities of low‑priced securities trading.

For firms that engage in or facilitate this activity, the regulatory expectation is clear: AML programs must move beyond generic frameworks and demonstrate a practical, working ability to detect, investigate, and escalate suspicious activity in higher‑risk areas of the business.

Firms that proactively address these gaps through targeted AML program testing, surveillance design reviews, and risk‑based control enhancements are better positioned to identify vulnerabilities before regulators do.

Renaissance Regulatory Services works with broker-dealers and other financial institutions to operationalize these expectations—supporting firms through independent AML testing, control framework assessments, and tailored remediation strategies designed to align programs with real-world regulatory scrutiny.

IA Annual Compliance Reviews – SEC Risk Alert

Business professionals review charts.

Is Your Annual Compliance Review Exam-Ready?

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Overview

The SEC’s Division of Examinations issued a Risk Alert on September 14, 2026, reminding advisers that the annual compliance review required by Advisers Act Rule 206(4)-7 must meaningfully assess both the adequacy of the firm’s policies and procedures and the effectiveness of their implementation. Examiners are focused on whether firms complete reviews timely, test current practices, preserve supporting documentation, identify deficiencies, and complete corrective actions.

While every SEC-registered adviser knows an annual review is required, the SEC’s message is clear: simply checking the box is not enough.

Where Examiners Found Weaknesses

• Timeliness of annual reviews

• Completeness of review procedures

• Alignment between policies and actual business practices

• Documentation and supporting records

• Follow-through on corrective actions

Perhaps the most significant takeaway is that the SEC expects firms to evaluate whether compliance programs actually work in practice. Policies that appear adequate on paper but do not reflect current operations, regulatory requirements, or business activities create examination risk.

Documentation Is Part of the Deliverable

The Risk Alert highlights a common weakness: firms may perform review activities but fail to preserve the supporting workpapers, testing records, findings, and recommendations needed to demonstrate the scope and quality of the review. Advisers should be prepared to show not only the final report, but also the evidence supporting their conclusions.

Findings Must Lead to Remediation

A finding is not resolved simply because it appears in an annual review report. Firms should assign responsibility, establish target dates, retain evidence of corrective action, and independently validate that the underlying condition has been corrected. Prior-year findings should be revisited to confirm that remediation remains effective.

Steps Advisers Should Consider

• Confirm that the review is completed no less frequently than annually.

• Ensure written procedures explain how testing and validation will be performed.

• Test current business practices against current policies and procedures.

• Maintain detailed workpapers and a centralized annual review file.

• Track regulatory, operational, personnel, and affiliate changes throughout the year.

• Use a corrective-action log and verify closure of prior findings.

• Evaluate whether significant events warrant an interim review.

Bottom line: An effective annual review should be timely, tailored to the adviser’s actual business, supported by evidence, and followed by verified corrective action.

Conclusion

As SEC examination activity continues, advisers should assess whether their annual review process would withstand examiner scrutiny today. A well-designed program should demonstrate what was reviewed, how it was tested, what issues were found, who was responsible for remediation, and how the firm confirmed that corrective action was effective.

Source

SEC Division of Examinations, Examinations Observations Regarding Investment Adviser Annual Compliance Review (Sept. 14, 2026).

Note: The Risk Alert reflects SEC staff views, has no legal force or effect, and does not create new obligations.

Financial Crimes – Common Scams and Ways to Fight Back

Business professional types on phone.

Pause, Think, Verify: Helping Clients Avoid Today’s Most Common Scams

Criminals are becoming increasingly sophisticated in their efforts to defraud investors. From impersonating government agencies and financial institutions to leveraging artificial intelligence to mimic voices, emails, and text messages, today’s scams are designed to create urgency, exploit vulnerabilities, and pressure individuals into making quick decisions.

While investor education remains a critical component of fraud prevention, investment advisers and broker-dealers are uniquely positioned to identify red flags, implement preventive measures, and help clients protect their assets before a scam succeeds.

Understanding Today’s Scam Environment

Scammers continually adapt their tactics to take advantage of current events, emerging technologies, and consumers’ trust in familiar institutions. While the methods vary, most scams are designed to create confusion, exploit emotions, and pressure victims into taking immediate action. By creating panic, scammers attempt to prevent victims from stopping to verify the legitimacy of the request. Understanding the most common scam types can help firms educate clients and recognize potential red flags.

Imposter Scams

Imposter scams occur when criminals pose as trusted organizations or individuals, such as government agencies, law enforcement officials, banks, credit card companies, or even family members. Fraudsters often use spoofed phone numbers, realistic emails, or text messages that appear legitimate. Their objective is typically to obtain sensitive personal information, gain access to financial accounts, or persuade victims to send money under false pretenses.

Investment and Affinity Scams

Investment scams frequently promise high returns with little or no risk, often involving products that are difficult to verify or understand. Fraudsters may use social media, online forums, or personal relationships to gain credibility before soliciting funds. Affinity scams are particularly effective because they target members of specific groups, communities, or organizations, leveraging existing trust to encourage participation.

Romance and Social Engineering Scams

Romance scams involve building an online relationship with a victim over weeks or months before requesting money for a fabricated emergency or investment opportunity. More broadly, social engineering scams manipulate victims through trust, fear, sympathy, or urgency. Rather than exploiting technological vulnerabilities, these scams exploit human behavior, making them especially difficult to detect.

Tech Support and Account Security Scams

In these schemes, individuals receive unsolicited calls, emails, or pop-up messages claiming that a computer, bank account, or financial account has been compromised. Victims are urged to provide login credentials, grant remote access to their devices, or transfer funds to supposedly “secure” accounts. In reality, the scammers are seeking direct access to the victim’s assets and information.

Payment and Cryptocurrency Scams

Many fraudsters instruct victims to use unusual payment methods such as gift cards, wire transfers, peer-to-peer payment applications, or cryptocurrency. These payment methods are difficult to reverse and can make recovery of lost funds nearly impossible. Requests for payment through non-traditional channels are often a significant warning sign that a scam may be underway.

What Advisory Firms and Broker-Dealers Can Do

Although firms cannot prevent every attempted fraud, there are several measures that can significantly reduce the risk of client harm.

Obtain Trusted Contact Information

One of the most effective tools available is obtaining a trusted contact person for client accounts. A trusted contact can serve as an important resource when there are concerns about possible financial exploitation, diminished capacity, or unusual account activity.

For broker-dealers, FINRA Rule 4512 requires firms to make reasonable efforts to obtain trusted contact information for retail customer accounts. Investment advisers are also increasingly adopting this practice as part of their overall client protection framework.

By proactively collecting and periodically updating trusted contact information, firms strengthen their ability to respond when suspicious situations arise.

Train Employees to Recognize Red Flags

Front-line personnel are often the first line of defense against fraud. Firms should provide ongoing training to help employees identify warning signs such as:

  1. sudden requests for large or unusual disbursements;
  2. wire transfers to unfamiliar third parties;
  3. increased client anxiety or references to secretive situations;
  4. requests involving cryptocurrency, gift cards, or other atypical payment methods;
  5. clients acting under apparent pressure from an outside party; and
  6. multiple failed attempts to verify account information or instructions.

An employee who recognizes these indicators may be able to intervene before fraudulent transactions occur.

Strengthening Verification Procedures

Verification procedures should be robust enough to address today’s evolving fraud tactics. Firms should consider implementing procedures that require additional verification for high-risk transactions, requests involving changes to account information, or instructions that deviate from established client behavior.

Encouraging clients to independently verify unsolicited requests through known telephone numbers or established communication channels can also help prevent successful impersonation attempts.

Educating Clients Regularly

Client awareness remains one of the strongest defenses against fraud. Regular communications, newsletters, seminars, and website resources can help clients understand current scam trends and recognize warning signs. Simple reminders can be highly effective:

  • pause before acting on urgent requests;
  • verify the identity of anyone requesting money or personal information;
  • be skeptical of unexpected communications; or
  • never assume an email, text message, or phone call is legitimate simply because it appears to come from a trusted source.

Conclusion

As fraud schemes continue to evolve, financial professionals must remain vigilant. A proactive approach that combines employee training, client education, trusted contact information, and strong supervisory controls can significantly reduce the likelihood that clients become victims of financial exploitation.

The most important message firms can share with clients is also the simplest: when faced with an urgent or unexpected request, pause, think, and verify before taking action. Those few moments of caution can make the difference between protecting a lifetime of savings and becoming the next victim of an increasingly sophisticated scam.

Contact RRS for more information.

Summertime is Here! Compliance Can Keep You Cool!

As the summer heat kicks in, while there is little indication that the regulatory “warming trend” will subside any time soon, the typical slowdown in business over the summer months provides opportunities to review your firm’s compliance program. Focusing on selected aspects of your compliance program may also reveal ways to cut costs associated with compliance in the long run. The secret to an efficient review is to focus on the regulatory target areas and not try to do too much.

The Regulatory Focus

The regulatory focus on the retail investor will continue. The SEC and FINRA have enhanced their practices to target the areas of the highest risk to the public. Novel new products such as digital assets, structured securities, and prediction markets are in focus. The updates to Regulation S-P brought renewed focus on firm’s due diligence practices for vendors that host systems and access or store customer data. Piling on all that is the increasing risk of cybercrime – both internal and external – and the increasing use of artificial intelligence tools. If that’s all buttoned up, then you don’t want to get caught off guard with “old school” compliance gaps such as inadequate policies and procedures, recordkeeping, or supervision. There are certainly a wide range of focus areas that can be addressed. Like many firms, the regulators are using AI to assist in their analysis, which provides the ability to cover a wider range of topics in exams.

Identifying the Areas to Review

With the above in mind, the review of your firm’s operations should focus on those areas most relevant to your business. First, assess your products and services from a financial perspective, identifying products and services that generate the most revenue. The compliance review should focus on those areas of your firm’s operations that generate the most business, i.e. revenue. Also, consider looking at the policies and procedures for supervising branch offices and remote locations. Additionally, if there is a product or service that you have not reviewed in some time, or that is new to your firm, the policies and procedures related to those areas should be included in your review. For example, if you’re selling more ETF’s or insurance securities, look at the supervisory and operational procedures for those products. If you recently added digital assets or prediction market access, look at the procedures governing those practices and the training programs in place for the public facing and supervisory personnel.

Second, consider any areas where you rely on third parties to provide a significant support function. The most common for broker-dealers is the clearing function, while RIAs may rely heavily on the custodian or a portfolio valuation service. Create a list of vendors that includes the services they provide, the contact people for the vendor, and the contract date. Larger firms should also add the person(s) internally who own the relationship, such as the financial officer for accounting software, the operations officer for clearing relationships, etc. Consider all services provided by third parties or affiliates (services provided by affiliates are typically considered outsourced) including surveillance and compliance management vendors. In addition to the clearing and custody relationships noted above, many firms use third party vendors to support internet access and email, storage of books and records, payroll processing, and accounting functions. Some other common areas that are often overlooked are the phone systems, technology support, law firms, and consultants.

Conducting the Review

For the areas you’ve selected to review, determine how the business is processed from start to finish. It may be helpful to create a flow diagram of the process that identifies “touch points” where a supervisory procedure or control would/should exist. A good example would be where the representative forwards completed paperwork for a variable annuity transaction to a principal for review. These points could include the representative assembling the paperwork, delivering it to a sales assistant, and the sales assistant forwarding it to the principal or a centralized operations department for review and approval. Your procedures should address a control or supervisory process for each time the paperwork changes hands. Perhaps the sales assistant does a check to ensure all the proper completed paperwork is included, and in the predetermined order, before forwarding to the principal. This simple control will reduce delays in processing paperwork and the time that the principal has to spend reviewing, and supervising, the transaction, thereby saving time and money. When reviewing processes, policies and procedures for new lines of business, be careful not to try to fit a square peg into a round hole. That is, don’t assume that the procedure for supervising an equity security transaction will fit the exchange traded note. You must consider the unique aspects of the product, related disclosures, and the customer’s objectives. This is a simple example and more complex operations require a more in-depth assessment even when processes are automated, we often find data breaks where two or more data feeds are required to complete a process. These need to be carefully mapped out.

If your firm relies on third party vendors and does not have a due diligence process for assessing them, develop one – you are late to the game. Start with the vendor contract to determine if the regulatory requirements are met. For example, Regulation S-P now formally requires notification of a breach within 72 hours. Also, if the vendor is deemed a “Service Bureau” for the purposes of the SEC’s Books and Records Rules, the vendor must agree to make the records available to the Regulators. Similarly consider any AML, business continuity, and privacy issues that may arise from the relationship. For FINRA members, these arrangements may also have to be disclosed before implementation. Depending on the nature of the vendor relationship, your due diligence process should include reviews of the vendor’s internal control reports, business continuity plans, information and technology security, and insurance coverage such as E&O, theft, and professional liability. Ongoing vendor monitoring is critical. While most services can be monitored on an ongoing basis – that is, if the service fails you know it and correct it with a backup plan – it’s a good practice to schedule a formal meeting at least annually with the vendors’ representatives to review the services and reassess the areas covered in the due diligence process.

Correction and Documentation

As you complete each review, create a short, written summary of the review and gap analysis performed, including the corrective steps to be taken, if any. For material deficiencies, consider reviewing with counsel to determine the potential regulatory impact. In addition to amending written policies and procedures, corrective actions should include training employees to ensure that proper procedures are implemented, and the new procedures are adequately communicated.

Conclusion

A compliance review provides a great opportunity to reassess your business operations, not only for compliance purposes, but to identify areas of efficiency and cost savings. This type of review can be incorporated into your annual review requirements and supervisory controls testing. Your review should be reasonable, and you should not try to do too much. Once you start digging, you may find that one issue will take longer than you anticipated completing. It’s better to do a portion at a time and complete a full review on an area than to take on too much and leave items undone.

So, what are your plans this summer? Awaiting the regulatory heat? Or sitting back and enjoying the compliance reliance?

By: Louis Dempsey, CRCP, CSCP


Regulation S-P: Next Steps for Investment Advisers

Business professionals looking at charts.

As the SEC’s amended Regulation S-P requirements become effective for all investment advisers, firms should now be focused on implementation of the requirements, including cybersecurity governance, vendor oversight, use of artificial intelligence (AI), and testing their ability to respond effectively to cyber incidents.

We outline key areas firms should prioritize over the balance of the year.

Implementation Readiness

The Regulation S-P requirements now place greater emphasis on incident response, customer notification, and protection of customer information.

Firms should ensure they have:

  • Written incident response procedures
  • Escalation and breach assessment protocols
  • Customer notification procedures
  • Vendor oversight programs
  • Information security controls
  • Documented employee training
  • Evidence of testing and governance

Recommended Action Items:

  • Conduct at least one tabletop cybersecurity exercise
  • Confirm client notification templates are prepared
  • Test escalation and communication workflows
  • Review vendor incident notification obligations

Key Risk: It is expected that the SEC will focus on firms that cannot demonstrate implementation and testing of their cybersecurity controls.

Artificial Intelligence (AI) Governance

AI usage has expanded rapidly, creating new regulatory and operational risks.

The SEC expects firms to maintain controls over customer information regardless of the technology platform being utilized.

Primary AI Risks:

  • Employees entering confidential client data into public AI systems
  • Unapproved “shadow AI” usage
  • AI-generated inaccuracies
  • Improper use of AI-generated marketing content
  • Vendor AI data retention concerns

Recommended Controls:

  • Establish an AI Governance Policy
  • Maintain an approved AI tools inventory
  • Prohibit entry of customer information into public AI platforms
  • Require human review of AI-generated content
  • Conduct employee AI usage training
  • Include AI vendors in vendor due diligence reviews

Best Practice: Treat AI access and governance similarly to email, cloud storage, and cybersecurity controls.

Cybersecurity & Threat Management

Cyber threats targeting financial services firms continue increasing in sophistication.

Key Threats Firms Should Monitor:

  • AI-powered phishing attacks
  • Business email compromise (BEC)
  • Remote Access Tool (RAT) attacks
  • Ransomware
  • Vendor and supply chain breaches
  • Credential theft and MFA bypass attacks

Recommended Controls:

  • Multi-factor authentication (MFA)
  • Endpoint Detection & Response (EDR)
  • Device encryption
  • Patch management
  • Privileged access restrictions
  • Secure backup testing
  • Employee phishing simulations
  • Wire transfer verification procedures

Best Practice: Cybersecurity should be treated as an enterprise risk management issue, not solely an IT function.

Vendor Oversight & Third-Party Risk Management

The SEC continues to increase focus on vendor oversight. Firms should identify all vendors with access to:

  • Customer information
  • Network infrastructure
  • Email systems
  • Portfolio or trading systems
  • AI or cloud environments

Recommended Vendor Reviews:

  • SOC 2 reports
  • Cybersecurity questionnaires
  • Incident notification obligations
  • Data encryption standards
  • Subcontractor usage
  • Business continuity capabilities
  • Cyber insurance coverage

Best Practice: Require contractual notification obligations for suspected breaches within 72 hours.

SEC Examination Preparedness

Regulators are increasingly requesting evidence of implementation rather than simply reviewing policies.

Firms should be prepared to provide:

  • Evidence of employee training
  • Incident response testing results
  • Vendor due diligence documentation
  • Access review records
  • Cybersecurity governance documentation
  • Risk assessments
  • AI governance documentation
  • Annual review and testing results

Likely SEC Examination Questions:

  • How does the firm identify and classify cyber incidents?
  • How are vendors monitored?
  • How does the firm govern AI usage?
  • What testing has been performed?
  • How would the firm notify clients after a breach?
  • What evidence exists that management reviewed cybersecurity risks?

Employee Training

Many cybersecurity incidents continue to originate from employee actions.

Training should include:

  • Phishing awareness
  • Password and MFA security
  • AI usage restrictions
  • Remote work security
  • Escalation procedures
  • Social engineering risks
  • Data handling procedures

Best Practice: Conduct periodic phishing simulations and maintain evidence of employee participation.

Governance & Documentation

One of the most important themes for 2026 is documentation.

If an action is not documented, regulators may assume it did not occur.

Firms should maintain documentation related to:

  • Testing activities
  • Vendor reviews
  • Employee training
  • Risk assessments
  • Incident response exercises
  • AI governance reviews
  • Cybersecurity committee or management discussions

Best Practice: Maintain centralized cybersecurity and compliance evidence repositories.

Final Takeaways

For the remainder of 2026, investment advisers should focus on five core themes:

  1. Implementation and Awareness
  2. Cybersecurity Governance
  3. AI Oversight and Controls
  4. Vendor Risk Management
  5. Testing and Documentation

The firms best positioned for SEC examinations will be those able to demonstrate that cybersecurity, AI governance, and operational controls are active, tested, and supported by management oversight.

Regulation S-P should now be viewed as a broader operational and cybersecurity framework rather than solely a privacy rule.

Strengthening Your Broker-Dealer Compliance Program with Support from RRS

Broker Dealer Compliance Program and FINRA Compliance Review

Broker-dealers operate in one of the most highly regulated areas of the financial services industry. Regulatory oversight from the SEC, FINRA, and other self-regulatory organizations requires firms to maintain strong compliance controls and supervisory systems. As a result, firms must implement a comprehensive broker dealer compliance program that addresses supervisory responsibilities, internal controls, regulatory reporting, and periodic compliance testing.

Continue reading

How RRS Helps Firms Build an Investment Adviser Compliance Program

Investment adviser compliance program review and regulatory testing

Investment advisers operate in a complex regulatory environment where maintaining a strong investment adviser compliance program is essential. The Securities and Exchange Commission (SEC) requires advisers to establish and maintain formal compliance systems designed to prevent regulatory violations and protect investors.

Continue reading