Compliance · Regulation S-P
What does SEC Regulation S-P require for service provider oversight?
Amended Regulation S-P requires broker-dealers, investment companies, registered investment advisers and transfer agents to keep an incident response program, oversee their service providers through due diligence and monitoring, and notify affected customers within 30 days of a breach. Service providers must tell the firm within 72 hours of becoming aware of a breach.
Who it covers
Broker-dealers, including funding portals, investment companies, registered investment advisers and transfer agents. The SEC adopted the amendments in May 2024.
Larger entities had to comply by December 3, 2025, and smaller entities by June 3, 2026, so the amendments now apply to every covered firm.
What it requires
- An incident response program, in written policies and procedures, to detect, respond to and recover from unauthorized access to or use of customer information.
- Customer notice within 30 days of becoming aware that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization.
- Oversight of service providers with access to customer information, through due diligence and monitoring.
- 72-hour notice from providers. A service provider must tell the firm as soon as possible, and no later than 72 hours after becoming aware of a breach.
How an MSP evidences it with Outerwall
- A supplier inventory. The service providers your client depends on, found from public sources and confirmed by your client, with where each was found.
- Supplier monitoring. Breach notices that name one of your client’s suppliers are flagged within hours, so you don’t depend on the provider’s own notice.
- External exposure evidence. Dated findings on the internet-facing assets your client approved, for its incident response program.
- Evidence packs mapped to the rule are on the roadmap.
Not legal advice. This page summarizes the rule for MSPs. Your client’s counsel or compliance lead decides what it requires of them. Outerwall’s output supports a client’s compliance evidence. It does not, by itself, make a client compliant.
Sources
Know when a supplier is breached.
Design partners get supplier alerts across every client they manage, from the first partner release.