Technology governance

Is My Vendor a Regulation S-P Service Provider? The Test Is Whether Client Information Flows

How do I tell which of my firm's vendors are Regulation S-P service providers, and what do I owe each one?

Under Regulation S-P, a service provider is any entity that "receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution" (17 CFR 248.30(d)(10)). The test is whether records about clients flow to the vendor or are accessible by it, not what the vendor is called, how big it is, or whether it uses AI. Since June 3, 2026, every SEC-registered adviser owes each service provider due diligence, monitoring, and written policies reasonably designed to secure a 72-hour breach notification, and the firm keeps the duty to notify clients itself.

Key facts

  • A service provider under Regulation S-P is "any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution" (17 CFR 248.30(d)(10)).
  • Customer information is any record containing nonpublic personal information about a customer of a financial institution that is in the firm's possession or handled on its behalf (248.30(d)(5)).
  • An SEC-registered adviser's incident response program must include written policies "reasonably designed to require oversight, including through due diligence and monitoring, of service providers" (248.30(a)(5)(i)), reasonably designed to ensure a provider notifies the firm "as soon as possible, but no later than 72 hours" after becoming aware of a breach of a customer information system it maintains (248.30(a)(5)(i)(B)).
  • The firm may contract for a provider to notify affected individuals on its behalf (248.30(a)(5)(ii)), but the obligation to ensure they are notified "rests with the covered institution" (248.30(a)(5)(iii)).
  • The written oversight policies and any agreement under 248.30(a)(5) are required records (Rule 204-2(a)(25)(iv) and (v)).

The Regulation S-P definition of a service provider turns on customer information, not on the vendor

Regulation S-P does not define service providers by industry, size, contract type, or technology. It defines them by what they touch: any entity that "receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution" (17 CFR 248.30(d)(10)). Two words in that sentence do the work. "Customer information" is any record containing nonpublic personal information about a customer of a financial institution that the firm possesses or that is handled or maintained on its behalf (248.30(d)(5)(i)), and it includes information about other institutions' customers that has been provided to the firm. "Permitted access" means a vendor that could reach client records is covered even if it never does. So the question for every vendor is the same: do records about clients flow to it, or can it get at them? If yes, it is a service provider. If the only thing it ever sees is information about the firm or the advisor, it is not.

A typical advisory firm's vendor list sorts into more service providers than expected, and fewer than feared

Applying the Regulation S-P service-provider test to a small firm's stack produces a list that is longer than most firms expect and shorter than the panic version. The custodian portal, the CRM, the financial planning software, the document storage, the email and calendar system, the meeting notetaker, an AI assistant that reads client files, the e-signature service, the client portal, the reporting engine, and an outsourced compliance consultant's platform all receive or can reach client records; each is a service provider. A website analytics tool that records page views, a scheduling link that holds only the advisor's calendar, a project tracker used for internal work, and a payroll system that holds employee rather than client data are not, on the rule's definition, however much data they hold about the firm. The service-provider inventory applies this sorting to a firm's own list, one vendor at a time, and prints the result.

AI vendors are sorted by the same test, and "we do not store your data" is not the answer

An AI assistant, notetaker, or drafting tool is a Regulation S-P service provider if client information reaches it, and for most advisory uses it does: a notetaker receives the audio of a client meeting, a drafting assistant is given the client's situation, a research tool is asked about a named household. A vendor's statement that it does not store, retain, or train on the firm's data addresses what the vendor does with customer information, not whether it receives it. Receiving is enough for the definition in 17 CFR 248.30(d)(10). The distinction matters because it decides whether the firm owes the vendor diligence and monitoring at all, and it explains why If Your AI Vendor Is Breached, You Have Thirty Days to Tell Your Clients reviewed vendor documents for a notification clause: for a service provider, the firm's policies must be reasonably designed to secure one.

An SEC-registered adviser owes each service provider due diligence, monitoring, and a 72-hour notification policy

Under 17 CFR 248.30(a)(5), an SEC-registered adviser owes each service provider three things. First, written policies reasonably designed to require oversight "including through due diligence and monitoring," which in practice means asking the vendor what it does with customer information, recording the answer, and asking again on a schedule. Second, policies reasonably designed to ensure the vendor takes appropriate measures to protect customer information and notifies the firm "as soon as possible, but no later than 72 hours" after becoming aware of a breach of a customer information system it maintains. Third, on receipt of such a notice, the firm must initiate its own incident response program. The rule does not require a contract clause; it requires policies, diligence, and monitoring, and a written clause is simply the easiest evidence that the diligence happened. The nine questions are the diligence in letter form, and the vendor diligence letter prints them addressed to a named vendor.

The firm keeps the duty to notify clients even when a service provider agrees to send the notice

Regulation S-P lets a firm enter a written agreement with a service provider to notify affected individuals on the firm's behalf (17 CFR 248.30(a)(5)(ii)). It does not let the firm transfer the responsibility: "the obligation to ensure that affected individuals are notified ... rests with the covered institution" (248.30(a)(5)(iii)). The firm's own notice is due "as soon as practicable, but not later than 30 days" after it becomes aware that unauthorized access has occurred or is reasonably likely to have occurred (248.30(a)(4)(iii)). The practical consequence is that the vendor's 72 hours and the firm's 30 days are one timeline: the sooner the vendor tells the firm, the more of the 30 days the firm has to investigate, decide whether notice is required, and send it. Regulation S-P Now Applies to Every SEC-Registered Adviser walks the 30-day clock and the notice contents paragraph by paragraph.

A vendor that is not a service provider still belongs in the inventory, for a different reason

A tool that never receives customer information is outside Regulation S-P's service-provider provisions in 17 CFR 248.30(a)(5), and the inventory should say so with the basis recorded: the vendor's name, what it holds, why that is not customer information, and the date the firm reached that conclusion. That does not make the vendor irrelevant. The firm's safeguards policy under 248.30(a)(1) still covers every system it uses, and the Dropbox incident showed that an account with no client files in it can still be the way in. Classification also drifts. An email tool adds a summarizer that reads the inbox, a scheduling link starts collecting client intake answers, a project tracker gets used for a client onboarding checklist, and a vendor that was outside the definition last year is inside it now without telling anyone. A "not a service provider" entry therefore needs a review date like every other row, and the review question is the same one asked at intake: does client information flow to it now?

What should a small SEC-registered adviser do this week?

A small SEC-registered adviser can build the Regulation S-P service-provider inventory in a few hours. First, list every vendor the firm pays or logs into: export the vendor list from accounts payable and the entries from the firm's password manager, because the second list catches the free tools the first one misses. Second, sort each vendor with the one question in 17 CFR 248.30(d)(10): does it receive, hold, process, or have permitted access to records about clients? The service-provider inventory walks the list one vendor at a time and prints the sorted result. Third, for each service provider, find the breach-notification commitment in the vendor's own documents, usually the data processing agreement or terms of service rather than the privacy policy, and note the document, the section, and the deadline it states. Where the firm cannot find one, send the vendor diligence letter and file the reply. Fourth, date every answer and set a review date, twelve months out or sooner if the vendor changes its product. Fifth, put the inventory and the dated answers with the firm's written oversight policies under 248.30(a)(5)(i), because that is the record Rule 204-2(a)(25)(iv) asks for.

What should the service-provider file contain when an examiner asks?

For the compliance officer at an SEC-registered adviser, the Regulation S-P service-provider record has four parts. The first is the inventory itself, dated, with each vendor's classification and the basis for it. The second is the written oversight policies required by 17 CFR 248.30(a)(5)(i), which Rule 204-2(a)(25)(iv) makes a required record. The third is each service provider's written notification commitment and the document it lives in, filed with the contract, which Rule 204-2(a)(25)(v) makes a required record where it forms an agreement under 248.30(a)(5). The fourth is the date each answer was obtained, so that monitoring has something to monitor and the next review has a baseline. A firm that can produce those four things has done what the rule asks of it on service providers. A firm that has the vendors but not the list has not. The vendor side of the file is the subject of the Technology governance articles as a set, and the incident side, the program that runs once a vendor's 72-hour notice arrives, is in Regulation S-P Now Applies to Every SEC-Registered Adviser.

Questions

Is every vendor a Regulation S-P service provider?

No. Only an entity that receives, maintains, processes, or is permitted access to customer information through services to the firm (17 CFR 248.30(d)(10)). A vendor that only sees information about the firm or the advisor is not one.

Is a vendor that does not store our data still a service provider?

If client information reaches it, yes. The definition turns on receiving or being permitted access, not on retention. What the vendor does with the information afterward is a diligence question, not a classification question.

Do we need a contract clause with every service provider?

Regulation S-P requires written policies reasonably designed to ensure 72-hour notification, including through due diligence and monitoring. A clause is the simplest evidence of that diligence, but the rule does not mandate one.

Can we make the vendor responsible for notifying our clients?

The firm may agree in writing for a provider to send the notices on its behalf (248.30(a)(5)(ii)). The obligation to ensure clients are notified stays with the firm (248.30(a)(5)(iii)).

What about a state-registered adviser?

Regulation S-P covers SEC-registered advisers. A state-registered adviser generally oversees service providers under the FTC Safeguards Rule (16 CFR part 314), which requires contractual oversight without a fixed notification deadline; the inventory and the questions are still the right tools, and the citations differ. Confirm the firm's status with counsel.

Advisor Insights provides general professional information, not individualized investment, legal, or compliance advice. Whether a particular vendor is a service provider for a particular firm is a determination for the firm and its counsel. Regulatory descriptions are U.S. federal and current as of September 2026.

Primary sources

General information from ValaisOS LLC, not legal, compliance, tax, or investment advice. Confirm requirements for your firm with counsel. See Terms of Use.

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access