ValaisOS glossary

Fiduciary data custody

Fiduciary data custody is the principle that an advisory firm holds client information, decision reasoning, and supporting documents as entrusted property, received with a record of what arrived, held under the firm's own control, versioned so changes are attributable, and returned or produced intact on request. Under fiduciary data custody, the firm, not any software intermediary, is the accountable steward of what it knows about a client.

Why fiduciary data custody is a design property and not a policy

A firm can write a policy saying it protects client information. Whether it does depends on where the information lives, how many parties can reach it, and whether the firm can produce it and account for changes to it without asking a vendor. Fiduciary data custody names those properties so they can be designed for. It asks four questions of any system that touches client information: what did it receive and when, who else can access it, what changed and who changed it, and can the firm get all of it back. For a compliance officer, those are the questions behind Regulation S-P's safeguards and service-provider provisions and behind Rule 204-2's retrieval requirements. For a small firm, they are the questions a client would ask if they knew to.

What fiduciary data custody is not

Fiduciary data custody is not the custody of client assets under Rule 206(4)-2, which concerns funds and securities, not information. It is not "data ownership," a contractual term that says who owns data without saying who can reach it or whether it can be recovered. It is not data residency, which says where data is stored and nothing about who controls it. And it is not a claim that information never leaves the firm; it is the requirement that every movement be a decision the firm made and can show.

Where fiduciary data custody touches regulation

Regulation S-P (17 CFR 248.30(a)(1)) requires every SEC-registered adviser to maintain written policies with administrative, technical, and physical safeguards for customer information. Section 248.30(a)(5)(i) requires oversight of service providers, "including through due diligence and monitoring," and policies reasonably designed to ensure a provider notifies the adviser within 72 hours of becoming aware of a breach of a customer information system the provider maintains. Section 248.30(a)(5)(iii) keeps the duty to notify affected individuals with the adviser regardless of any service provider. Rule 204-2(g)(2) requires that electronic records be arranged for retrieval and produced promptly on request. Fiduciary data custody is a way of designing so those obligations are met by the structure of the system rather than by after-the-fact effort. It does not replace the firm's legal analysis of which information is customer information or which records are required. Regulatory descriptions are U.S. federal and current as of September 2026.

How the term is used on this site

The Trust Center describes the ValaisOS trust model as received with custody, reviewed in presence, and returned with clarity. Fiduciary data custody is the name for the first and third of those. The nine questions to send any AI vendor are the same four custody questions, asked of a vendor in writing.

Related terms

Articles that use this term

Questions

Is fiduciary data custody the same as the custody rule for client assets?

No. Rule 206(4)-2, the custody rule, concerns client funds and securities. Fiduciary data custody concerns client information and the firm's accountability for where it lives, who can reach it, what changed, and whether it can be produced.

Does fiduciary data custody mean client information never leaves the firm?

No. It means every movement of client information is a decision the firm made and can show, and that the firm can get all of it back. Where information may go is the firm's policy choice.

How does fiduciary data custody relate to Regulation S-P?

Regulation S-P requires written safeguards for customer information and oversight of the service providers that access it, and it keeps the duty to notify affected individuals with the firm. Fiduciary data custody is a way of designing systems so those obligations are met by structure rather than by after-the-fact effort.

Primary sources

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access