Why fiduciary data custody is a design property and not a policy
A firm can write a policy saying it protects client information. Whether it does depends on where the information lives, how many parties can reach it, and whether the firm can produce it and account for changes to it without asking a vendor. Fiduciary data custody names those properties so they can be designed for. It asks four questions of any system that touches client information: what did it receive and when, who else can access it, what changed and who changed it, and can the firm get all of it back. For a compliance officer, those are the questions behind Regulation S-P's safeguards and service-provider provisions and behind Rule 204-2's retrieval requirements. For a small firm, they are the questions a client would ask if they knew to.
What fiduciary data custody is not
Fiduciary data custody is not the custody of client assets under Rule 206(4)-2, which concerns funds and securities, not information. It is not "data ownership," a contractual term that says who owns data without saying who can reach it or whether it can be recovered. It is not data residency, which says where data is stored and nothing about who controls it. And it is not a claim that information never leaves the firm; it is the requirement that every movement be a decision the firm made and can show.
Where fiduciary data custody touches regulation
Regulation S-P (17 CFR 248.30(a)(1)) requires every SEC-registered adviser to maintain written policies with administrative, technical, and physical safeguards for customer information. Section 248.30(a)(5)(i) requires oversight of service providers, "including through due diligence and monitoring," and policies reasonably designed to ensure a provider notifies the adviser within 72 hours of becoming aware of a breach of a customer information system the provider maintains. Section 248.30(a)(5)(iii) keeps the duty to notify affected individuals with the adviser regardless of any service provider. Rule 204-2(g)(2) requires that electronic records be arranged for retrieval and produced promptly on request. Fiduciary data custody is a way of designing so those obligations are met by the structure of the system rather than by after-the-fact effort. It does not replace the firm's legal analysis of which information is customer information or which records are required. Regulatory descriptions are U.S. federal and current as of September 2026.
How the term is used on this site
The Trust Center describes the ValaisOS trust model as received with custody, reviewed in presence, and returned with clarity. Fiduciary data custody is the name for the first and third of those. The nine questions to send any AI vendor are the same four custody questions, asked of a vendor in writing.
Related terms
Articles that use this term
- The Vendors Behind Your Vendor: What Nineteen Subprocessor Lists Do Not Name
- Is My Vendor a Regulation S-P Service Provider? The Test Is Whether Client Information Flows
- Regulation S-P Now Applies to Every SEC-Registered Adviser. Here Is What Changed for a Small Firm.
- A Surprise Tax Bill Is a Data Problem Wearing a Tax Costume
- Nine Questions to Send Any AI Vendor Before You Sign
- If Your AI Vendor Is Breached, You Have Thirty Days to Tell Your Clients
- When a Client Arrives With a Headline
- The $140,000 Nobody Was Looking At
- Your Firm Has More Client Information Than Client Context
Questions
Is fiduciary data custody the same as the custody rule for client assets?
No. Rule 206(4)-2, the custody rule, concerns client funds and securities. Fiduciary data custody concerns client information and the firm's accountability for where it lives, who can reach it, what changed, and whether it can be produced.
Does fiduciary data custody mean client information never leaves the firm?
No. It means every movement of client information is a decision the firm made and can show, and that the firm can get all of it back. Where information may go is the firm's policy choice.
How does fiduciary data custody relate to Regulation S-P?
Regulation S-P requires written safeguards for customer information and oversight of the service providers that access it, and it keeps the duty to notify affected individuals with the firm. Fiduciary data custody is a way of designing systems so those obligations are met by structure rather than by after-the-fact effort.