Key facts
- A service provider under Regulation S-P is "any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution" (17 CFR 248.30(d)(10)).
- The firm's incident response program must include written policies "reasonably designed to require oversight, including through due diligence and monitoring, of service providers" (248.30(a)(5)(i)).
- Those policies must be reasonably designed to ensure service providers notify the firm "as soon as possible, but no later than 72 hours" after becoming aware of a breach of a customer information system they maintain (248.30(a)(5)(i)(B)).
- The duty to ensure affected individuals are notified stays with the firm regardless of any service provider (248.30(a)(5)(iii)), and the firm's own notice is due no later than 30 days after becoming aware (248.30(a)(4)(iii)).
- Written service-provider oversight policies and any agreement made under 248.30(a)(5) are required records for an SEC-registered adviser (Rule 204-2(a)(25)(iv) and (v)).
List the systems that touch client information
Start with the obvious ones: custodian portals, CRM, planning software, document storage, email, the meeting notetaker, any AI assistant, the portfolio system, the e-signature tool, the outsourced compliance consultant's platform. Add one row per vendor. Nothing you enter leaves this page.
The inventory
How the classification works
A vendor that receives, holds, processes, or can reach client records is classified as a service provider under 17 CFR 248.30(d)(10), whatever it is called in the contract. A vendor that only sees information about the firm or the advisor is not one on the rule's definition, and the inventory says so. "Unsure" is treated as a service provider until the firm finds out, because the cost of the question is an email and the cost of being wrong is a 30-day clock the firm did not know had started. For each service provider the inventory lists the next action: obtain the written notification commitment if there is none, find and file the clause if there is one, and record the date so monitoring has something to monitor.
What to do with the printed inventory
- Keep it with the firm's written service-provider oversight policies; it is the list those policies apply to (248.30(a)(5)(i); Rule 204-2(a)(25)(iv)).
- For every service provider without a written commitment, send the vendor diligence letter and file the reply with the contract.
- Date the printout and set a review date. Regulation S-P's standard is diligence and monitoring, and a dated inventory that gets refreshed is what monitoring looks like on paper.
Questions
What makes a vendor a Regulation S-P service provider?
Receiving, maintaining, processing, or being permitted access to customer information through services provided directly to the firm (17 CFR 248.30(d)(10)). Customer information is any record containing nonpublic personal information about a customer of a financial institution that the firm holds or that is handled on its behalf (248.30(d)(5)).
Is a vendor that only holds advisor behavioral data a service provider?
Not on the rule's definition. Usage data about the advisor, such as clickstream or search history, is not customer information. The test is whether records about clients flow to or are accessible by the vendor.
Does the inventory create the written policies the rule requires?
No. Regulation S-P requires written policies reasonably designed to require oversight of service providers, including through due diligence and monitoring. The inventory is the list those policies apply to, and a printed copy dated today is evidence that the firm knows who its service providers are.
Does this page store the vendors I enter?
No. The inventory is built and scored in your browser and shown on the page. Print it if you want to keep it. Nothing is transmitted, saved, or measured.
Primary sources
General information from ValaisOS LLC, not legal, compliance, tax, or investment advice. Confirm requirements for your firm with counsel. See Terms of Use.