Reg S-P is live — the AI vendor file your examiner expects
Author
Audrey
NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.
Date Published
What happened
The amended Regulation S-P safeguards rule is now in force for the entire covered market. Larger entities had to comply by December 3, 2025; all smaller entities were on the hook as of June 3, 2026. Industry groups asked the SEC to push the smaller-firm date back — that extension request was denied — so if you are a registered investment adviser or broker-dealer of any size, the amended rule already applies to you.
The mechanics are in 17 CFR 248.30. Three pieces matter most for this post. First, you must maintain written policies and procedures requiring oversight — including through due diligence and monitoring — of your service providers, specifically so that customers get any required breach notice. Second, your contracts and program have to secure a 72-hour notification from a service provider to you after that provider becomes aware of a breach of a system holding your customer information. Third, you must notify affected customers as soon as practicable, and no later than 30 days after you become aware of unauthorized access. All of this sits inside a written incident-response program you are now expected to have on paper.
None of this is AI-specific. The rule never says the word. That is exactly why it matters.
Why it matters
Reg S-P is the rule that quietly converts "our vendors use AI now" from a technology curiosity into a documented compliance obligation. The amended safeguards rule doesn't care whether your service provider processes customer records with a mainframe, a spreadsheet macro, or a large language model. If a provider touches your customer information, it falls inside the service-provider oversight language — and that provider's AI subprocessors, model vendors, and data-retention behavior are now part of what you're expected to have looked at.
There's a second reason to take this seriously right now: the SEC's Division of Examinations named Reg S-P compliance a FY2026 examination priority. That means the amended rule isn't theoretical for the exam cycle you're in. An examiner who opens your service-provider file is entitled to see written policies, evidence of due diligence, and evidence of ongoing monitoring — not a signed contract from three years ago and a shrug.
The trap most firms are walking into: they treated Reg S-P as a privacy-notice-and-encryption exercise, checked it off, and moved on. The amended rule reframed it as a program — ongoing oversight, incident response, breach-clock discipline — and the AI your vendors are adding is precisely the surface that oversight now has to reach. Your custodian added an AI assistant. Your CRM shipped an AI summarizer. Your email security tool started sending message content to a model. Each of those is a service provider touching customer information, and each is a line your oversight file is supposed to account for.
What it means for you
If you're an RIA or broker-dealer: this is your rule, and the deadline is behind you, not ahead of you. The do-this-Monday version:
- Pull your service-provider list and mark, for each one, whether it processes customer information and whether it has added AI features. If you can't answer the second question, that's a finding — write it down.
- Check your contracts for the 72-hour clock. The amended rule expects your program to secure timely breach notification from providers. Older MSAs often say "promptly" or say nothing. That gap is now a documented weakness, not a formality.
- Write (or update) the incident-response program. It has to exist on paper, cover the 30-day customer-notice obligation, and name who does what. An examiner will ask to read it.
- Reconcile with your Form ADV. If your brochure describes your data-security or AI posture, it has to match what your oversight file actually shows. Inconsistency between what you say and what you do is the classic exam finding — and "AI washing" (claiming AI diligence you can't evidence) is squarely on the SEC's radar this cycle.
If you're a credit union or community bank: Reg S-P is not your rule — it lives under the SEC, and you answer to the NCUA or your prudential regulator. But don't file this away as irrelevant. The structure the SEC just made explicit — written service-provider oversight, due diligence, ongoing monitoring, breach-clock discipline — is the same structure the FFIEC and NCUA already expect through third-party risk management and the NCUA's proportional vendor-diligence framework. When one regulator writes the expectation down in this much detail, it becomes the reference the others get compared against. Read Reg S-P as a preview of the questions your examiner will learn to ask.
How to get ahead of it
The prepared move is to build one artifact and reuse it: an AI vendor-oversight file that sits inside your existing service-provider program. For each provider that touches customer information, it holds four things — what the vendor does, whether and how it uses AI (including subprocessors and model vendors), what your due diligence found, and how you monitor it going forward. That's it. That file is your Reg S-P service-provider evidence for the AI surface, and it's reusable at every exam, not rebuilt each time.
Two disciplines make it examiner-durable. Date everything — due diligence is a point-in-time act, and "we reviewed this vendor" means nothing without a date and a next-review trigger. And write down what you couldn't verify. A vendor that won't answer your questionnaire is a finding you document and manage, not a hole you paper over. Examiners reward a firm that names its gaps and has a plan; they penalize the firm that pretends it has none.
If you want the step-by-step version of assembling this, it's the same muscle as a Reg S-P service-provider oversight file and the AI vendor due-diligence questions that actually matter.
What to watch out for
The overreaction is to buy an enterprise governance platform and call it compliance. Reg S-P doesn't ask for a platform; it asks for written oversight you can evidence. A five-person RIA does not need a six-figure GRC suite to satisfy 248.30 — it needs a real, dated, honest oversight file and an incident-response program someone actually wrote.
The snake-oil to sidestep: any vendor claiming its tool "makes you Reg S-P compliant" for AI. No product makes you compliant. Compliance is your written program plus evidence that you ran it. A tool can help you build the evidence — inventory the AI surface, structure the due diligence, keep it current — but the obligation is yours, and a regulator will hold you, not your vendor, to it.
And the honest caveat that most vendors won't tell you: a point-in-time vendor file does not monitor your vendors continuously. The amended rule expects ongoing oversight, which means the file is a floor, not a finish line. You still need a monitoring cadence — a re-review trigger when a vendor changes its AI features or its subprocessors. A one-time assessment is the right start and the wrong end. We'd rather say that plainly than sell you a snapshot as if it were surveillance.
The bottom line
Reg S-P didn't add an AI rule — it made your existing AI exposure examinable, on a deadline that has already passed for smaller firms and a topic the SEC has flagged for this exam cycle. The obligation is inherited through the service-provider oversight language, not a new AI mandate, but the practical effect is the same: your examiner can now ask to see the file, and most firms don't have it. Building that file — the AI your vendors use, what your diligence found, how you keep it current — is exactly the kind of exposure a Discover scan is built to inventory.
Get your Reg S-P AI vendor file. We run it with you.