NobleCloak
RIAs & Broker-Dealers

The Reg S-P AI vendor file your examiner now expects.

Reg S-P's amended safeguards rule is live — including a written obligation to oversee your service providers on an ongoing basis. NobleCloak gives you an AI vendor-risk assessment scoped to exactly that: every AI tool your firm and its vendors actually use, what data it can reach, and evidence you can hand an examiner. In days, not months.

The deadline already passed

Your vendors still won't answer your due-diligence letters.

The SEC's amendments to Regulation S-P took effect for larger firms on December 3, 2025, and for every remaining smaller firm on June 3, 2026 — the joint SIFMA/IAA request for more time was denied. The rule now requires written policies for ongoing oversight of your service providers, a 72-hour provider-to-firm breach notice, and a 30-day customer notice. That's not a policy you write once and file — it's an ongoing obligation to know what your vendors do with your customers' data. And the vendors you're supposed to be diligencing have quietly started running AI inside the products you already pay for — your CRM added an assistant, your portfolio tool ships a summarizer. Most firms are only partially aware of which of their vendors even use AI (Ncontracts' 2026 State of TPRM survey, n=173: 72% partially aware, 0% extremely confident). So you send the questionnaire, and the answers that come back are marketing copy, not the facts an examiner wants.

Why RIAs, specifically

Reg S-P compliance is a named priority in the SEC Division of Examinations 2026 exam priorities — the oversight file is on the list. And the amended rule made service-provider oversight a written, ongoing obligation for the entire covered RIA and broker-dealer market at once, small firms included. There is no size threshold to hide under.

What NobleCloak gives you

The assessment, in the language of your exam.

A Reg S-P-scoped AI vendor file

The Discover scan is an AI vendor-risk assessment that maps directly to the service-provider oversight the amended rule requires. Every AI tool your people authorized, the data scopes it holds, who is using it, and since when.

Findings, not questionnaires to send

Instead of "please describe your AI data practices," you get "Otter.ai holds Calendar + Drive read access for 6 users since March. Recordings retained. No SOC 2 on file." Generated, not hand-written — that sentence is the evidence.

A framework crosswalk

Findings mapped to Reg S-P's oversight and incident-response requirements and to the NIST AI RMF — consistent with what you already say in your Form ADV. No surprises, no AI washing.

Built for a one- or two-person program

Concierge. We run your first report with you. Days, not months — for a fraction of what a compliance consultant retainer runs.

The honest part

Exposure and get-ahead — not a mandate that doesn’t exist yet.

This is exposure and get-ahead, not a claim that any US regulator mandates AI-specific vendor controls today. There is no such mandate. What exists is the obligation you already inherited through Reg S-P's service-provider oversight and safeguards rules: know your vendors, monitor them, prove it. The scan reads your SSO- and OAuth-discoverable AI surface as of the scan date — it does not capture personal-account usage, personal devices, or direct API access. We state that boundary on every report, because a report that implied completeness would be worse than nothing at an exam.

Built by people who lived it

NobleCloak was built by people who sat inside the compliance conversation — a product leader from the third-party-risk world and a security architect who built the guardrails. We know what an examiner pulls, because we used to assemble it.