SEC Third-Party Risk Management Requirements for RIAs

The SEC’s third-party risk management requirements for registered investment advisers do not come from a single rule. They come from a combination of the fiduciary duty an RIA owes its clients, the 2024 amendments to Regulation S-P, the recordkeeping obligations in Rule 204-2, and the areas SEC examiners are actively reviewing in the current cycle. The proposed standalone outsourcing rule was withdrawn in June 2025, but the underlying obligations are already binding and enforceable.

Fiduciary Duty Is the Starting Point

Every third-party obligation an RIA has traces back to one idea: hiring a vendor does not hand off the legal responsibility that comes with the function. The Commission has said this plainly. In its 2022 outsourcing proposal, the SEC wrote that “an adviser remains liable for its obligations, including under the Advisers Act, the other Federal securities laws and any contract entered into with the client, even if the adviser outsources functions.”1U.S. Securities and Exchange Commission. Outsourcing Fiduciary Duty to the Commission – Statement on Proposed Outsourcing by Investment Advisers If a vendor mishandles portfolio accounting, breaches client data, or fails to file something on time, the adviser wears the consequences.

Examination staff has reinforced this in practice. A 2015 risk alert on outsourced chief compliance officers found that advisers using outsourced CCOs who served many unaffiliated firms showed more significant compliance deficiencies, particularly when the outsourced CCO could not articulate the specific business and compliance risks of the adviser.2U.S. Securities and Exchange Commission. Examinations of Advisers and Funds That Outsource Their Chief Compliance Officers The takeaway is straightforward. You need enough internal expertise to know whether a vendor is doing its job, even when the vendor handles the day-to-day work.

The Withdrawn Outsourcing Rule

Advisers researching this topic often find references to proposed Rule 206(4)-11. It’s worth knowing where that stands. In October 2022, the SEC proposed the rule to create prescriptive due diligence and monitoring requirements for advisers outsourcing “covered functions” — services necessary for the adviser to provide advisory services in compliance with federal securities laws, where negligent performance would be reasonably likely to cause material harm to clients.3Securities and Exchange Commission. Outsourcing by Investment Advisers – Proposed Rule Clerical and general office functions were excluded.

In June 2025, the SEC formally withdrew the proposal, stating that it “does not intend to issue final rules with respect to” the outsourcing rulemaking.4U.S. Securities and Exchange Commission. Outsourcing by Investment Advisers The withdrawal doesn’t mean the SEC has lost interest in vendor oversight. It means the Commission is relying on existing authority instead of a new standalone rule. Firms that built compliance programs around the proposal’s framework aren’t wasting effort; the same principles show up in what examiners are already reviewing.

Regulation S-P: The Binding Vendor Oversight Rule

The 2024 amendments to Regulation S-P are the most specific, enforceable set of vendor oversight obligations the SEC has issued for advisers. Larger entities had to comply by December 3, 2025. Smaller entities must comply by June 3, 2026.5U.S. Securities and Exchange Commission. Enhancements to Regulation S-P – A Small Entity Compliance Guide

The amended rule requires covered advisers to establish, maintain, and enforce written policies and procedures for overseeing service providers. Those policies must include due diligence and monitoring, and they must be reasonably designed to ensure providers take appropriate measures to protect against unauthorized access to customer information.6eCFR. 17 CFR 248.30 – Procedures to Safeguard Customer Information

The 72-Hour Vendor Notification

Advisers must ensure their service providers notify them no later than 72 hours after the provider becomes aware that a breach involving customer information has occurred. Once notified, the adviser must trigger its own incident response program.6eCFR. 17 CFR 248.30 – Procedures to Safeguard Customer Information The 72-hour clock runs from the provider’s awareness, not the firm’s. A vendor that sits on a breach for weeks puts the adviser in a difficult spot. The rule doesn’t technically require this notification obligation be captured in a written agreement, but putting it in the contract is the only realistic way to enforce it.

The 30-Day Customer Notification

Once an adviser becomes aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred, it must notify affected customers as soon as practicable and no later than 30 days.6eCFR. 17 CFR 248.30 – Procedures to Safeguard Customer Information The only exception is a national security delay authorized by the U.S. Attorney General. An adviser can delegate the logistics of sending notices to a vendor, but the obligation itself stays with the adviser.

Building the Due Diligence and Monitoring Program

A workable program starts with an inventory. List every outsourced function and identify which ones would cause the most damage if they failed. Cloud infrastructure holding client data, trading systems operated by vendors, and outsourced compliance functions all carry different risk profiles and warrant different levels of oversight. Not every vendor needs the same scrutiny. The ones handling sensitive data or critical operations do.

Before You Sign

Pre-engagement due diligence should evaluate whether the provider can actually deliver what it promises. Key areas include financial stability (a vendor on shaky footing is a business continuity risk), technical and operational capacity, the provider’s own security controls, and whether the provider subcontracts work to others. Independent audit reports, particularly SOC 2 reports, are the standard way to assess whether a provider’s internal controls meet reasonable standards.

Subcontractor risk needs particular attention. When your vendor relies on its own third parties, you inherit risk from entities you may never interact with directly. Regulators don’t expect you to manage those subcontractor relationships yourself. They do expect you to confirm your primary vendor has its own oversight program and is cascading appropriate standards down the chain. Contracts are the main lever. You can’t audit a company you have no relationship with, but you can require your vendor to.

After You Sign

Initial diligence isn’t a one-time exercise. The monitoring process should track whether the provider is meeting its service commitments, review incident reports, and refresh the risk assessment when the vendor’s operations change. A merger, a new subcontractor, or a shift to different infrastructure can all move the risk profile. Reassessment frequency should match the criticality of the function. A trade execution vendor warrants closer review than an office supplier.

Senior management or the board must own the framework. The SEC’s examination program looks at whether governance structures provide meaningful oversight of outsourced activities, including who approves vendor relationships and how risks get escalated. A program that exists only on paper is the kind of deficiency examiners flag.

Contract Terms That Make the Rules Workable

Well-drafted vendor agreements are what makes the existing obligations enforceable. Reg S-P’s 72-hour notification requirement, for instance, is far easier to enforce when it’s written into the contract. At minimum, agreements with providers handling sensitive functions or client data should address:

  • Incident notification timelines aligned with the 72-hour Reg S-P requirement.
  • Audit and inspection rights, so the firm can review the provider’s compliance with security and operational commitments.
  • Measurable performance standards that give the firm a real basis for ongoing monitoring.
  • Restrictions on the provider’s ability to subcontract without notice or approval.
  • Termination rights, especially for material non-compliance or security failure.

Firms that rely on a vendor’s standard terms often discover the gap only after an incident, when they lack the contractual leverage to get the information or cooperation they need.

Recordkeeping Under Rule 204-2

Investment advisers must maintain books and records in an easily accessible location for at least five years from the end of the fiscal year of the last entry, with the first two years in an appropriate office of the adviser.7eCFR. 17 CFR 275.204-2 – Books and Records to Be Maintained by Investment Advisers This applies to the documentation supporting vendor relationships: due diligence assessments, monitoring reports, risk analyses, and copies of service agreements. When a third party maintains records on the adviser’s behalf, the adviser is still responsible for ensuring those records are preserved and available for SEC examination. The SEC has brought enforcement actions against firms that relied on vendors to maintain required records without confirming the vendor was actually doing so.

What Examiners Are Looking At in FY2026

The SEC’s fiscal year 2026 examination priorities put vendor oversight squarely on the review list. For investment advisers, examiners are focused on firms “utilizing third-parties to access clients’ accounts, where controls may be insufficient to protect client assets and data.”8U.S. Securities and Exchange Commission. Fiscal Year 2026 Examination Priorities

The priorities also single out Regulation S-P compliance, stating that examinations “will focus on firms’ policies and procedures, internal controls, oversight of third-party vendors, and governance practices.”8U.S. Securities and Exchange Commission. Fiscal Year 2026 Examination Priorities

The withdrawal of the outsourcing proposal did not soften the SEC’s interest in this area. The examination priorities suggest the Commission plans to enforce existing obligations more aggressively rather than wait for new rulemaking. Advisers that read the withdrawal as breathing room are likely to find the opposite when examiners arrive.