Skip to main content

RESOURCES

Reg S-P incident response with an AI vendor in scope

The vendor has 72 hours to tell you. You have 30 days to tell your clients. Almost all of the work happens in the gap, using information only the vendor has.

Last reviewed: 2 August 2026 · All resources

What applies, and to whom

Does Regulation S-P apply to my advisory firm?

Regulation S-P governs how covered institutions handle customer information. SEC-registered investment advisers are covered institutions, alongside broker-dealers, investment companies, and transfer agents. If your firm is SEC-registered and holds information about individual clients, it applies.

State-registered advisers should check their own regulator’s requirements, which frequently track the federal position but are not identical.

What did the 2024 amendments change?

They turned things that were good practice into things that are required. Covered institutions must maintain written policies and procedures for an incident response program designed to detect, respond to, and recover from unauthorized access to or use of customer information. That program has to include customer notification, and it has to include oversight of service providers.

The service-provider piece is the one that matters for an AI purchase: the obligation is discharged through written agreements, which means the protection you rely on has to be in a contract you can enforce rather than on a page the vendor can edit. Those requirements are now in effect.

Is an AI vendor a service provider for this purpose?

If it receives, maintains, processes, or otherwise has access to customer information, yes, and the label the vendor prefers for itself does not change that. A meeting-notes tool that ingests calls with clients, a drafting assistant connected to a mailbox, and a document tool connected to a client folder are all in scope.

The practical consequence is that these tools belong in your service-provider inventory rather than in a separate list of software, and their contracts need the same clauses your custodian’s does.

The two clocks

Incident response with a vendor in scope is a sequencing problem. Two deadlines run, they start at different moments, and one of them is mostly consumed before you learn anything.

How fast does the vendor have to tell us?

The amended rule requires covered institutions to take reasonable measures, through written agreements, to ensure service providers protect against unauthorized access to or use of customer information, and to notify the covered institution as soon as possible and no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system.

Check the number in your own agreement. Standard vendor terms often say something slower, or condition notification on the vendor’s own confirmation of impact, which can add days before the clock the rule contemplates has even started.

BALAU AI’S ANSWER

Balau AI’s incident-notification commitments are contractual rather than published. Request the agreement and the procurement pack at trust@balau.ai and read them before signing.

How long do we have to tell clients?

A covered institution must notify affected individuals as soon as practicable, and no later than 30 days after becoming aware that unauthorized access to or use of sensitive customer information has occurred or is reasonably likely to have occurred.

There is an exception: notification is not required if the institution determines, after a reasonable investigation, that the sensitive customer information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience. That determination is a decision the firm makes and should document, not a default.

Why is the gap between the two the real problem?

Do the arithmetic. The vendor has up to 72 hours to tell you a breach happened. Your 30 days begin when you become aware. Everything between those points, working out whose data was involved, whether it was sensitive, and whether harm is reasonably likely, happens on your clock using information only the vendor has.

This is why the useful contractual term is not just the notification deadline but the cooperation obligation: what the vendor will tell you, in what detail, how quickly after the initial notice, and whether it will support your determination with evidence rather than assurances.

Do state breach-notification laws still apply?

Yes, and they run in parallel rather than being displaced. Every US state has a breach-notification statute, the definitions of covered information differ, and several have deadlines shorter than 30 days or require notice to a state authority as well as to individuals.

Your incident response plan should therefore ask "which states do the affected clients live in" early, not late. That question is often the one that sets the actual deadline.

What to do before anything happens

What has to be in the contract before the incident?

The terms that are impossible to negotiate once something has gone wrong:

  • The notification trigger, the deadline, and what "becoming aware" means.
  • The channel and the named contact, on both sides, with a fallback.
  • A cooperation obligation covering forensic detail, scope of affected data, and evidence you can rely on for your own determination.
  • A preservation obligation, so logs and artifacts are not rotated away during the investigation.
  • Flow-down of the same obligations to the vendor’s sub-processors.
  • Who may speak publicly, and a requirement that the vendor not name you without agreement.

What do we need to know in advance about what the vendor holds?

The question you will be asked first, by clients and by your regulator, is "whose information was involved". If answering that requires the vendor to run an investigation, you have lost days you did not have.

Keep your own record of what each AI vendor receives, at the field level, and which client populations it touches. Refresh it when the integration changes. It is the difference between a scoping exercise measured in hours and one measured in weeks.

BALAU AI’S ANSWER

Access follows the firm’s roles and data permissions, and personal identifiers are redacted before AI processing. Redaction is enforced by the type system at compile time on the context-packet path, and at runtime on every other path that reaches a model.

What should a tabletop exercise cover when AI is involved?

Run the scenario where the vendor, not the firm, is breached, because it is the one your existing plan is least likely to handle. Useful things to discover in a rehearsal rather than in the event:

  • Who at the firm receives the vendor’s notification, and what happens if that person is on leave.
  • How quickly you can list the clients whose information the vendor held.
  • Whether you can determine what left, or only what was accessible.
  • Who decides whether the substantial-harm exception applies, and what they need to decide it.
  • Whether you can suspend the integration without losing access to records you are required to keep.
  • What you would tell clients, and who signs it off.

Write down what the rehearsal found, including the parts that did not work. That artifact is worth more at an examination than a plan with no evidence of ever having been used.

What evidence should survive the incident?

The timeline, principally: when the vendor became aware, when it told you, what it told you, what you did next, what you determined and on what basis, and when notice went out. An incident that was handled well but cannot be reconstructed will be examined as though it was handled badly.

Access history matters too. Being able to show who could see the affected material, and who actually did, is what turns a scoping estimate into a finding of fact.

BALAU AI’S ANSWER

Access and activity evidence is preserved: who saw what, when, and what was approved is retained and reconstructable. Audit records are retained for seven years, and the firm remains the record-keeper of obligation.