What the SEC's Reg S-P Sweep Letter Actually Asks For

Last updated: September 2026

Why the real issue is not the length of the request - it is whether an RIA can document that its program is operating

The SEC's Division of Examinations is examining compliance with the amended Regulation S-P requirements. Industry reports also indicate that document request letters have been issued in what appears to be a sweep examination of registered investment advisers. [1, 3]

The reported request is fairly straightforward.

Examiners want to see whether firms can produce the records supporting their cybersecurity, privacy, vendor monitoring, incident response, and governance programs. [1]

That's the important part.

The challenge isn't necessarily understanding what Regulation S-P requires. It's being able to show what your firm has actually done.

Foley Hoag's August 18 analysis of the reported examination request describes requests involving governance and risk management, compliance programs, privacy and information security, cybersecurity incidents, service providers and vendor management, and related documentation. [1]

For smaller covered institutions, including SEC-registered investment advisers below the applicable $1.5 billion AUM threshold, the compliance date was June 3, 2026. Both compliance deadlines under the amended Regulation S-P have now passed. [1, 2]

If an examination request arrived tomorrow, what could you actually produce?

What examiners appear to be looking for

The reported sweep covers several areas that should already be familiar to firms operating a cybersecurity compliance program.

Governance and risk management. The reported request includes organization charts, cybersecurity reporting lines, committee structures, IT governance, and risk-assessment documentation. [1]

Risk assessments. Firms should be prepared to produce documentation showing how cybersecurity and information-security risks are being evaluated and addressed. Risk-assessment documentation is specifically among the materials described in the reported request. [1]

Vendor identification and risk monitoring. The reported request includes vendor policies, vendor risk assessments, monitoring records, service agreements, and vendor lists. The amended rule separately requires written policies and procedures reasonably designed to provide for oversight of service providers, including monitoring. [1, 2]

Incident response. The amended rule requires covered institutions to adopt written policies and procedures for an incident response program addressing unauthorized access to or use of customer information. The reported sweep also seeks incident-response materials and information regarding cybersecurity incidents. [1, 2]

Cybersecurity and privacy safeguards. The SEC's FY 2026 Examination Priorities state that, after the applicable compliance dates, examinations will evaluate whether firms have developed, implemented, and maintained policies and procedures addressing administrative, technical, and physical safeguards for customer information. [3]

None of that is particularly exotic. The more important question is whether you can produce the records.

Having a policy isn't the same as documenting compliance

The amended Regulation S-P expressly requires covered institutions to make and maintain written records documenting compliance with the safeguards rule and disposal rule requirements. [2]

It's one thing to say you perform cybersecurity risk assessments. It's another to produce the assessment and show that the process is being maintained.

It's one thing to say you monitor service-provider risk. It's another to produce records showing which vendors were evaluated, what risks were identified, and that monitoring continued over time.

It's one thing to have an incident-response plan. It's another to maintain the records supporting an active incident-response program.

And it's one thing to have written cybersecurity policies. It's another to maintain documentation showing that the program described in those policies is actually being implemented.

That distinction matters because the SEC's FY 2026 Examination Priorities say examiners will evaluate whether firms have developed, implemented, and maintained policies and procedures in accordance with the amended rule after the applicable compliance dates. [3]

Reg S-P compliance isn't just about having documents. It's about having the documentation showing the work is being done.

What should already be available

If an examination request arrived, these shouldn't become new projects. They should already exist as part of the firm's ongoing program.

• A current risk assessment. Documentation showing that cybersecurity and privacy risks have been evaluated and that appropriate safeguards are being maintained. The reported sweep specifically includes risk-assessment documentation. [1]

• Written cybersecurity and privacy policies and procedures. The framework describing how the firm protects customer information and operates its compliance program. Regulation S-P requires written safeguards and incident-response policies and procedures. [2]

• Vendor risk monitoring records. Documentation showing that relevant service providers have been identified and that the firm's oversight and monitoring process is actually occurring. [1, 2]

• A written incident-response program. Procedures designed to detect, respond to, and recover from unauthorized access to or use of customer information. [2]

• Governance documentation. Records showing that cybersecurity and privacy responsibilities are assigned and that the program is being managed. Governance materials are among the categories described in the reported sweep request. [1]

• Evidence of compliance. Records demonstrating that required safeguards, incident-response procedures, service-provider monitoring, and other elements of the program are actually being implemented and maintained. [2, 3]

An examination isn't only about what your policies say. It's about what you can demonstrate.

Service-provider oversight is a good example

The amended rule requires a covered institution's incident-response program to include written policies and procedures reasonably designed to provide for oversight of service providers, including through monitoring. [2]

Those procedures must be reasonably designed to ensure service providers take appropriate measures to protect against unauthorized access to or use of customer information and notify the covered institution as soon as possible - but no later than 72 hours after becoming aware of a qualifying breach involving a customer information system maintained by the service provider. [2]

The final rule did not retain the proposal's requirement that covered institutions enter into written contracts containing specified safeguarding and notification provisions. Instead, the final amendments focus on the covered institution's oversight of its service providers. [2]

So the issue isn't simply whether you collected another vendor agreement.

Have you identified the relevant service providers?

Have you evaluated their risk?

Are you monitoring that risk?

And can you show that you are doing it?

That is what an ongoing vendor risk monitoring program should be able to demonstrate.

Our white paper, Service Provider Breach Notification Under the Final Regulation S-P Amendments, explains the service-provider requirements in greater detail and how firms can document an ongoing monitoring program.

The real question isn't whether you have a cybersecurity program

It's whether you can demonstrate it.

That is increasingly important under Regulation S-P.

Policies alone don't show that vendor risk is being monitored.

They don't show that risk assessments are being maintained.

They don't show that incident-response procedures are ready.

And they don't provide the records documenting that required cybersecurity work is actually occurring.

The amended rule requires written records documenting compliance, and the SEC has stated that examinations will focus on whether firms have developed, implemented, and maintained the required policies and procedures. [2, 3]

The evidence needs to exist before the examination request arrives.

That's what Advisor Armor is designed to do.

Advisor Armor gives RIAs a single cybersecurity compliance program for maintaining risk assessments, written policies, incident response, vendor risk monitoring, security testing, employee training, device monitoring, and the documentation that shows the work is being performed.

So when an examiner asks what your firm has done, you're not trying to reconstruct the answer.

You already have it.

See what your firm could produce today -> Schedule a 10-minute review


Sources and references

1. Foley Hoag LLP. SEC Reg S-P Sweep Exams: What Investment Advisers Should Be Ready to Produce Now (Aug. 18, 2026).

2. U.S. Securities and Exchange Commission. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information, Release Nos. 34-100155, IA-6604, IC-35193 (May 16, 2024; Federal Register publication June 3, 2024).

3. U.S. Securities and Exchange Commission, Division of Examinations. FY 2026 Examination Priorities (Nov. 17, 2025).

Note: The SEC has not publicly released the reported sweep letter. References to the contents of that letter are therefore attributed to Foley Hoag's August 18, 2026 summary of the reported request.

For informational purposes only. This article is not legal advice.

Next
Next

New white paper: What the Reg S-P 72-hour vendor breach rule actually requires