What does an affiliated investment adviser add to a CPA firm’s obligations?
An SEC-registered adviser puts a second set of security rules on your systems.
If your firm shares systems with an SEC-registered investment adviser, the adviser’s rules reach those systems. It must keep written security policies and a breach plan. After a breach, it must tell each affected person as soon as it can, and no later than 30 days. The 30 days start when it learns customer data was accessed or used without permission, or that this is reasonably likely. It can skip the notice if a reasonable investigation finds no substantial harm or inconvenience has resulted or is reasonably likely. Its policies must also have vendors report a breach to it within 72 hours. That promise lives in the vendor contracts. A partner should make checking those contracts someone’s job, and have the breach notice written before it is needed.
A second safeguards regime on the same systems. 17 CFR 248.30(a)(1) requires every covered institution, which includes an investment adviser registered with the Commission, to develop, implement and maintain written policies and procedures addressing administrative, technical and physical safeguards for the protection of customer information.
17 CFR 248.30(a)(3) requires those policies to include a response program reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information, with procedures to assess the incident, contain it, and notify affected individuals.
17 CFR 248.30(a)(4)(iii) sets the clock: notice as soon as practicable, but not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred.
The vendor clock most firms have not noticed
The adviser’s vendors have a deadline too. Under 17 CFR 248.30(a)(5)(i)(B), the adviser’s policies must be reasonably designed to make sure a vendor tells the adviser about a breach as soon as possible. The rule calls the vendor a service provider. The outer limit is 72 hours after the vendor becomes aware of the breach.
The clock covers a breach in security that gave someone unauthorized access to a customer information system the vendor maintains. Once the adviser hears, it must start its own response program, its plan for handling a breach.
This clock lives in the contracts signed with those vendors. That makes it a contracting task, not a security task. It is usually nobody’s job.
How the SEC rule differs from the FTC rule
- What sets it off. The FTC rule applies when someone acquires unencrypted customer information without authorization and 500 or more consumers are affected. Under 17 CFR 248.30(a)(4)(i), the SEC rule applies when sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. There is no minimum consumer count.
- Who is told. Under the FTC rule, the firm tells the FTC. Under 17 CFR 248.30(a)(4), the adviser tells each affected individual.
- The way out. The FTC rule does not count encrypted data. Under 17 CFR 248.30(a)(4)(i), the adviser can skip the notice after a reasonable investigation. It has to find that the information has not been, and is not reasonably likely to be, used in a way that causes substantial harm or inconvenience.
- Who checks. The FTC enforces after the fact. The SEC examines advisers routinely.
What the notice has to say
Under 17 CFR 248.30(a)(4)(iv), the notice must contain eight things. They include:
- a general description of the incident and the type of sensitive customer information involved
- the date or date range, where it can be determined
- contact details, including a telephone number and a named office
- a recommendation to review account statements
- an explanation of fraud alerts and how to place one
- a recommendation to obtain credit reports
- how to obtain one free of charge
- a pointer to Federal Trade Commission guidance on identity theft
Because the contents are fixed, the notice is a template. Your firm can write it once, in advance, and keep it with the breach response program.
Related questions
Who counts as a covered institution?+
Under 17 CFR 248.30(d)(3), it means any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission (the SEC) or another appropriate regulatory agency.
What is sensitive customer information?+
Under 17 CFR 248.30(d)(9), it is any part of customer information that, if compromised, could create a reasonably likely risk of substantial harm or inconvenience. The rule’s examples include a Social Security number, a driver’s license or identification number, a biometric record, and an account number combined with authenticating information.
Can a vendor send the notices for the firm?+
Yes, under a written agreement. 17 CFR 248.30(a)(5)(ii) lets the adviser sign a written agreement for a service provider to notify affected individuals on its behalf. Under 17 CFR 248.30(a)(5)(iii), the adviser is still responsible for making sure notice is given.
When did this take effect?+
The amendments were published on 3 June 2024, at 89 FR 47688. Your compliance date is set separately. The SEC’s release adopting them set separate compliance dates for larger and smaller entities. Check the release for the date that applies to your firm.
The obligations on this page are three of the many that bind a firm holding client financial data. The map shows the rest, and which control satisfies each one.
See the obligation mapRun the exposure checkTalk to usGeneral reference, not legal or tax advice. Every figure and deadline on this page was read against the primary source. Claremont Security does not perform audits, issue certifications, or attest to any examination.
